Class SerializingHttpMessageConverter
java.lang.Object
org.springframework.http.converter.AbstractHttpMessageConverter<Serializable>
org.springframework.integration.http.converter.SerializingHttpMessageConverter
- All Implemented Interfaces:
HttpMessageConverter<Serializable>
An
HttpMessageConverter implementation for
Serializable instances.
Incoming requests are deserialized through an AllowListDeserializingConverter.
To guard against unsafe Java deserialization, the patterns of trusted classes/packages
are provided via the SerializingHttpMessageConverter(String...) constructor
and can be extended with addAllowedPatterns(String...).
For backward compatibility, no class restriction is applied when the deprecated default
constructor is used and no patterns are configured.
- Since:
- 2.0
- Author:
- Mark Fisher, Gary Russell, Artem Bilan, Uwez Khan, Hyun Lee
-
Field Summary
Fields inherited from class org.springframework.http.converter.AbstractHttpMessageConverter
logger -
Constructor Summary
ConstructorsConstructorDescriptionDeprecated, for removal: This API element is subject to removal in a future version.SerializingHttpMessageConverter(String... allowedPatterns) Create a new instance with simple patterns for allowable packages/classes for deserialization. -
Method Summary
Modifier and TypeMethodDescriptionvoidaddAllowedPatterns(String... allowedPatterns) Add package/class patterns to the allowed list.booleanreadInternal(Class<? extends Serializable> clazz, HttpInputMessage inputMessage) voidsetAllowedPatterns(String... allowedPatterns) Deprecated, for removal: This API element is subject to removal in a future version.Since 7.2 in favor ofSerializingHttpMessageConverter(String...).booleanprotected voidwriteInternal(Serializable object, HttpOutputMessage outputMessage) Methods inherited from class org.springframework.http.converter.AbstractHttpMessageConverter
addDefaultHeaders, canRead, canRead, canWrite, getContentLength, getDefaultCharset, getDefaultContentType, getSupportedMediaTypes, read, setDefaultCharset, setSupportedMediaTypes, supportsRepeatableWrites, writeMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.springframework.http.converter.HttpMessageConverter
canWriteRepeatedly, getSupportedMediaTypes
-
Constructor Details
-
SerializingHttpMessageConverter
Deprecated, for removal: This API element is subject to removal in a future version.Since 7.2 in favor ofSerializingHttpMessageConverter(String...)with an explicit list of allowed patterns.Creates a new instance of theSerializingHttpMessageConverter. -
SerializingHttpMessageConverter
Create a new instance with simple patterns for allowable packages/classes for deserialization. The patterns will be applied in order until a match is found. A class can be fully qualified, or a wildcard'*'is allowed at the beginning or end of the class name. Examples:com.example.*,*.MyClass. The basic types (String,Number, arrays and primitives) are always allowed.- Parameters:
allowedPatterns- the patterns; must not be empty.- Since:
- 7.2
-
-
Method Details
-
setAllowedPatterns
Deprecated, for removal: This API element is subject to removal in a future version.Since 7.2 in favor ofSerializingHttpMessageConverter(String...).Set simple patterns for allowable packages/classes for deserialization. The patterns will be applied in order until a match is found. A class can be fully qualified, or a wildcard'*'is allowed at the beginning or end of the class name. Examples:com.foo.*,*.MyClass. The basic types (String,Number, arrays and primitives) are always allowed. When no patterns are configured, all classes are deserialized (the previous, unrestricted behavior).- Parameters:
allowedPatterns- the patterns.- Since:
- 5.5.22
-
addAllowedPatterns
Add package/class patterns to the allowed list.- Parameters:
allowedPatterns- the patterns to add.- Since:
- 5.5.22
- See Also:
-
supports
- Specified by:
supportsin classAbstractHttpMessageConverter<Serializable>
-
canWrite
- Specified by:
canWritein interfaceHttpMessageConverter<Serializable>- Overrides:
canWritein classAbstractHttpMessageConverter<Serializable>
-
readInternal
public Serializable readInternal(Class<? extends Serializable> clazz, HttpInputMessage inputMessage) throws IOException - Specified by:
readInternalin classAbstractHttpMessageConverter<Serializable>- Throws:
IOException
-
writeInternal
protected void writeInternal(Serializable object, HttpOutputMessage outputMessage) throws IOException - Specified by:
writeInternalin classAbstractHttpMessageConverter<Serializable>- Throws:
IOException
-
SerializingHttpMessageConverter(String...)with an explicit list of allowed patterns.