Path: csiph.com!news.mixmin.net!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail From: =?UTF-8?Q?Arne_Vajh=C3=B8j?= Newsgroups: comp.lang.java.programmer Subject: Re: LDAP, .setReturningObjFlag(true) and alternatives... Date: Wed, 18 Oct 2023 10:43:17 -0400 Organization: A noiseless patient Spider Lines: 46 Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Injection-Date: Wed, 18 Oct 2023 14:43:18 -0000 (UTC) Injection-Info: dont-email.me; posting-host="84d47e0ae08b5bc06707cacaca74b78c"; logging-data="3895816"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX184/hV8ortDvUn1TETB26SC5SsO9wps/pM=" User-Agent: Mozilla Thunderbird Cancel-Lock: sha1:RnbBbUCBznemNKEBpur0+4k+SrQ= Content-Language: en-US In-Reply-To: Xref: csiph.com comp.lang.java.programmer:40024 On 10/18/2023 10:15 AM, Andreas Leitgeb wrote: > Arne Vajhøj wrote: >> So depending on security level you can: >> * decide that you trust LDAP and continue to automatic deserialize > yes, sure. > >> * continue to automatic deserialize but find a way to plugin >> a deserialization filter (assuming you are on Java 9+ where that >> was introduced) > > Ah, good to know - for future. Java 9+ docs should have the details. The short version is: -Djdk.serialFilter=mypackage.MyClass which should only allow this specific class to be deserialized. (there are a ton of other options) >> * drop the automatic deserialize and redesign the data transfer >> in some way: >> - instead of Java object have either JSON or XML and >> do a DOM tree parse not a binding to get the data over >> in a Java object >> - move the info from LDAP to somewhere else like database > > Not sure if I understand this correctly... is this a way to retrieve > the same data that is already stored in LDAP but in alternative formats, > or do you mean that the data in LDAP needs to be stored in those other > formats(e.g. json) for that to work? I am talking about being stored in a different format. It could solve the deserialization security problem. And I think there would be other benefits. Serialized Java objects and what happen if the class definition changes later is a big topic. Arne