gnodet-bot commented on code in PR #27205:
URL: https://github.com/apache/camel/pull/27205#discussion_r4163857852


##########
components/camel-jgroups/src/main/java/org/apache/camel/component/jgroups/JGroupsEndpoint.java:
##########
@@ -153,6 +167,52 @@ private ObjectInputFilter resolveDeserializationFilter() {
                 deserializationFilter, 
DeserializationFilterHelper.DEFAULT_CLASS_DESERIALIZATION_FILTER);
     }
 
+    /**
+     * Verifies, at consumer start, that inbound cluster messages will not be 
Java-deserialized without a pre-read
+     * protection in place. JGroups materializes the message body with {@code 
ObjectInputStream.readObject()} inside its
+     * own receive path, before Camel can inspect the result, so the post-read 
{@link #deserializationFilter} check is
+     * defense-in-depth only. A pre-read control is considered present when 
any of the following holds: a JVM-wide
+     * serialization filter ({@code -Djdk.serialFilter}) is configured, the 
JGroups
+     * {@code jgroups.deserialization.filter} system property is set, the 
{@code deserializationFilter} option is

Review Comment:
   💡 **Javadoc/code mismatch:** The Javadoc lists "`the deserializationFilter 
option is configured`" as one of the conditions that satisfies the guard, but 
the code (line 184 inline comment and the actual guard logic) explicitly 
_excludes_ `deserializationFilter` — which is the correct behaviour per 
davsclaus's finding #1. This sentence is a leftover from the first revision.
   
   ```suggestion
        * Verifies, at consumer start, that inbound cluster messages will not 
be Java-deserialized without a pre-read
        * protection in place. JGroups materializes the message body with 
{@code ObjectInputStream.readObject()} inside its
        * own receive path, before Camel can inspect the result, so the 
post-read {@link #deserializationFilter} check is
        * defense-in-depth only. A pre-read control is considered present when 
any of the following holds: a JVM-wide
        * serialization filter ({@code -Djdk.serialFilter}) is configured, the 
JGroups
        * {@code jgroups.deserialization.filter} system property is set, or the 
channel protocol stack includes
        * authentication/encryption. Set {@link #acceptAllObjects} to
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to