ramanathan1504 commented on PR #4271:
URL: https://github.com/apache/logging-log4j2/pull/4271#issuecomment-5909387783
@ppkarwasz
The write side now degrades to keep the event, but the read side throws the
whole event away. `testJavaIoSerializableWithClassNotOnAllowlist` locks that
in: one
`ObjectMessage` holding a `java.net.URI` and the record is gone,
timestamp, level and formatted message with it. Any application object behaves
the same, the allowlist is
only the four prefixes.
`LogEventProxy` still writes `messageString` and `message()` still falls
back to `new SimpleMessage(messageString)`, so the degrade path is there and
the rethrow makes it
unreachable. Was losing the whole event the intent, or only for corrupted
data?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]