I think it's better to use standard API.
see Java Serialization Filters
|
protected Class<?> resolveClass(ObjectStreamClass classDesc) throws IOException, ClassNotFoundException { |
|
Class<?> clazz = super.resolveClass(classDesc); |
|
checkAllowedList(clazz); |
|
return clazz; |
|
} |
|
protected Class<?> resolveClass(ObjectStreamClass classDesc) |
|
throws IOException, ClassNotFoundException { |
|
Class<?> clazz = super.resolveClass(classDesc); |
|
checkAllowedList(clazz); |
|
return clazz; |
|
} |