Class RegexAllowListChecker

java.lang.Object
com.broadleafcommerce.common.extension.serialization.RegexAllowListChecker
All Implemented Interfaces:
org.apache.fory.resolver.TypeChecker

@ThreadSafe public class RegexAllowListChecker extends Object implements org.apache.fory.resolver.TypeChecker
Custom TypeChecker that supports advanced wildcards (intermediate and suffix '*') by converting them to regular expressions.

This implementation includes an internal cache for resolved class names to ensure O(1) performance after the initial regex match.

  • Constructor Details

  • Method Details

    • checkType

      public boolean checkType(org.apache.fory.resolver.TypeResolver typeResolver, String className)
      Specified by:
      checkType in interface org.apache.fory.resolver.TypeChecker
    • reportIfWithoutPackage

      protected void reportIfWithoutPackage(String className)
      Logs, once per distinct name, any class whose name contains no '.' and therefore has no package.

      Two shapes qualify: classes in the unnamed package, and multi-dimensional primitive arrays such as [[I and [[B, whose names contain no dot either. One-dimensional primitive arrays do not - they are pre-registered and written by class id.

      On Fury 0.10.x such a class was written by name with an empty package meta-string that resolved to a JVM-global singleton carrying a mutable write id. Pooled writers raced on it and could emit a back-reference their own stream never defined, producing cache entries that failed every subsequent read. Fory 1.6.0 removes that shared state - MetaStringWriter tracks write ids per writer - so that defect does not apply here.

      The check is kept because a class with no package remains worth surfacing: it is unusual, it is the shape that triggered the historical corruption, and reporting it costs one log line per distinct class for the life of the JVM.

      Parameters:
      className - the class name being checked
    • allowClass

      public void allowClass(String classNameOrWildcard)
    • allowClasses

      public void allowClasses(Collection<String> classNamesOrWildcards)
    • disallowClass

      public void disallowClass(String classNameOrWildcard)
    • getCheckLevel

      public RegexAllowListChecker.CheckLevel getCheckLevel()
    • setCheckLevel

      public void setCheckLevel(RegexAllowListChecker.CheckLevel checkLevel)