[
https://issues.apache.org/jira/browse/ARTEMIS-4167?focusedWorklogId=939552&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-939552
]
ASF GitHub Bot logged work on ARTEMIS-4167:
-------------------------------------------
Author: ASF GitHub Bot
Created on: 22/Oct/24 17:49
Start Date: 22/Oct/24 17:49
Worklog Time Spent: 10m
Work Description: swerner0 commented on code in PR #5307:
URL: https://github.com/apache/activemq-artemis/pull/5307#discussion_r1811148933
##########
docs/user-manual/security.adoc:
##########
@@ -1431,6 +1431,16 @@ comma separated values for allow list
These properties, once specified, are eventually set on the corresponding
internal factories.
+=== Filtering using built-in JVM support
+
+Now that Apache ActiveMQ Artemis requires a minimum JVM version of 11,
built-in Java serialization filtering mechanisms can be utilized.
+Instead of providing an `allow list` or `deny list`, you can specify either a
`serialFilter` or `serialFilterClassName`.
+
+* `serialFilter` - A pattern based filter that allows you to define allow/deny
lists and constraints limiting graph complexity and size.
https://docs.oracle.com/en/java/javase/17/core/serialization-filtering1.html#JSCOR-GUID-8296D8E8-2B93-4B9A-856E-0A65AF9B8C66[Filter
Syntax]
+* `serialFilterClassName` - For those who need a custom filtering solution,
you can supply an implementation of
https://docs.oracle.com/en/java/javase/17/docs/api/java.base/java/io/ObjectInputFilter.html[ObjectInputFilter]
Review Comment:
Do you want to continue to support the allow/denyList and custom
inputstream? We can say they are deprecated in favor of the new at some point,
and list an order of execution if both are specified, although that would be
frowned upon
Issue Time Tracking
-------------------
Worklog Id: (was: 939552)
Time Spent: 4h (was: 3h 50m)
> Enhance deserialization filter beyond black/whitelist functionality
> -------------------------------------------------------------------
>
> Key: ARTEMIS-4167
> URL: https://issues.apache.org/jira/browse/ARTEMIS-4167
> Project: ActiveMQ Artemis
> Issue Type: New Feature
> Reporter: Scott Werner
> Priority: Minor
> Labels: pull-request-available
> Time Spent: 4h
> Remaining Estimate: 0h
>
> Now that Artemis is Java 11+ compatible, there is now the ability to set an
> ObjectInputFilter on an ObjectInputStream. There are also built in methods to
> generate filters similar to the current syntax and offers many other features
> out of the box. A global jvm property (jdk.serialFilter) can be set, but this
> is quite restrictive. I suggest adding a new serial filter pattern and class
> name of an ObjectInputFilter implementation, everywhere blacklist/whitelist
> exist today. In time we can look into converting the existing black/whitelist
> to the new format or just deprecating as the semantics are a bit different
> and may not be able to make it 100% compatible.
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact