Class SerializingHttpMessageConverter

java.lang.Object
org.springframework.http.converter.AbstractHttpMessageConverter<Serializable>
org.springframework.integration.http.converter.SerializingHttpMessageConverter
All Implemented Interfaces:
HttpMessageConverter<Serializable>

public class SerializingHttpMessageConverter extends AbstractHttpMessageConverter<Serializable>
An HttpMessageConverter implementation for Serializable instances.

Incoming requests are deserialized through an AllowListDeserializingConverter. To guard against unsafe Java deserialization, the patterns of trusted classes/packages are provided via the SerializingHttpMessageConverter(String...) constructor and can be extended with addAllowedPatterns(String...). For backward compatibility, no class restriction is applied when the deprecated default constructor is used and no patterns are configured.

Since:
2.0
Author:
Mark Fisher, Gary Russell, Artem Bilan, Uwez Khan, Hyun Lee