Java में Serialization
In this page:
class ClassName implements Serializable {
// fields
}
ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("file"));
out.writeObject(object);
What is Serialization?
Serialization एक live Java object को एक byte stream में convert करता है जिसे एक file में save या network पर send किया जा सकता है, और बाद में वापस एक equivalent object में reconstruct किया जा सकता है — class को marker interface Serializable implement करना चाहिए।
उदाहरण: What is Serialization?
// Import java.io.Serializable so it can be used by its short name
import java.io.Serializable;
// Define the class Person
class Person implements Serializable {
// Declare name and set it to "Alice"
String name = "Alice";
}
// Define the class Main
public class Main {
// Program entry point: the JVM starts running here
public static void main(String[] args) {
// Create a new Person object and store it in p
Person p = new Person();
// Print a line to the console
System.out.println(p instanceof Serializable);
}
}
Login to try C/C++/Java/PHP code in the editor
Writing Objects with ObjectOutputStream
ObjectOutputStream एक serializable object की पूरी state को writeObject() के ज़रिए एक underlying stream में लिखता है, हर non-transient field की current value capture करते हुए।
उदाहरण: Writing Objects with ObjectOutputStream
// Import java.io.* so it can be used by its short name
import java.io.*;
// Define the class Person
class Person implements Serializable {
// Declare name and set it to "Alice"
String name = "Alice";
}
// Define the class Main
public class Main {
// Program entry point: the JVM starts running here
public static void main(String[] args) throws IOException {
// Create a new ObjectOutputStream object and store it in out
ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("person.ser"));
out.writeObject(new Person());
out.close();
// Print a line to the console
System.out.println("Written");
}
}
Login to try C/C++/Java/PHP code in the editor
Reading Objects with ObjectInputStream
ObjectInputStream वह byte stream वापस पढ़ता है और readObject() के ज़रिए object reconstruct करता है, इसकी fields को serialization time पर उनकी values में restore करते हुए।
उदाहरण: Reading Objects with ObjectInputStream
// Import java.io.* so it can be used by its short name
import java.io.*;
// Define the class Person
class Person implements Serializable {
// Declare name and set it to "Alice"
String name = "Alice";
}
// Define the class Main
public class Main {
// Program entry point: the JVM starts running here
public static void main(String[] args) throws IOException, ClassNotFoundException {
// Create a new ObjectOutputStream object and store it in out
ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("person.ser"));
out.writeObject(new Person());
out.close();
// Create a new ObjectInputStream object and store it in in
ObjectInputStream in = new ObjectInputStream(new FileInputStream("person.ser"));
Person p = (Person) in.readObject();
in.close();
// Print a line to the console
System.out.println(p.name);
}
}
Login to try C/C++/Java/PHP code in the editor
Transient Fields
एक field को transient मार्क करना इसे serialization से पूरी तरह exclude करता है — आमतौर पर passwords जैसे sensitive data के लिए, या उन fields के लिए (जैसे एक open file handle) जिन्हें बस meaningfully save और restore नहीं किया जा सकता।
उदाहरण: Transient Fields
import java.io.Serializable;
class Person implements Serializable {
String name = "Alice";
transient String password = "secret"; // excluded from serialization
}
public class Main {
public static void main(String[] args) {
Person p = new Person();
System.out.println(p.password);
}
}
Login to try C/C++/Java/PHP code in the editor
Safe Serialization Practices
अगर आप untrusted data deserialize करें तो Serialization में असली security risks हैं, क्योंकि एक malicious byte stream unexpected code execution trigger कर सकता है — सिर्फ उन sources से data deserialize करें जिन पर आप पूरी तरह भरोसा करते हैं।
उदाहरण: Safe Serialization Practices
// Import java.io.Serializable so it can be used by its short name
import java.io.Serializable;
// Define the class Main
public class Main {
// Define the class Data
static class Data implements Serializable {
// Declare value and set it to 5
int value = 5;
}
// Program entry point: the JVM starts running here
public static void main(String[] args) {
// Print a line to the console
System.out.println("Only deserialize data from trusted sources");
}
}
Login to try C/C++/Java/PHP code in the editor
Serializableimplement करना भूल जाना, जोNotSerializableExceptionthrow करता है।- यह उम्मीद करना कि
transientfields save होंगी, जब वे skip होती हैं और वापस default values के रूप में पढ़ी जाती हैं। - पढ़े object को गलत class में cast करना, जो
ClassCastExceptionthrow करता है।
Chapter Quiz — Complete all 9 topics to unlock
0/9 topics done
Complete these topics first: