Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.java.programmer > #40021
| From | Andreas Leitgeb <avl@logic.at> |
|---|---|
| Newsgroups | comp.lang.java.programmer |
| Subject | LDAP, .setReturningObjFlag(true) and alternatives... |
| Date | 2023-10-13 14:57 +0000 |
| Organization | A noiseless patient Spider |
| Message-ID | <slrnuiimne.9968.avl@logic.at> (permalink) |
I've stumbled over java code, that does an LDAP query, and sets flag .setReturningObjFlag(true) on the searchControl object. According to some ressources, like e.g. https://app.deepsource.com/directory/analyzers/java/issues/JAVA-S1026 this should be avoided, unless the LDAP server and its data is really trusted. I'd be curious, what would be the alternatives, under the assumption, that there are indeed serialized Objects stored in LDAP in whose value I'm really interested, and if I then didn't want to trust the server to always return data for the expected objects. According to description of setReturningObjFlag(): if this flag is false "... only the name and class of the object is returned", which to me sounds like I won't get the serialized data. Do I misunderstand it, or is there no third option besides: - trust the LDAP-server and have received data immediately deserialized - not trust the LDAP-server and just not get the data at all. Is there, maybe, a way to restrict the classes to a whitelist of classes that it may deserialize, and get an exception on any attempt to pull in any other class, before that other class is even initialized? Is there, maybe, a way to just retrieve the serialized stream and scrape the relevant info without full deserialization?
Back to comp.lang.java.programmer | Previous | Next — Next in thread | Find similar | Unroll thread
LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-13 14:57 +0000
Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-13 11:15 -0400
Re: LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-18 14:15 +0000
Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-18 10:43 -0400
csiph-web