Book: Migration guide
Chapter:5.4.3. Additional RESTEasy Changes
Please add new subchapter "SerializableProvider".
It should state information that:
"Deserializing Java objects from untrusted sources is unsafe. Therefore org.jboss.resteasy.plugins.providers.SerializableProvider is disabled by default. It is not recommended to use this provider."
- relates to
-
JBEAP-5486 SerializableProvider should be deprecated
- Verified
-
JBEAP-5409 Devel guide for webservices - resteasy SerializableProvider note
- Closed