diff --git a/dubbo-dependencies-bom/pom.xml b/dubbo-dependencies-bom/pom.xml
index eae1bc812c8..c2426e27e70 100644
--- a/dubbo-dependencies-bom/pom.xml
+++ b/dubbo-dependencies-bom/pom.xml
@@ -152,7 +152,7 @@
1.2.0
1.11.2
0.3.0
- 3.2.7
+ 3.2.8
1.5.19
4.3.16.RELEASE
diff --git a/dubbo-serialization/dubbo-serialization-hessian2/src/main/java/org/apache/dubbo/common/serialize/hessian2/Hessian2SerializerFactory.java b/dubbo-serialization/dubbo-serialization-hessian2/src/main/java/org/apache/dubbo/common/serialize/hessian2/Hessian2SerializerFactory.java
index a5c5a9020ea..d0ff3a74e01 100644
--- a/dubbo-serialization/dubbo-serialization-hessian2/src/main/java/org/apache/dubbo/common/serialize/hessian2/Hessian2SerializerFactory.java
+++ b/dubbo-serialization/dubbo-serialization-hessian2/src/main/java/org/apache/dubbo/common/serialize/hessian2/Hessian2SerializerFactory.java
@@ -16,11 +16,38 @@
*/
package org.apache.dubbo.common.serialize.hessian2;
+import org.apache.dubbo.common.config.ConfigurationUtils;
+import org.apache.dubbo.common.utils.StringUtils;
+
import com.alibaba.com.caucho.hessian.io.SerializerFactory;
public class Hessian2SerializerFactory extends SerializerFactory {
+ private static final String WHITELIST = "dubbo.application.hessian2.whitelist";
+ private static final String ALLOW = "dubbo.application.hessian2.allow";
+ private static final String DENY = "dubbo.application.hessian2.deny";
+
+ public static final SerializerFactory SERIALIZER_FACTORY;
- public static final SerializerFactory SERIALIZER_FACTORY = new Hessian2SerializerFactory();
+ /**
+ * see https://github.com/ebourg/hessian/commit/cf851f5131707891e723f7f6a9718c2461aed826
+ */
+ static {
+ SERIALIZER_FACTORY = new Hessian2SerializerFactory();
+ String whiteList = ConfigurationUtils.getProperty(WHITELIST);
+ if ("true".equals(whiteList)) {
+ SERIALIZER_FACTORY.getClassFactory().setWhitelist(true);
+ String allowPattern = ConfigurationUtils.getProperty(ALLOW);
+ if (StringUtils.isNotEmpty(allowPattern)) {
+ SERIALIZER_FACTORY.getClassFactory().allow(allowPattern);
+ }
+ } else {
+ SERIALIZER_FACTORY.getClassFactory().setWhitelist(false);
+ String denyPattern = ConfigurationUtils.getProperty(DENY);
+ if (StringUtils.isNotEmpty(denyPattern)) {
+ SERIALIZER_FACTORY.getClassFactory().deny(denyPattern);
+ }
+ }
+ }
private Hessian2SerializerFactory() {
}