[ https://issues.apache.org/jira/browse/ARTEMIS-4167?focusedWorklogId=903940&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-903940 ]
ASF GitHub Bot logged work on ARTEMIS-4167: ------------------------------------------- Author: ASF GitHub Bot Created on: 06/Feb/24 18:55 Start Date: 06/Feb/24 18:55 Worklog Time Spent: 10m Work Description: jbertram commented on PR #4368: URL: https://github.com/apache/activemq-artemis/pull/4368#issuecomment-1930565717 FWIW, you can update your branch, push -f, and then re-open this PR when you're ready. Issue Time Tracking ------------------- Worklog Id: (was: 903940) Time Spent: 2h 20m (was: 2h 10m) > Enhance deserialization filter beyond black/whitelist functionality > ------------------------------------------------------------------- > > Key: ARTEMIS-4167 > URL: https://issues.apache.org/jira/browse/ARTEMIS-4167 > Project: ActiveMQ Artemis > Issue Type: New Feature > Reporter: Scott Werner > Priority: Minor > Time Spent: 2h 20m > Remaining Estimate: 0h > > Now that Artemis is Java 11+ compatible, there is now the ability to set an > ObjectInputFilter on an ObjectInputStream. There are also built in methods to > generate filters similar to the current syntax and offers many other features > out of the box. A global jvm property (jdk.serialFilter) can be set, but this > is quite restrictive. I suggest adding a new serial filter pattern and class > name of an ObjectInputFilter implementation, everywhere blacklist/whitelist > exist today. In time we can look into converting the existing black/whitelist > to the new format or just deprecating as the semantics are a bit different > and may not be able to make it 100% compatible. > -- This message was sent by Atlassian Jira (v8.20.10#820010)