I think it's better to use standard API.
see Java Serialization Filters
|
protected Class<?> resolveClass(ObjectStreamClass classDesc) throws IOException, ClassNotFoundException { |
|
Class<?> clazz = super.resolveClass(classDesc); |
|
checkAllowedList(clazz); |
|
return clazz; |
|
} |
|
protected Class<?> resolveClass(ObjectStreamClass classDesc) |
|
throws IOException, ClassNotFoundException { |
|
Class<?> clazz = super.resolveClass(classDesc); |
|
checkAllowedList(clazz); |
|
return clazz; |
|
} |
I think it's better to use standard API.
see Java Serialization Filters
spring-amqp/spring-amqp/src/main/java/org/springframework/amqp/support/converter/SimpleMessageConverter.java
Lines 158 to 162 in 603e6c8
spring-amqp/spring-amqp/src/main/java/org/springframework/amqp/support/converter/SerializerMessageConverter.java
Lines 167 to 172 in 603e6c8