Part 5 extra: the three discriminator failure modes
This commit is contained in:
@@ -0,0 +1,36 @@
|
|||||||
|
package com.ankurm.jackson3.part5polymorphic;
|
||||||
|
|
||||||
|
import tools.jackson.databind.json.JsonMapper;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* BEYOND THE POST — what actually happens when the discriminator is wrong.
|
||||||
|
*
|
||||||
|
* The security post asserts that an unregistered type name throws
|
||||||
|
* InvalidTypeIdException. This runs the three failure modes so the exception types
|
||||||
|
* are on the record rather than assumed: unknown name, attacker-supplied class name,
|
||||||
|
* and a missing discriminator.
|
||||||
|
*/
|
||||||
|
public class F04UnknownTypeId {
|
||||||
|
|
||||||
|
public static void main(String[] args) {
|
||||||
|
JsonMapper mapper = JsonMapper.builder().build();
|
||||||
|
|
||||||
|
attempt(mapper, "unknown logical name",
|
||||||
|
"{\"paymentType\":\"crypto\",\"paymentId\":9,\"amountDue\":1.0}");
|
||||||
|
|
||||||
|
attempt(mapper, "attacker-supplied class name",
|
||||||
|
"{\"paymentType\":\"com.malicious.Gadget\",\"paymentId\":9,\"amountDue\":1.0}");
|
||||||
|
|
||||||
|
attempt(mapper, "missing discriminator",
|
||||||
|
"{\"paymentId\":9,\"amountDue\":1.0}");
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void attempt(JsonMapper mapper, String label, String json) {
|
||||||
|
try {
|
||||||
|
PaymentMethod result = mapper.readValue(json, PaymentMethod.class);
|
||||||
|
System.out.printf("%-30s -> UNEXPECTEDLY OK: %s%n", label, result);
|
||||||
|
} catch (Exception e) {
|
||||||
|
System.out.printf("%-30s -> %s%n", label, e.getClass().getSimpleName());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user