[ 
https://issues.apache.org/jira/browse/ARTEMIS-4167?focusedWorklogId=903940&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-903940
 ]

ASF GitHub Bot logged work on ARTEMIS-4167:
-------------------------------------------

                Author: ASF GitHub Bot
            Created on: 06/Feb/24 18:55
            Start Date: 06/Feb/24 18:55
    Worklog Time Spent: 10m 
      Work Description: jbertram commented on PR #4368:
URL: 
https://github.com/apache/activemq-artemis/pull/4368#issuecomment-1930565717

   FWIW, you can update your branch, push -f, and then re-open this PR when 
you're ready.




Issue Time Tracking
-------------------

    Worklog Id:     (was: 903940)
    Time Spent: 2h 20m  (was: 2h 10m)

> Enhance deserialization filter beyond black/whitelist functionality
> -------------------------------------------------------------------
>
>                 Key: ARTEMIS-4167
>                 URL: https://issues.apache.org/jira/browse/ARTEMIS-4167
>             Project: ActiveMQ Artemis
>          Issue Type: New Feature
>            Reporter: Scott Werner
>            Priority: Minor
>          Time Spent: 2h 20m
>  Remaining Estimate: 0h
>
> Now that Artemis is Java 11+ compatible, there is now the ability to set an 
> ObjectInputFilter on an ObjectInputStream. There are also built in methods to 
> generate filters similar to the current syntax and offers many other features 
> out of the box. A global jvm property (jdk.serialFilter) can be set, but this 
> is quite restrictive. I suggest adding a new serial filter pattern and class 
> name of an ObjectInputFilter implementation, everywhere blacklist/whitelist 
> exist today. In time we can look into converting the existing black/whitelist 
> to the new format or just deprecating as the semantics are a bit different 
> and may not be able to make it 100% compatible.
>  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to