oscerd commented on PR #27205: URL: https://github.com/apache/camel/pull/27205#issuecomment-5947731211
Thanks for the review — all four points are addressed in the latest push (force-pushed after a rebase onto current main): 1. The guard no longer accepts the post-read `deserializationFilter` as pre-read protection. Only `-Djdk.serialFilter`, the `jgroups.deserialization.filter` system property, or an AUTH/encrypted channel satisfy it. Component doc and upgrade guide updated to match. 2. `acceptAllObjects` now carries `security = "insecure:serialization"` on both the endpoint `@UriParam` and the component `@Metadata`; `SecurityUtils`, catalog JSON and DSL regenerated. 3. `shouldRejectDeniedTypeWithDefaultFilter` is restored — the default-filter and explicit-filter tests now satisfy the guard via the `jgroups.deserialization.filter` property, so the post-read allow-list is still exercised. 4. `JGroupsDeserializationStartupGuardTest` now covers fail-fast, `acceptAllObjects`, the `jgroups.deserialization.filter` path, and `isSecuredChannel` (AUTH-in-stack) detection. On the questions: - `acceptAllObjects=true` is the single "accept any type" insecure opt-in: it bypasses the guard and disables the post-read check. To keep post-read filtering, leave it off and configure a pre-read control plus `deserializationFilter`. Documented. - `AUTH` without encryption satisfies the guard by design (it already restricts who may join and send); now stated in the Security section. - A filter installed only via a custom `jdk.serialFilterFactory` is not detectable (`ObjectInputFilter.Config.getSerialFilterFactory()` is never null), so such deployments would hit the guard. Documented, with `jgroups.deserialization.filter` / `acceptAllObjects` as the escape hatch, rather than adding an unreliable check. - Agreed: main-only, no backports — consistent with the 4.23-only upgrade-guide entry. All 26 camel-jgroups module tests pass; the change was regenerated with a full reactor from root. _Claude Code on behalf of oscerd_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
