Andrea Cosentino created CAMEL-25229:
----------------------------------------
Summary: camel-hazelcast: serialization filter docs and WARN for
user-supplied configs
Key: CAMEL-25229
URL: https://issues.apache.org/jira/browse/CAMEL-25229
Project: Camel
Issue Type: Improvement
Components: camel-hazelcast
Reporter: Andrea Cosentino
Assignee: Andrea Cosentino
Follow-up to CAMEL-23414.
Camel applies a default {{JavaSerializationFilterConfig}} (allow-list
{{java.}}, {{javax.}}, {{org.apache.camel.}}; deny-list {{java.net.}}) only to
the Hazelcast configurations it builds itself. A configuration supplied by the
user is used unchanged, by design:
* a {{Config}} / {{ClientConfig}} bean passed as {{hazelcastConfig}}
* a {{hazelcastConfigUri}}
* a pre-built {{hazelcastInstance}}, or one looked up by
{{hazelcastInstanceName}}
The Java serialization settings of such an instance are whatever the user's
configuration declares. Hazelcast's own default configurations
({{hazelcast-default.xml}}, {{hazelcast-client-default.xml}}) declare no
{{<java-serialization-filter>}}, so a configuration based on them has no filter
unless the user adds one.
Today this is described only in the 4.18 and 4.21 upgrade guides. The
camel-hazelcast component pages do not mention the serialization filter, and
nothing at runtime tells users that the configuration they supplied has none.
h3. Proposed changes
# *Documentation*
({{components/camel-hazelcast/src/main/docs/hazelcast-summary.adoc}}): add a
section explaining which instances get Camel's default filter (the ones Camel
creates itself) and which do not (anything the user supplies). Show how to
declare a {{JavaSerializationFilterConfig}} that covers the application's own
classes, in XML and in Java, and mention the JVM-wide {{-Djdk.serialFilter}}
alternative.
# *Runtime WARN* ({{HazelcastDefaultComponent#getOrCreateHzInstance}} and
{{#getOrCreateHzClientInstance}}): when Camel starts a member or client from a
user-supplied {{Config}} / {{ClientConfig}} (bean or {{hazelcastConfigUri}})
whose {{SerializationConfig}} has no {{JavaSerializationFilterConfig}}, log a
WARN pointing to the new documentation section. The user's configuration is not
modified.
# *Tests*: the WARN is logged for a user-supplied configuration without a
filter, and is not logged when one is declared.
h3. Out of scope
Applying Camel's default filter to user-supplied configurations. Every
application class outside the default allow-list would become unreadable, so
that change would need its own discussion and an upgrade-guide entry.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)