Andrea Cosentino created CAMEL-25229:
----------------------------------------

             Summary: camel-hazelcast: serialization filter docs and WARN for 
user-supplied configs
                 Key: CAMEL-25229
                 URL: https://issues.apache.org/jira/browse/CAMEL-25229
             Project: Camel
          Issue Type: Improvement
          Components: camel-hazelcast
            Reporter: Andrea Cosentino
            Assignee: Andrea Cosentino


Follow-up to CAMEL-23414.

Camel applies a default {{JavaSerializationFilterConfig}} (allow-list 
{{java.}}, {{javax.}}, {{org.apache.camel.}}; deny-list {{java.net.}}) only to 
the Hazelcast configurations it builds itself. A configuration supplied by the 
user is used unchanged, by design:
* a {{Config}} / {{ClientConfig}} bean passed as {{hazelcastConfig}}
* a {{hazelcastConfigUri}}
* a pre-built {{hazelcastInstance}}, or one looked up by 
{{hazelcastInstanceName}}

The Java serialization settings of such an instance are whatever the user's 
configuration declares. Hazelcast's own default configurations 
({{hazelcast-default.xml}}, {{hazelcast-client-default.xml}}) declare no 
{{<java-serialization-filter>}}, so a configuration based on them has no filter 
unless the user adds one.

Today this is described only in the 4.18 and 4.21 upgrade guides. The 
camel-hazelcast component pages do not mention the serialization filter, and 
nothing at runtime tells users that the configuration they supplied has none.

h3. Proposed changes

# *Documentation* 
({{components/camel-hazelcast/src/main/docs/hazelcast-summary.adoc}}): add a 
section explaining which instances get Camel's default filter (the ones Camel 
creates itself) and which do not (anything the user supplies). Show how to 
declare a {{JavaSerializationFilterConfig}} that covers the application's own 
classes, in XML and in Java, and mention the JVM-wide {{-Djdk.serialFilter}} 
alternative.
# *Runtime WARN* ({{HazelcastDefaultComponent#getOrCreateHzInstance}} and 
{{#getOrCreateHzClientInstance}}): when Camel starts a member or client from a 
user-supplied {{Config}} / {{ClientConfig}} (bean or {{hazelcastConfigUri}}) 
whose {{SerializationConfig}} has no {{JavaSerializationFilterConfig}}, log a 
WARN pointing to the new documentation section. The user's configuration is not 
modified.
# *Tests*: the WARN is logged for a user-supplied configuration without a 
filter, and is not logged when one is declared.

h3. Out of scope

Applying Camel's default filter to user-supplied configurations. Every 
application class outside the default allow-list would become unreadable, so 
that change would need its own discussion and an upgrade-guide entry.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to