Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -131,7 +131,15 @@ public Object deserialize(JsonParser p, DeserializationContext ctxt) throws IOEx
} else if (p.hasToken(JsonToken.VALUE_EMBEDDED_OBJECT)) {
// 20-Apr-2016, tatu: Related to [databind#1208], can try supporting embedded
// values quite easily
return p.getEmbeddedObject();
// [modules-java8#389]: only accept a value of this type. A byte[] must
// not be stored as a ZoneId, Period, or ZoneOffset.
Object embedded = p.getEmbeddedObject();
if (embedded == null || handledType().isInstance(embedded)) {
return embedded;
}
return _handleUnexpectedToken(ctxt, p,
"Unexpected embedded value of type %s",
embedded.getClass().getName());
} else if (p.isExpectedStartArrayToken()) {
return _deserializeFromArray(p, ctxt);
}
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
package com.fasterxml.jackson.datatype.jsr310.deser;

import java.time.Period;
import java.time.ZoneId;
import java.time.ZoneOffset;
import java.util.Map;

import org.junit.jupiter.api.Test;

import com.fasterxml.jackson.core.type.TypeReference;
import com.fasterxml.jackson.databind.ObjectMapper;
import com.fasterxml.jackson.databind.exc.MismatchedInputException;
import com.fasterxml.jackson.databind.node.ObjectNode;
import com.fasterxml.jackson.datatype.jsr310.ModuleTestBase;

import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertInstanceOf;
import static org.junit.jupiter.api.Assertions.assertThrows;

// [modules-java8#389]
public class JSR310EmbeddedObjectDeserTest extends ModuleTestBase
{
private final ObjectMapper MAPPER = newMapper();

@Test
public void testZoneIdRejectsEmbeddedBytes() {
ObjectNode node = MAPPER.createObjectNode();
node.putPOJO("zone", new byte[] { (byte) 0xDE, (byte) 0xAD });

IllegalArgumentException e = assertThrows(IllegalArgumentException.class, () ->
MAPPER.convertValue(node, new TypeReference<Map<String, ZoneId>>() { }));
assertInstanceOf(MismatchedInputException.class, e.getCause());
}

@Test
public void testZoneIdAcceptsEmbeddedZoneId() {
ObjectNode node = MAPPER.createObjectNode();
node.putPOJO("zone", ZoneId.of("UTC"));

Map<String, ZoneId> result = MAPPER.convertValue(node,
new TypeReference<Map<String, ZoneId>>() { });
assertEquals(ZoneId.of("UTC"), result.get("zone"));
}

@Test
public void testPeriodRejectsEmbeddedBytes() {
ObjectNode node = MAPPER.createObjectNode();
node.putPOJO("period", new byte[] { 1, 2 });

IllegalArgumentException e = assertThrows(IllegalArgumentException.class, () ->
MAPPER.convertValue(node, new TypeReference<Map<String, Period>>() { }));
assertInstanceOf(MismatchedInputException.class, e.getCause());
}

@Test
public void testZoneOffsetRejectsEmbeddedBytes() {
ObjectNode node = MAPPER.createObjectNode();
node.putPOJO("offset", new byte[] { 1, 2 });

IllegalArgumentException e = assertThrows(IllegalArgumentException.class, () ->
MAPPER.convertValue(node, new TypeReference<Map<String, ZoneOffset>>() { }));
assertInstanceOf(MismatchedInputException.class, e.getCause());
}
}
10 changes: 10 additions & 0 deletions release-notes/CREDITS-2.x
Original file line number Diff line number Diff line change
Expand Up @@ -243,3 +243,13 @@ Seonwoo Jung (@seonwooj0810)
* Contributed fix for #76: Missing milliseconds, when serializing Java 8 date-time,
if they are zeros
(2.23.0)

Manqing Zhou (@manqingzhou)
* Reported #389: Validate embedded objects (`JsonToken.VALUE_EMBEDDED_OBJECT`)
against expected `java.time` type, instead of returning them as-is
(2.23.0)

Aditya Bagla (@adityabagla7)
* Contributed fix for #389: Validate embedded objects (`JsonToken.VALUE_EMBEDDED_OBJECT`)
against expected `java.time` type, instead of returning them as-is
(2.23.0)
4 changes: 4 additions & 0 deletions release-notes/VERSION-2.x
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,10 @@ Modules:
`JavaTimeFeature.ALWAYS_WRITE_SUBSECOND_DIGITS`)
(reported by @rycler)
(fix contributed by Seonwoo J)
#389: Validate embedded objects (`JsonToken.VALUE_EMBEDDED_OBJECT`) against
expected `java.time` type, instead of returning them as-is
(reported by @manqingzhou)
(fix contributed by Aditya B)

2.22.3 (21-Sep-2026)
2.22.2 (16-Aug-2026)
Expand Down