GitHub user zonghaishang created a discussion: [General][Dubbo] 序列化安全校验
### Pre-check - [X] I am sure that all the content I provide is in English. ### Apache Dubbo Component Java SDK (apache/dubbo) ### Details using dubbo path: https://github.com/apache/dubbo/blob/3a3043227f5571d25eb2889de5bca22f2914843b/dubbo-rpc/dubbo-rpc-dubbo/src/main/java/org/apache/dubbo/rpc/protocol/dubbo/DecodeableRpcInvocation.java#L146 using dubbo interface: https://github.com/apache/dubbo/blob/3a3043227f5571d25eb2889de5bca22f2914843b/dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/protocol/PermittedSerializationKeeper.java#L41 dubbo path may not same with interface, maybe throw exception: ``` ClassLoader originClassLoader = Thread.currentThread().getContextClassLoader(); try { if (CHECK_SERIALIZATION) { PermittedSerializationKeeper keeper = frameworkModel.getBeanFactory().getBean(PermittedSerializationKeeper.class); if (!keeper.checkSerializationPermitted(keyWithoutGroup, serializationType)) { throw new IOException("Unexpected serialization id:" + serializationType + " received from network, please check if the peer send the right id."); } } ``` ### Code of Conduct - [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct) GitHub link: https://github.com/apache/dubbo/discussions/16422 ---- This is an automatically sent email for [email protected]. To unsubscribe, please send an email to: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
