oscerd commented on code in PR #27205:
URL: https://github.com/apache/camel/pull/27205#discussion_r4165255536


##########
components/camel-jgroups/src/main/java/org/apache/camel/component/jgroups/JGroupsEndpoint.java:
##########
@@ -153,6 +167,52 @@ private ObjectInputFilter resolveDeserializationFilter() {
                 deserializationFilter, 
DeserializationFilterHelper.DEFAULT_CLASS_DESERIALIZATION_FILTER);
     }
 
+    /**
+     * Verifies, at consumer start, that inbound cluster messages will not be 
Java-deserialized without a pre-read
+     * protection in place. JGroups materializes the message body with {@code 
ObjectInputStream.readObject()} inside its
+     * own receive path, before Camel can inspect the result, so the post-read 
{@link #deserializationFilter} check is
+     * defense-in-depth only. A pre-read control is considered present when 
any of the following holds: a JVM-wide
+     * serialization filter ({@code -Djdk.serialFilter}) is configured, the 
JGroups
+     * {@code jgroups.deserialization.filter} system property is set, the 
{@code deserializationFilter} option is

Review Comment:
   Fixed in 6349eba — removed the leftover `deserializationFilter` mention from 
the `verifyConsumerDeserializationGuard()` Javadoc so it matches the guard code 
and the component/upgrade-guide docs. Good catch on the leftover from the first 
revision.
   
   _Claude Code on behalf of oscerd_
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to