[
https://issues.apache.org/jira/browse/ARTEMIS-4167?focusedWorklogId=939654&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-939654
]
ASF GitHub Bot logged work on ARTEMIS-4167:
-------------------------------------------
Author: ASF GitHub Bot
Created on: 23/Oct/24 08:50
Start Date: 23/Oct/24 08:50
Worklog Time Spent: 10m
Work Description: gemmellr commented on code in PR #5307:
URL: https://github.com/apache/activemq-artemis/pull/5307#discussion_r1812237786
##########
docs/user-manual/security.adoc:
##########
@@ -1431,6 +1431,16 @@ comma separated values for allow list
These properties, once specified, are eventually set on the corresponding
internal factories.
+=== Filtering using built-in JVM support
+
+Now that Apache ActiveMQ Artemis requires a minimum JVM version of 11,
built-in Java serialization filtering mechanisms can be utilized.
+Instead of providing an `allow list` or `deny list`, you can specify either a
`serialFilter` or `serialFilterClassName`.
+
+* `serialFilter` - A pattern based filter that allows you to define allow/deny
lists and constraints limiting graph complexity and size.
https://docs.oracle.com/en/java/javase/17/core/serialization-filtering1.html#JSCOR-GUID-8296D8E8-2B93-4B9A-856E-0A65AF9B8C66[Filter
Syntax]
+* `serialFilterClassName` - For those who need a custom filtering solution,
you can supply an implementation of
https://docs.oracle.com/en/java/javase/17/docs/api/java.base/java/io/ObjectInputFilter.html[ObjectInputFilter]
Review Comment:
Regardless how quickly we were to remove the old one, both will be there
until then and so what it does or allows / not should be clear and documented.
Its not even clear currently what would happen between the 2 new options, or
their system properties, let alone once you consider any mix with the older
existing stuff.
Even if we deprecate the old, I dont see us removing the old bits
particularly quickly (or ever for 2.x) given it is all anyone has ever used,
and in many cases will likely continue to use right up until it goes away. We
also just deprecated the original names to replace with allow/deny, so would
seems especially unfair to then quickly _require_ another update for the same
functionality for anyone that did already adapt to that.
Issue Time Tracking
-------------------
Worklog Id: (was: 939654)
Time Spent: 4h 10m (was: 4h)
> Enhance deserialization filter beyond black/whitelist functionality
> -------------------------------------------------------------------
>
> Key: ARTEMIS-4167
> URL: https://issues.apache.org/jira/browse/ARTEMIS-4167
> Project: ActiveMQ Artemis
> Issue Type: New Feature
> Reporter: Scott Werner
> Priority: Minor
> Labels: pull-request-available
> Time Spent: 4h 10m
> Remaining Estimate: 0h
>
> Now that Artemis is Java 11+ compatible, there is now the ability to set an
> ObjectInputFilter on an ObjectInputStream. There are also built in methods to
> generate filters similar to the current syntax and offers many other features
> out of the box. A global jvm property (jdk.serialFilter) can be set, but this
> is quite restrictive. I suggest adding a new serial filter pattern and class
> name of an ObjectInputFilter implementation, everywhere blacklist/whitelist
> exist today. In time we can look into converting the existing black/whitelist
> to the new format or just deprecating as the semantics are a bit different
> and may not be able to make it 100% compatible.
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact