Logo
The Changes to JSON serialization in SitecoreAI page has loaded.

SitecoreAI Changelog

Learn more about new versions, changes and improvements for SitecoreAI

SitecoreAI is introducing an improvement to PipelineArgs serialization and deserialization by changing the underlying configuration from TypeNameHandling.All to TypeNameHandling.None. This change removes embedded .NET type metadata from serialized payloads and enforces more restrictive deserialization behavior.

Most implementations are not expected to be affected. Standard scenarios that use primitive values such as strings, numbers, and booleans will continue to function as before. The primary impact area is custom code that stores complex objects in PipelineArgs.CustomData and later serializes and deserializes those values.

After this change, custom classes, interface-based objects, abstract types, and heterogeneous object collections may no longer be automatically restored to their original .NET types during deserialization. Depending on the implementation, values may be returned as generic JSON objects, resulting in casting failures, missing data, or other compatibility issues.

Action required

Customers should review any serialization round-trips involving PipelineArgs.CustomData and consider using strongly typed models or explicitly reconstructing custom objects after deserialization.

To support validation and migration, a feature flag will be provided that allows customers to enable the new behavior before it becomes the default and temporarily revert if compatibility issues are discovered. We strongly recommend testing any customizations that serialize and deserialize PipelineArgs data during the notification period to identify and address potential impacts before rollout.

We also strongly recommend that you test the new security implementation before the base image release scheduled for November 29 by creating a patch configuration file and redeploying your environment. 


Example configuration to enable the changes:

<sitecore>
  <settings>
     <setting name="PipelineArgs.DisableUnsafeSerialization">
     <patch:attribute name="value">true</patch:attribute>
     </setting>
  </settings>
</sitecore>