(Translated by https://www.hiragana.jp/)
GitHub - sofastack/sofa-hessian: An internal improved version of Hessian3/4 powered by Ant Group CO., Ltd.
Skip to content

An internal improved version of Hessian3/4 powered by Ant Group CO., Ltd.

License

Notifications You must be signed in to change notification settings

sofastack/sofa-hessian

Repository files navigation

SOFA-Hessian

Build Status Coverage Status License

Hessian 一个性能较优且兼容性较好的二进制序列化协议。

SOFA-Hessian もと于原せい Hessian v4.0.51 进行あらため进,目前もくぜんやめ经蚂蚁金ふく内部ないぶ稳定运行多年たねんわが们修复了いち些 bug,增强ぞうきょうりょういち些功のう,并且添加てんかりょういち些特せい包括ほうかつ

  • 增加ぞうか泛化序列じょれつ
  • 增加ぞうか ClassNameResolver ClassNameFilter よう于类めいてきうつ、转换、过滤とう
  • 增加ぞうか序列じょれつくろめい单(らい蚂蚁きんふく安全あんぜん团队)。
  • あらためSerializerFactory うち缓存てき锁机せい
  • さらさん见:あらため进点

需要じゅよう

  • JDK 6 及以じょう

ぶん

开源许可

めん声明せいめい

Hessian 一种二进制序列化协议。

よし于 Hessian 自身じしん实现关系,つう过构づくり特定とくていてき序列じょれつながれ,经过はん序列じょれつきさき可能かのうかい造成ぞうせい任意にんいだい码执ぎょう存在そんざい安全あんぜん风险,けん议用户配置はいちくろめい单或しろめい单的方式ほうしきらいかい决该问题。

ほん项目ないおけてきくろめい单来内部ないぶ实践外部がいぶ贡献,仅供参考さんこう做主动更新こうしんわがほういん此承担法律ほうりつ责任。如需要じゅようさら严格てきこう验,请使用しようしろめい单功のう

Hessian is a binary serialization protocol.

Because of the implement of Hessian, by constructing a specific serialization stream, it may cause arbitrary code execution when doing deserialization. It is recommended that users configure blacklist or whitelist to solve the problem.

The blacklist built into the project comes from internal practices and external contributions, and is for reference only and is not actively updated, we do not assume any legal responsibility for this. For more rigorous verification, please use the whitelist feature.