# The @class property is input: the allow-list decides what it may name --- A class outside the allow-list --- $ redis-cli -p 6390 SET user:evil '{"@class":"com.ankurm.other.Outsider","name":"x"}' OK jsonTemplate.opsForValue().get("user:evil") org.springframework.data.redis.serializer.SerializationException message: Could not read JSON: Could not resolve type id 'com.ankurm.other.Outsider' as a subtype of `com.ankurm.other.Outsider`: Configured `PolymorphicTypeValidator` (of type `tools.jackson.databind.jsontype.BasicPolymorphicTypeValidator`) denied resolution --- A class inside the allow-list that no longer exists --- $ redis-cli -p 6390 SET user:gone '{"@class":"com.ankurm.redis.model.Gone","id":9}' OK jsonTemplate.opsForValue().get("user:gone") org.springframework.data.redis.serializer.SerializationException message: Could not read JSON: Failed to parse type 'com.ankurm.redis.model.Gone' (remaining: ''): Cannot locate class 'com.ankurm.redis.model.Gone', problem: com.ankurm.redis.model.Gone