gnodet-bot commented on code in PR #27205:
URL: https://github.com/apache/camel/pull/27205#discussion_r4163857852
##########
components/camel-jgroups/src/main/java/org/apache/camel/component/jgroups/JGroupsEndpoint.java:
##########
@@ -153,6 +167,52 @@ private ObjectInputFilter resolveDeserializationFilter() {
deserializationFilter,
DeserializationFilterHelper.DEFAULT_CLASS_DESERIALIZATION_FILTER);
}
+ /**
+ * Verifies, at consumer start, that inbound cluster messages will not be
Java-deserialized without a pre-read
+ * protection in place. JGroups materializes the message body with {@code
ObjectInputStream.readObject()} inside its
+ * own receive path, before Camel can inspect the result, so the post-read
{@link #deserializationFilter} check is
+ * defense-in-depth only. A pre-read control is considered present when
any of the following holds: a JVM-wide
+ * serialization filter ({@code -Djdk.serialFilter}) is configured, the
JGroups
+ * {@code jgroups.deserialization.filter} system property is set, the
{@code deserializationFilter} option is
Review Comment:
💡 **Javadoc/code mismatch:** The Javadoc lists "`the deserializationFilter
option is configured`" as one of the conditions that satisfies the guard, but
the code (line 184 inline comment and the actual guard logic) explicitly
_excludes_ `deserializationFilter` — which is the correct behaviour per
davsclaus's finding #1. This sentence is a leftover from the first revision.
```suggestion
* Verifies, at consumer start, that inbound cluster messages will not
be Java-deserialized without a pre-read
* protection in place. JGroups materializes the message body with
{@code ObjectInputStream.readObject()} inside its
* own receive path, before Camel can inspect the result, so the
post-read {@link #deserializationFilter} check is
* defense-in-depth only. A pre-read control is considered present when
any of the following holds: a JVM-wide
* serialization filter ({@code -Djdk.serialFilter}) is configured, the
JGroups
* {@code jgroups.deserialization.filter} system property is set, or the
channel protocol stack includes
* authentication/encryption. Set {@link #acceptAllObjects} to
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]