Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.java.programmer > #40024

Re: LDAP, .setReturningObjFlag(true) and alternatives...

Path csiph.com!news.mixmin.net!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From Arne Vajhøj <arne@vajhoej.dk>
Newsgroups comp.lang.java.programmer
Subject Re: LDAP, .setReturningObjFlag(true) and alternatives...
Date Wed, 18 Oct 2023 10:43:17 -0400
Organization A noiseless patient Spider
Lines 46
Message-ID <ugoqu5$3msg8$1@dont-email.me> (permalink)
References <slrnuiimne.9968.avl@logic.at> <ugbmum$38ehq$1@dont-email.me> <slrnuivq4v.1q3b.avl@logic.at>
MIME-Version 1.0
Content-Type text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding 8bit
Injection-Date Wed, 18 Oct 2023 14:43:18 -0000 (UTC)
Injection-Info dont-email.me; posting-host="84d47e0ae08b5bc06707cacaca74b78c"; logging-data="3895816"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX184/hV8ortDvUn1TETB26SC5SsO9wps/pM="
User-Agent Mozilla Thunderbird
Cancel-Lock sha1:RnbBbUCBznemNKEBpur0+4k+SrQ=
Content-Language en-US
In-Reply-To <slrnuivq4v.1q3b.avl@logic.at>
Xref csiph.com comp.lang.java.programmer:40024

Show key headers only | View raw


On 10/18/2023 10:15 AM, Andreas Leitgeb wrote:
> Arne Vajhøj <arne@vajhoej.dk> wrote:
>> So depending on security level you can:
>> * decide that you trust LDAP and continue to automatic deserialize
> yes, sure.
> 
>> * continue to automatic deserialize but find a way to plugin
>>     a deserialization filter (assuming you are on Java 9+ where that
>>     was introduced)
> 
> Ah, good to know - for future.

Java 9+ docs should have the details.

The short version is:

-Djdk.serialFilter=mypackage.MyClass

which should only allow this specific class to be deserialized.

(there are a ton of other options)

>> * drop the automatic deserialize and redesign the data transfer
>>     in some way:
>>       - instead of Java object have either JSON or XML and
>>         do a DOM tree parse not a binding to get the data over
>>         in a Java object
>>       - move the info from LDAP to somewhere else like database
> 
> Not sure if I understand this correctly...   is this a way to retrieve
> the same data that is already stored in LDAP but in alternative formats,
> or do you mean that the data in LDAP needs to be stored in those other
> formats(e.g. json) for that to work?

I am talking about being stored in a different format.

It could solve the deserialization security problem.

And I think there would be other benefits.

Serialized Java objects and what happen if the class
definition changes later is a big topic.

Arne

Back to comp.lang.java.programmer | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-13 14:57 +0000
  Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-13 11:15 -0400
    Re: LDAP, .setReturningObjFlag(true) and alternatives... Andreas Leitgeb <avl@logic.at> - 2023-10-18 14:15 +0000
      Re: LDAP, .setReturningObjFlag(true) and alternatives... Arne Vajhøj <arne@vajhoej.dk> - 2023-10-18 10:43 -0400

csiph-web