Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.java.programmer > #40024
| From | Arne Vajhøj <arne@vajhoej.dk> |
|---|---|
| Newsgroups | comp.lang.java.programmer |
| Subject | Re: LDAP, .setReturningObjFlag(true) and alternatives... |
| Date | 2023-10-18 10:43 -0400 |
| Organization | A noiseless patient Spider |
| Message-ID | <ugoqu5$3msg8$1@dont-email.me> (permalink) |
| References | <slrnuiimne.9968.avl@logic.at> <ugbmum$38ehq$1@dont-email.me> <slrnuivq4v.1q3b.avl@logic.at> |
On 10/18/2023 10:15 AM, Andreas Leitgeb wrote: > Arne Vajhøj <arne@vajhoej.dk> wrote: >> So depending on security level you can: >> * decide that you trust LDAP and continue to automatic deserialize > yes, sure. > >> * continue to automatic deserialize but find a way to plugin >> a deserialization filter (assuming you are on Java 9+ where that >> was introduced) > > Ah, good to know - for future. Java 9+ docs should have the details. The short version is: -Djdk.serialFilter=mypackage.MyClass which should only allow this specific class to be deserialized. (there are a ton of other options) >> * drop the automatic deserialize and redesign the data transfer >> in some way: >> - instead of Java object have either JSON or XML and >> do a DOM tree parse not a binding to get the data over >> in a Java object >> - move the info from LDAP to somewhere else like database > > Not sure if I understand this correctly... is this a way to retrieve > the same data that is already stored in LDAP but in alternative formats, > or do you mean that the data in LDAP needs to be stored in those other > formats(e.g. json) for that to work? I am talking about being stored in a different format. It could solve the deserialization security problem. And I think there would be other benefits. Serialized Java objects and what happen if the class definition changes later is a big topic. Arne
Back to comp.lang.java.programmer | Previous | Next — Previous in thread | Find similar | Unroll thread
LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-13 14:57 +0000
Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-13 11:15 -0400
Re: LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-18 14:15 +0000
Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-18 10:43 -0400
csiph-web