← Back to Advanced Java Course | Chapter 11: Advanced & Security | Lesson 15 of 19

Java की Advanced Serialization

Advanced serialization आपको यह control करने देता है कि कोई object bytes में कैसे save होता है, जैसे यह चुनना कि किसी suitcase में क्या पैक करना है। आप कुछ fields skip कर सकते हैं या process को customize कर सकते हैं।

Advanced Serialization

Serialization किसी object की in-memory state को एक byte stream में बदल देता है ताकि इसे किसी file में save किया जा सके या network पर भेजा जा सके और बाद में फिर से बनाया जा सके। किसी class को यह support करने के लिए, इसे marker interface Serializable implement करना चाहिए, JVM को बताते हुए कि इसे serialize करना सुरक्षित है।

उदाहरण: Advanced Serialization

java
import java.io.*;
public class Main {
	static class User implements Serializable { // marker interface -- tells the JVM it's safe to serialize
		String name = "Riya";
	}
	public static void main(String[] args) throws Exception {
		ByteArrayOutputStream bos = new ByteArrayOutputStream();
		new ObjectOutputStream(bos).writeObject(new User());
		System.out.println("Serialized to " + bos.size() + " bytes");
	}
}

The transient Keyword

किसी field पर transient keyword लगाना serialization process को इसे पूरी तरह skip करने के लिए कहता है, जो sensitive data (जैसे password field) या derived values के लिए बिल्कुल वही है जो serialized form में persist या तार पर नहीं भेजी जानी चाहिए।

उदाहरण: The transient Keyword

java
import java.io.*;
public class Main {
	static class User implements Serializable {
		String name = "Riya";
		transient String password = "secret"; // skipped entirely during serialization
	}
	public static void main(String[] args) throws Exception {
		ByteArrayOutputStream bos = new ByteArrayOutputStream();
		new ObjectOutputStream(bos).writeObject(new User());
		ObjectInputStream in = new ObjectInputStream(new ByteArrayInputStream(bos.toByteArray()));
		User restored = (User) in.readObject();
		System.out.println(restored.name + " " + restored.password); // password is null after restore
	}
}

serialVersionUID

serialVersionUID एक static final long constant है जो deserialization time पर यह verify करने के लिए उपयोग होता है कि incoming byte stream असल में अभी loaded class के version से मेल खाती है। एक explicit के बिना, किसी class में बदलाव चुपचाप पहले से save किए data की deserialization तोड़ सकता है।

उदाहरण: serialVersionUID

java
import java.io.*;
public class Main {
	static class User implements Serializable {
		static final long serialVersionUID = 1L; // verified against the byte stream at deserialization
		String name = "Riya";
	}
	public static void main(String[] args) {
		System.out.println("serialVersionUID = " + User.serialVersionUID);
	}
}

Custom Serialization

आप अपनी Serializable class के अंदर private writeObject() और readObject() methods define करके default serialization behavior को override कर सकते हैं, आपको उन fields को handle करने के लिए manual control देते हुए जिन्हें default field-by-field approach के बजाय custom encoding logic चाहिए।

उदाहरण: Custom Serialization

java
import java.io.*;
public class Main {
	static class User implements Serializable {
		String name = "Riya";
		private void writeObject(ObjectOutputStream out) throws IOException {
			out.defaultWriteObject();
			out.writeObject(name.toUpperCase()); // custom encoding logic
		}
	}
	public static void main(String[] args) throws Exception {
		ByteArrayOutputStream bos = new ByteArrayOutputStream();
		new ObjectOutputStream(bos).writeObject(new User());
		System.out.println("Custom writeObject() ran, " + bos.size() + " bytes written");
	}
}

Externalizable Interface

Externalizable interface Serializable को extend करता है लेकिन आपको writeExternal() और readExternal() के ज़रिए पूरे serialization process पर पूरा, manual control देता है, बजाय Java के default reflective serialization mechanism पर बिल्कुल निर्भर रहने के।

उदाहरण: Externalizable Interface

java
import java.io.*;
public class Main {
	static class User implements Externalizable {
		String name = "Riya";
		public User() {}
		public void writeExternal(ObjectOutput out) throws IOException {
			out.writeUTF(name); // fully manual control, no default reflective serialization
		}
		public void readExternal(ObjectInput in) throws IOException {
			name = in.readUTF();
		}
	}
	public static void main(String[] args) throws Exception {
		ByteArrayOutputStream bos = new ByteArrayOutputStream();
		new ObjectOutputStream(bos).writeObject(new User());
		System.out.println("Externalizable wrote " + bos.size() + " bytes manually");
	}
}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. किसी ऐसी class को serialize करना जो Serializable implement नहीं करती, जो NotSerializableException फेंकता है, ठीक वैसे ही जैसे कोई field जिसका type serializable नहीं है।
  2. यह उम्मीद करना कि एक transient field अपनी value बनाए रखेगा, जबकि deserialization के बाद यह null, 0 या false के रूप में वापस आता है।
  3. serialVersionUID declare न करना, जिससे बाद में class बदलने से पुराना data पढ़ते समय InvalidClassException आ सकता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.