[
https://issues.apache.org/jira/browse/CAMEL-24421?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino resolved CAMEL-24421.
--------------------------------------
Resolution: Fixed
> camel-spring-redis: apply a configurable ObjectInputFilter to the default JDK
> serializer
> ----------------------------------------------------------------------------------------
>
> Key: CAMEL-24421
> URL: https://issues.apache.org/jira/browse/CAMEL-24421
> Project: Camel
> Issue Type: Improvement
> Components: camel-spring-redis
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.22.1, 4.23.0, 4.18.5
>
>
> camel-spring-redis builds JdkSerializationRedisSerializer as its default
> serializer in RedisConfiguration.createDefaultSerializer(). Unlike the other
> Camel components that perform JDK deserialization -- camel-consul,
> camel-leveldb, camel-mina, camel-netty, camel-netty-http, camel-vertx-http,
> camel-jms, camel-sjms, camel-http-common, camel-cassandraql -- this path
> installs no ObjectInputFilter, so it does not participate in the filtering
> the rest of the codebase applies.
> Bring it in line with the rest of the codebase:
> * Add a "deserializationFilter" option (label advanced,security) with the
> standard default pattern.
> * Apply it to the serializer used by RedisConsumer.setBody().
> * Apply it to the default template built in
> RedisConfiguration.createDefaultTemplate(), and therefore to
> SpringRedisIdempotentRepository, which shares that template.
> Implementation note: JdkSerializationRedisSerializer exposes no filter hook.
> Use its (Converter<Object,byte[]>, Converter<byte[],Object>) constructor with
> a filtering deserializer, or a Camel-owned RedisSerializer.
> Note that setting a custom redisTemplate does not currently affect the
> consumer, which reads getSerializer() directly -- the option needs to cover
> both paths.
> Affected branches: main (4.23.0), camel-4.22.x, camel-4.18.x, camel-4.14.x.
> On 4.18.x and 4.14.x, DeserializationFilterHelper does not exist; follow the
> local-constant pattern already used there by NettyHttpHelper, JmsBinding and
> MinaConverter.
> This changes a default, so it needs an upgrade-guide entry on main.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)