[ 
https://issues.apache.org/jira/browse/CAMEL-25223?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on CAMEL-25223 started by Andrea Cosentino.
------------------------------------------------
> camel-jgroups: fail fast (or require explicit opt-in) when the consumer has 
> no pre-read deserialization control on the default channel
> --------------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25223
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25223
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-jgroups
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> Follow-up / hardening on top of CAMEL-24676.
> CAMEL-24676 added a {{deserializationFilter}} option and a default, post-read 
> class check in the camel-jgroups consumer, documented as defense-in-depth. 
> The controls that actually take effect *before* JGroups reads the object are 
> a JVM-wide {{-Djdk.serialFilter}}, the JGroups-native 
> {{jgroups.deserialization.filter}} system property (JGroups 5.5.x+), or a 
> channel configured with authentication/encryption.
> With the default channel ({{new JChannel()}}, i.e. no {{channelProperties}}) 
> and none of those configured, the consumer starts silently with no pre-read 
> control in place and no signal to the operator.
> Proposal: on consumer start, detect whether any pre-read control is in effect 
> - the {{deserializationFilter}} option, a JVM-wide filter 
> ({{ObjectInputFilter.Config.getSerialFilter()}}), the 
> {{jgroups.deserialization.filter}} property, or an authenticated/encrypted 
> channel. When none is, either fail to start with a clear message pointing at 
> the component Security section, or require an explicit opt-in option to keep 
> the current permissive behaviour (mirroring how camel-jms gates object 
> messages).
> Document the new behaviour and the {{jgroups.deserialization.filter}} 
> property in the component Security section and the upgrade guide (changed 
> default / new option).
> Touch points:
> - components/camel-jgroups/.../JGroupsEndpoint.java (doStart)
> - components/camel-jgroups/.../JGroupsComponent.java (new option)
> - components/camel-jgroups/src/main/docs/jgroups-component.adoc (+ matching 
> upgrade-guide entry on main)
> Continues the serialization-hardening consistency work (CAMEL-24676; shared 
> DeserializationFilterHelper from CAMEL-23815 / CAMEL-24296).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to