davsclaus commented on code in PR #27205:
URL: https://github.com/apache/camel/pull/27205#discussion_r4157289664


##########
components/camel-jgroups/src/main/java/org/apache/camel/component/jgroups/JGroupsEndpoint.java:
##########
@@ -153,6 +167,53 @@ private ObjectInputFilter resolveDeserializationFilter() {
                 deserializationFilter, 
DeserializationFilterHelper.DEFAULT_CLASS_DESERIALIZATION_FILTER);
     }
 
+    /**
+     * Verifies, at consumer start, that inbound cluster messages will not be 
Java-deserialized without a pre-read
+     * protection in place. JGroups materializes the message body with {@code 
ObjectInputStream.readObject()} inside its
+     * own receive path, before Camel can inspect the result, so the post-read 
{@link #deserializationFilter} check is
+     * defense-in-depth only. A pre-read control is considered present when 
any of the following holds: a JVM-wide
+     * serialization filter ({@code -Djdk.serialFilter}) is configured, the 
JGroups
+     * {@code jgroups.deserialization.filter} system property is set, the 
{@code deserializationFilter} option is
+     * configured, or the channel protocol stack includes 
authentication/encryption. Set {@link #acceptAllObjects} to
+     * {@code true} to start anyway and accept any type, restoring the 
previous behaviour.
+     *
+     * @throws JGroupsException if none of the above is configured on the 
(unauthenticated) default channel
+     */
+    void verifyConsumerDeserializationGuard() {
+        if (acceptAllObjects) {
+            return;
+        }
+        if (deserializationFilter != null && !deserializationFilter.isBlank()) 
{

Review Comment:
   `deserializationFilter` is the post-read class check (CAMEL-24676) - it runs 
after `Message.getObject()` and does not restrict `readObject()`. Letting it 
satisfy the guard means `deserializationFilter=java.**` passes with no pre-read 
protection, and `deserializationFilter=*` is effectively an unmarked 
`acceptAllObjects=true`. Suggest dropping this branch (and the matching wording 
in the component doc and upgrade guide).



##########
components/camel-jgroups/src/main/java/org/apache/camel/component/jgroups/JGroupsEndpoint.java:
##########
@@ -68,6 +72,16 @@ public class JGroupsEndpoint extends DefaultEndpoint {
                             + " java.**, javax.** and org.apache.camel.** is 
applied. Use * to accept any type.")
     private String deserializationFilter;
 
+    @UriParam(label = "consumer,security", defaultValue = "false",
+              description = "Whether to start the consumer and accept any 
object deserialized from the cluster even"
+                            + " when no pre-read deserialization control is 
configured. When false (the default) the"
+                            + " consumer fails to start on an unauthenticated 
default channel unless a JVM-wide"
+                            + " -Djdk.serialFilter, the JGroups 
jgroups.deserialization.filter system property, the"
+                            + " deserializationFilter option, or an 
authenticated/encrypted channel is configured. Set"
+                            + " to true to restore the previous behaviour of 
accepting any serialized type; this also"
+                            + " disables the post-read class check.")
+    private boolean acceptAllObjects;

Review Comment:
   This is an insecure-serialization opt-in, so it should carry `security = 
"insecure:serialization"` on the `@UriParam` (and on the `@Metadata` in 
`JGroupsComponent`), like the equivalent flags in camel-jms / camel-netty. 
Otherwise `camel.main.profile=prod` will not reject `acceptAllObjects=true`. 
Generated JSON/DSL need regenerating afterwards.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to