activemq-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From davscl...@apache.org
Subject [2/2] activemq git commit: AMQ-6166: Add option to configure trustAllPackages on Camel ActiveMQ component
Date Thu, 11 Feb 2016 11:10:09 GMT
AMQ-6166: Add option to configure trustAllPackages on Camel ActiveMQ component


Project: http://git-wip-us.apache.org/repos/asf/activemq/repo
Commit: http://git-wip-us.apache.org/repos/asf/activemq/commit/55947728
Tree: http://git-wip-us.apache.org/repos/asf/activemq/tree/55947728
Diff: http://git-wip-us.apache.org/repos/asf/activemq/diff/55947728

Branch: refs/heads/activemq-5.13.x
Commit: 559477285c20f2012450ce472959f3fd8e26712b
Parents: 0715d09
Author: Claus Ibsen <claus.ibsen@gmail.com>
Authored: Thu Feb 11 12:04:24 2016 +0100
Committer: Claus Ibsen <claus.ibsen@gmail.com>
Committed: Thu Feb 11 12:09:51 2016 +0100

----------------------------------------------------------------------
 .../camel/component/ActiveMQComponent.java      |  6 ++++++
 .../camel/component/ActiveMQConfiguration.java  | 20 ++++++++++++++++++++
 2 files changed, 26 insertions(+)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/activemq/blob/55947728/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQComponent.java
----------------------------------------------------------------------
diff --git a/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQComponent.java
b/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQComponent.java
index df38a00..39d4420 100644
--- a/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQComponent.java
+++ b/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQComponent.java
@@ -121,6 +121,12 @@ public class ActiveMQComponent extends JmsComponent implements EndpointCompleter
         }
     }
 
+    public void setTrustAllPackages(boolean trustAllPackages) {
+        if (getConfiguration() instanceof ActiveMQConfiguration) {
+            ((ActiveMQConfiguration)getConfiguration()).setTrustAllPackages(trustAllPackages);
+        }
+    }
+
     public boolean isExposeAllQueues() {
         return exposeAllQueues;
     }

http://git-wip-us.apache.org/repos/asf/activemq/blob/55947728/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQConfiguration.java
----------------------------------------------------------------------
diff --git a/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQConfiguration.java
b/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQConfiguration.java
index 7eecac2..26d31a6 100644
--- a/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQConfiguration.java
+++ b/activemq-camel/src/main/java/org/apache/activemq/camel/component/ActiveMQConfiguration.java
@@ -37,6 +37,7 @@ public class ActiveMQConfiguration extends JmsConfiguration {
     private boolean usePooledConnection = true;
     private String userName;
     private String password;
+    private boolean trustAllPackages;
 
     public ActiveMQConfiguration() {
     }
@@ -109,6 +110,24 @@ public class ActiveMQConfiguration extends JmsConfiguration {
         this.usePooledConnection = usePooledConnection;
     }
 
+    public boolean isTrustAllPackages() {
+        return trustAllPackages;
+    }
+
+    /**
+     * ObjectMessage objects depend on Java serialization of marshal/unmarshal object payload.
+     * This process is generally considered unsafe as malicious payload can exploit the host
system.
+     * That's why starting with versions 5.12.2 and 5.13.0, ActiveMQ enforces users to explicitly
whitelist packages
+     * that can be exchanged using ObjectMessages.
+     * <br/>
+     * This option can be set to <tt>true</tt> to trust all packages (eg whitelist
is *).
+     * <p/>
+     * See more details at: http://activemq.apache.org/objectmessage.html
+     */
+    public void setTrustAllPackages(boolean trustAllPackages) {
+        this.trustAllPackages = trustAllPackages;
+    }
+
     /**
      * Factory method to create a default transaction manager if one is not specified
      */
@@ -126,6 +145,7 @@ public class ActiveMQConfiguration extends JmsConfiguration {
     @Override
     protected ConnectionFactory createConnectionFactory() {
         ActiveMQConnectionFactory answer = new ActiveMQConnectionFactory();
+        answer.setTrustAllPackages(trustAllPackages);
         if (userName != null) {
             answer.setUserName(userName);
         }


Mime
View raw message