Part 7: reflective proof of which mapper mutators survived into Jackson 3
This commit is contained in:
@@ -0,0 +1,52 @@
|
|||||||
|
package com.ankurm.jackson3.part7security;
|
||||||
|
|
||||||
|
import tools.jackson.databind.ObjectMapper;
|
||||||
|
import tools.jackson.databind.json.JsonMapper;
|
||||||
|
|
||||||
|
import java.lang.reflect.Method;
|
||||||
|
import java.util.Arrays;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Post: Jackson Security Best Practices — https://ankurm.com/jackson-security-best-practices/
|
||||||
|
* Section: "The Safe Alternative: PolymorphicTypeValidator"
|
||||||
|
*
|
||||||
|
* CORRECTION TO THE POST. The post shows the remediation as
|
||||||
|
*
|
||||||
|
* ObjectMapper mapper = new ObjectMapper();
|
||||||
|
* mapper.activateDefaultTyping(validator, DefaultTyping.NON_FINAL, As.PROPERTY);
|
||||||
|
*
|
||||||
|
* That is Jackson 2 code. In Jackson 3 BOTH enableDefaultTyping and
|
||||||
|
* activateDefaultTyping are absent from the mapper — the mapper has no mutators at
|
||||||
|
* all. activateDefaultTyping survives only on JsonMapper.Builder. This prints the
|
||||||
|
* reflective proof for each claim rather than asserting it.
|
||||||
|
*
|
||||||
|
* See H03PolymorphicTypeValidatorAllowlist for the working builder-based form.
|
||||||
|
*/
|
||||||
|
public class H02DefaultTypingRemoved {
|
||||||
|
|
||||||
|
public static void main(String[] args) {
|
||||||
|
System.out.println("--- tools.jackson.databind.ObjectMapper ---");
|
||||||
|
report(ObjectMapper.class, "enableDefaultTyping");
|
||||||
|
report(ObjectMapper.class, "activateDefaultTyping");
|
||||||
|
report(ObjectMapper.class, "setSerializationInclusion");
|
||||||
|
report(ObjectMapper.class, "registerModule");
|
||||||
|
report(ObjectMapper.class, "addMixIn");
|
||||||
|
System.out.println("total set*() mutators: " + Arrays.stream(ObjectMapper.class.getMethods())
|
||||||
|
.filter(m -> m.getName().startsWith("set")).count());
|
||||||
|
|
||||||
|
System.out.println();
|
||||||
|
System.out.println("--- tools.jackson.databind.json.JsonMapper.Builder ---");
|
||||||
|
report(JsonMapper.Builder.class, "activateDefaultTyping");
|
||||||
|
report(JsonMapper.Builder.class, "deactivateDefaultTyping");
|
||||||
|
report(JsonMapper.Builder.class, "polymorphicTypeValidator");
|
||||||
|
report(JsonMapper.Builder.class, "changeDefaultPropertyInclusion");
|
||||||
|
report(JsonMapper.Builder.class, "serializationInclusion");
|
||||||
|
}
|
||||||
|
|
||||||
|
private static void report(Class<?> type, String methodName) {
|
||||||
|
boolean present = Arrays.stream(type.getMethods())
|
||||||
|
.map(Method::getName)
|
||||||
|
.anyMatch(methodName::equals);
|
||||||
|
System.out.printf(" %-32s %s%n", methodName, present ? "present" : "ABSENT");
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user