Command Palette

Search for a command to run...

Back to the lesson: Topic 12.4 — Serialization and Why to Avoid It
Core Java · Example 3 of 3 Java 9+

A deserialization filter rejects unexpected classes

The filter allows String and rejects every other class (!*), so the ArrayList is refused before any object is created.

Java serialization turns an object graph into bytes (ObjectOutputStream) and rebuilds it later (ObjectInputStream). It's built in and easy, but it's fragile across versions and reading untrusted bytes is a classic security hole, so modern code prefers explicit formats like JSON and uses filters when it must deserialize.

Change the code and press Run (Ctrl+Enter). Try to predict the output first, then break it on purpose and read the error. Your edits are saved and match the lesson page.

Practice questions

Write the code in the editor, run it, then open the model answer to compare.

01

Serialize a list of two records to a byte array and read it back, printing the list.

02

Show that a static field is not serialized: change it after writing, then read the object back.

Explain it without notes

01

What happens, step by step, when you call writeObject and readObject?

02

Why is deserializing untrusted data dangerous, and how do you defend against it?

03

What do transient and serialVersionUID do?

A deserialization filter rejects unexpected classes Java 9+
Sign in to run this example in your browser.

Expected output

rejected: filter status: REJECTED