Application security gap analysis in Struts2

2009-05-05 Thread Arshan Dabirsiaghi
Struts2 folks, The Intrinsic Security Working Group (ISWG) at OWASP (http://www.owasp.org) has been researching what security countermeasures an application architect or technical lead must plan for when creating a Struts2 application. The result of this research is a document that we are look

UI tags encoding/stripping behavior

2009-03-12 Thread Arshan Dabirsiaghi
I'm a Struts1 guy who just started researching Struts2. Is there any place where the encoding and stripping behavior of the UI tags is located? I've done a fair bit of Googling and downloaded the source code, but I can't find any correlating logic. If I send the following string as a parameter that