Skip to content

Commit e9a9c07

Browse files
authored
Add more warnings about BinaryFormatter and NetDataContractSerializer (#43433)
* Add more warnings about BinaryFormatter and NetDataContractSerializer * Revert uneditable file. Fix include paths.
1 parent 2674429 commit e9a9c07

File tree

4 files changed

+8
-3
lines changed

4 files changed

+8
-3
lines changed

docs/orleans/host/configuration-guide/serialization.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -389,6 +389,8 @@ Alternatively, the fallback serialization provider can be specified in XML confi
389389

390390
The <xref:Orleans.Serialization.BinaryFormatterSerializer> is the default fallback serializer.
391391

392+
[!INCLUDE [binary-serialization-warning](../../../../includes/binary-serialization-warning.md)]
393+
392394
## Exception serialization
393395

394396
Exceptions are serialized using the [fallback serializer](serialization.md#fallback-serialization). Using the default configuration, `BinaryFormatter` is the fallback serializer and so the [ISerializable pattern](/previous-versions/dotnet/fundamentals/serialization/binary/custom-serialization) must be followed in order to ensure correct serialization of all properties in an exception type.

docs/standard/serialization/binaryformatter-migration-guide/choose-a-serializer.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,8 +58,7 @@ While `DataContractSerializer` carries those functional benefits when migrating
5858

5959
[Migrate to DataContractSerializer (XML)](./migrate-to-datacontractserializer.md).
6060

61-
> [!NOTE]
62-
> Do not confuse <xref:System.Runtime.Serialization.DataContractSerializer> with <xref:System.Runtime.Serialization.NetDataContractSerializer>. <xref:System.Runtime.Serialization.NetDataContractSerializer> is also identified as a [dangerous serializer](../binaryformatter-security-guide.md#dangerous-alternatives).
61+
[!INCLUDE [netdatacontractserializer-warning](../../../../includes/netdatacontractserializer-warning.md)]
6362

6463
## Binary using MessagePack
6564

includes/migration-guide/runtime/serialization/soapformatter-cannot-deserialize-hashtable-similar-ordered-collection.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,12 @@ The <xref:System.Runtime.Serialization.Formatters.Soap.SoapFormatter?displayProp
66

77
#### Suggestion
88

9-
<xref:System.Runtime.Serialization.Formatters.Soap.SoapFormatter?displayProperty=fullName> serialization should be replaced with <xref:System.Runtime.Serialization.Formatters.Binary.BinaryFormatter?displayProperty=fullName> serialization or <xref:System.Runtime.Serialization.NetDataContractSerializer?displayProperty=fullName> to be resilient to .NET Framework changes.
9+
<xref:System.Runtime.Serialization.Formatters.Soap.SoapFormatter?displayProperty=fullName> serialization should be replaced with a serializer that is resilient to .NET Framework changes. Examples include [System.Text.Json](/dotnet/standard/serialization/system-text-json/overview) and <xref:System.Runtime.Serialization.DataContractSerializer?displayProperty=fullName>.
1010

1111
[!INCLUDE [binary-serialization-warning](../../../binary-serialization-warning.md)]
1212

13+
[!INCLUDE [netdatacontractserializer-warning](../../../netdatacontractserializer-warning.md)]
14+
1315
| Name | Value |
1416
| :------ | :------ |
1517
| Scope | Minor |
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
> [!WARNING]
2+
> Do not confuse <xref:System.Runtime.Serialization.DataContractSerializer> with <xref:System.Runtime.Serialization.NetDataContractSerializer>. <xref:System.Runtime.Serialization.NetDataContractSerializer> is identified as a [dangerous serializer](/dotnet/standard/serialization/binaryformatter-security-guide.md#dangerous-alternatives).

0 commit comments

Comments
 (0)