Hathoute commented on PR #4962:
URL: 
https://github.com/apache/activemq-artemis/pull/4962#issuecomment-2155041259

   I do agree that this could be a bad idea, that's why I tried discussing it 
in the users mailbox. This PR is just an attempt I did before starting the 
discussion.
   
   I believe it is the responsibility of the broker admin to verify that a 
custom filter is trusted before adding it, just like plugins, with the only 
difference that filters can receive external user input. Now if the filter does 
not correctly validate its input, that's another issue...
   
   Also, existing filters (XPath for example) can also have a performance 
impact if not used correctly, yet any user is allowed to use them.
   
   Again, I agree it might not be a good idea to move forward if we are not 
being extremely careful with the implementation, and perfectly implementing 
this will probably take too much effort, which in the end won't be worth it.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact


Reply via email to