We can reject serialized Java objects instead of giving the transient keyword
•
Java
We can avoid serializing fields by using the transient keyword
Solution
http://java.sun.com/javase/6/docs/platform/serialization/spec/security.html
Here are some links
Declaring serialPersistenetFields.
Serialization architecture specification.
Security in Object Serialization.
The content of this article comes from the network collection of netizens. It is used as a learning reference. The copyright belongs to the original author.
THE END
二维码