Return-Path: X-Original-To: apmail-struts-issues-archive@minotaur.apache.org Delivered-To: apmail-struts-issues-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 0D64618210 for ; Tue, 3 Nov 2015 18:38:28 +0000 (UTC) Received: (qmail 35571 invoked by uid 500); 3 Nov 2015 18:38:27 -0000 Delivered-To: apmail-struts-issues-archive@struts.apache.org Received: (qmail 35533 invoked by uid 500); 3 Nov 2015 18:38:27 -0000 Mailing-List: contact issues-help@struts.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@struts.apache.org Delivered-To: mailing list issues@struts.apache.org Received: (qmail 35511 invoked by uid 99); 3 Nov 2015 18:38:27 -0000 Received: from arcas.apache.org (HELO arcas) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 03 Nov 2015 18:38:27 +0000 Received: from arcas.apache.org (localhost [127.0.0.1]) by arcas (Postfix) with ESMTP id B562B2C1F63 for ; Tue, 3 Nov 2015 18:38:27 +0000 (UTC) Date: Tue, 3 Nov 2015 18:38:27 +0000 (UTC) From: "Pablo Lozano (JIRA)" To: issues@struts.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Created] (WW-4560) ParametersInterceptor check for valid values blocks many acceptable values using the same rules for parameters. MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 Pablo Lozano created WW-4560: -------------------------------- Summary: ParametersInterceptor check for valid values blocks many acceptable values using the same rules for parameters. Key: WW-4560 URL: https://issues.apache.org/jira/browse/WW-4560 Project: Struts 2 Issue Type: Bug Components: Core Interceptors Affects Versions: 2.3.24, 2.3.20 Reporter: Pablo Lozano Commit :5ebc0643b55d728a6713a82559a594d875452cd8 Added an extra check to validate also parameter Values. Before it only checked if the parameter is accepted. This extra check is not allowing some values to be used as they are being blocked which should be perfectly valid values. The same rules to validate parameters should not be the same for the values. Is there a reason why this is implemented this way? -- This message was sent by Atlassian JIRA (v6.3.4#6332)