Return-Path: X-Original-To: apmail-struts-user-archive@www.apache.org Delivered-To: apmail-struts-user-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id CE492F305 for ; Wed, 8 May 2013 05:51:40 +0000 (UTC) Received: (qmail 75504 invoked by uid 500); 8 May 2013 05:51:38 -0000 Delivered-To: apmail-struts-user-archive@struts.apache.org Received: (qmail 75478 invoked by uid 500); 8 May 2013 05:51:38 -0000 Mailing-List: contact user-help@struts.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Help: List-Post: List-Id: "Struts Users Mailing List" Reply-To: "Struts Users Mailing List" Delivered-To: mailing list user@struts.apache.org Received: (qmail 75461 invoked by uid 99); 8 May 2013 05:51:38 -0000 Received: from minotaur.apache.org (HELO minotaur.apache.org) (140.211.11.9) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 08 May 2013 05:51:38 +0000 Received: from localhost (HELO mail-pb0-f42.google.com) (127.0.0.1) (smtp-auth username lukaszlenart, mechanism plain) by minotaur.apache.org (qpsmtpd/0.29) with ESMTP; Wed, 08 May 2013 05:51:38 +0000 Received: by mail-pb0-f42.google.com with SMTP id up7so964117pbc.15 for ; Tue, 07 May 2013 22:51:37 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=x-received:mime-version:in-reply-to:references:from:date:message-id :subject:to:content-type:content-transfer-encoding; bh=dmJaTI/8hIKpK9GDk3Y/1VNuJCag2vpCwM237SZuxDo=; b=h9anQKWPHhNf3rvvS9lt0Lr1gMh6G81VEnWH+WiKd1NEdNy6U2z0YpyrZ2fJ8j0aNa yFOirQ6sWuJRCMIKEpTdCqkIYBSMHgdAo+d4q4GpAEuKx52Fzo3680yFBloSJkVDccFU VJHgyhZ59Gt0jvCe2ee/eho/8c3jH7JQV61ytL0NVx2r4LNfkDF+06ULzfAghPLnQJ11 C2NDNrB2DtTDlaffOQo1gsvfPBRe4xTv7c7JXq4pbs/31BGI0CR3ChfzUJNGgy3T8Pkz Fhj+hemKxkWCeEEPFhv7UHYj6ySgD5f+CFLRUvPNEVpgWCmvMP4O2m1vpBsnx1wRPlM7 EjeA== X-Received: by 10.66.7.202 with SMTP id l10mr6329562paa.176.1367992297592; Tue, 07 May 2013 22:51:37 -0700 (PDT) MIME-Version: 1.0 Received: by 10.68.216.102 with HTTP; Tue, 7 May 2013 22:51:17 -0700 (PDT) In-Reply-To: <40B92331-D541-48E4-B23F-18D0A0998890@Newfield.org> References: <40B92331-D541-48E4-B23F-18D0A0998890@Newfield.org> From: Lukasz Lenart Date: Wed, 8 May 2013 07:51:17 +0200 Message-ID: Subject: Re: Localised text tag To: Struts Users Mailing List Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Hi, Yeah, it looks like a double evaluation which is a bug probably Regards --=20 =C5=81ukasz + 48 606 323 122 http://www.lenart.org.pl/ 2013/5/8 Dale Newfield : > It seems like an evaluation of a value, which could be bad, in fact a lar= ge security hole. What if that value were "System.exit()"? (I forget my og= nl...I think you need fully qualified path and a hash or at or something to= call static methods, but you get the point.) > > -Dale > > > On May 7, 2013, at 11:10 PM, Zoran Avtarovski w= rote: > >> I have a small issue that I'm trying to resolve and I was hoping the som= eone >> might have come across it earlier. >> >> I'll try to explain as best I can: >> I have a number of objects on the value stack: >> 1. pojo - a java object with a string attribute called key which links = to a >> DB based localised text value >> 2. movement =C2=AD another java object with a string attribute called st= rength >> To display the localised text associated with the pojo key I use the >> following tag >> >> >> >> The problem is that if the key value clashes with another item on the va= lue >> stack I don't get the string value. >> For example if the key value on pojo is "movement.strength" and the stre= ngth >> value for movement is "weak" I don't get the expected results. Instead o= f >> getting the localised text with key "movement.strength" I get the locali= sed >> text with key "weak". I tried setting the searchValueStack property to f= alse >> but it made no change. >> >> I'd appreciate any help. >> >> Z. >> >> >> > > --------------------------------------------------------------------- > To unsubscribe, e-mail: user-unsubscribe@struts.apache.org > For additional commands, e-mail: user-help@struts.apache.org > --------------------------------------------------------------------- To unsubscribe, e-mail: user-unsubscribe@struts.apache.org For additional commands, e-mail: user-help@struts.apache.org