This is an automated email from the ASF dual-hosted git repository.

coheigea pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/ws-xmlschema.git


The following commit(s) were added to refs/heads/master by this push:
     new 01f25f02 Stop capturing foreign children of the document element (#157)
01f25f02 is described below

commit 01f25f02b2a864463766d2966b77a2f3fa7585a1
Author: Colm O hEigeartaigh <[email protected]>
AuthorDate: Thu Sep 17 10:19:56 2026 +0100

    Stop capturing foreign children of the document element (#157)
---
 .../apache/ws/commons/schema/SchemaBuilder.java    |  19 +++-
 .../java/tests/ForeignTopLevelContentTest.java     | 105 +++++++++++++++++++++
 2 files changed, 122 insertions(+), 2 deletions(-)

diff --git 
a/xmlschema-core/src/main/java/org/apache/ws/commons/schema/SchemaBuilder.java 
b/xmlschema-core/src/main/java/org/apache/ws/commons/schema/SchemaBuilder.java
index 5c57d6af..e7609d9f 100644
--- 
a/xmlschema-core/src/main/java/org/apache/ws/commons/schema/SchemaBuilder.java
+++ 
b/xmlschema-core/src/main/java/org/apache/ws/commons/schema/SchemaBuilder.java
@@ -737,7 +737,7 @@ public class SchemaBuilder {
         }
 
         // add the extensibility components
-        processExtensibilityComponents(currentSchema, schemaEl, false);
+        processExtensibilityComponents(currentSchema, schemaEl, false, false);
 
         return currentSchema;
     }
@@ -1982,6 +1982,21 @@ public class SchemaBuilder {
     private void processExtensibilityComponents(XmlSchemaObject schemaObject,
                                                 Element parentElement,
                                                 boolean namespaces) {
+        processExtensibilityComponents(schemaObject, parentElement, 
namespaces, true);
+    }
+
+    /**
+     * @param childElements whether foreign-namespace child elements are 
captured as well as
+     *        foreign attributes. False for the document element: xs:schema 
permits foreign
+     *        attributes but no foreign children, and a document reached 
through a
+     *        schemaLocation is whatever was at that URL. Capturing its 
children put the
+     *        contents of any XML file into the model, which the serializer 
then wrote back
+     *        out - so an embedding that republishes resolved schemas handed 
them back.
+     */
+    private void processExtensibilityComponents(XmlSchemaObject schemaObject,
+                                                Element parentElement,
+                                                boolean namespaces,
+                                                boolean childElements) {
 
         if (extReg != null) {
             // process attributes
@@ -2003,7 +2018,7 @@ public class SchemaBuilder {
             }
 
             // process elements
-            Node child = parentElement.getFirstChild();
+            Node child = childElements ? parentElement.getFirstChild() : null;
             while (child != null) {
                 if (child.getNodeType() == Node.ELEMENT_NODE) {
                     Element extElement = (Element)child;
diff --git a/xmlschema-core/src/test/java/tests/ForeignTopLevelContentTest.java 
b/xmlschema-core/src/test/java/tests/ForeignTopLevelContentTest.java
new file mode 100644
index 00000000..a2d4cb17
--- /dev/null
+++ b/xmlschema-core/src/test/java/tests/ForeignTopLevelContentTest.java
@@ -0,0 +1,105 @@
+/**
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements. See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership. The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+
+package tests;
+
+import java.io.StringReader;
+import java.io.StringWriter;
+
+import org.apache.ws.commons.schema.XmlSchema;
+import org.apache.ws.commons.schema.XmlSchemaCollection;
+import org.apache.ws.commons.schema.resolver.URIResolver;
+
+import org.junit.Assert;
+import org.junit.Test;
+import org.xml.sax.InputSource;
+
+/**
+ * A document reached through a schemaLocation is whatever was at that URL, 
and any XML root
+ * parses as a schema. Its foreign children must not be captured into the 
model, or an
+ * embedding that republishes resolved schemas hands the fetched file's 
contents back.
+ */
+public class ForeignTopLevelContentTest extends Assert {
+
+    private static final String SECRET = "TOP-SECRET-VALUE";
+
+    private static final String NOT_A_SCHEMA =
+        "<config targetNamespace=\"urn:internal\" xmlns=\"urn:internal\">"
+        + "<dbPassword>" + SECRET + "</dbPassword>"
+        + "</config>";
+
+    private static String republish(XmlSchema schema) throws Exception {
+        StringWriter writer = new StringWriter();
+        schema.write(writer);
+        return writer.toString();
+    }
+
+    @Test
+    public void testForeignChildrenOfTheRootAreNotRepublished() throws 
Exception {
+        XmlSchema schema = new XmlSchemaCollection().read(new 
StringReader(NOT_A_SCHEMA));
+        assertFalse("the fetched document's content must not reach the 
serializer",
+                    republish(schema).contains(SECRET));
+    }
+
+    @Test
+    public void testForeignChildrenOfAnImportedDocumentAreNotRepublished() 
throws Exception {
+        XmlSchemaCollection collection = new XmlSchemaCollection();
+        collection.setSchemaResolver(new URIResolver() {
+            public InputSource resolveEntity(String namespace, String 
schemaLocation, String baseUri) {
+                InputSource source = new InputSource(new 
StringReader(NOT_A_SCHEMA));
+                source.setSystemId("http://example.invalid/"; + schemaLocation);
+                return source;
+            }
+        });
+        collection.read(new StringReader(
+            "<xs:schema xmlns:xs=\"http://www.w3.org/2001/XMLSchema\"; 
targetNamespace=\"urn:a\">"
+            + "<xs:import namespace=\"urn:internal\" 
schemaLocation=\"config.xml\"/>"
+            + "</xs:schema>"));
+
+        XmlSchema imported = collection.schemaForNamespace("urn:internal");
+        assertNotNull(imported);
+        assertFalse(republish(imported).contains(SECRET));
+    }
+
+    /** Foreign attributes on xs:schema are legal, and are still captured. */
+    @Test
+    public void testForeignAttributesOnTheRootAreStillCaptured() throws 
Exception {
+        XmlSchema schema = new XmlSchemaCollection().read(new StringReader(
+            "<xs:schema xmlns:xs=\"http://www.w3.org/2001/XMLSchema\"";
+            + " xmlns:ext=\"http://customattrib.org\"; ext:stamp=\"kept\""
+            + " targetNamespace=\"urn:a\">"
+            + "<xs:element name=\"e\" type=\"xs:string\"/></xs:schema>"));
+        assertNotNull("a foreign attribute on xs:schema must still be 
captured",
+                      schema.getMetaInfoMap());
+    }
+
+    /** Foreign children of a complexType or element are legal extension 
points and still work. */
+    @Test
+    public void testForeignChildrenOfOtherComponentsAreStillCaptured() throws 
Exception {
+        XmlSchema schema = new XmlSchemaCollection().read(new StringReader(
+            "<xs:schema xmlns:xs=\"http://www.w3.org/2001/XMLSchema\"";
+            + " xmlns:ext=\"http://customattrib.org\"; 
targetNamespace=\"urn:a\">"
+            + "<xs:element name=\"e\" type=\"xs:string\">"
+            + "<ext:customElt prefix=\"ext\" suffix=\"elt\"/>"
+            + "</xs:element></xs:schema>"));
+        assertNotNull(schema.getElementByName("e"));
+        assertNotNull("extension elements on an xs:element must still be 
captured",
+                      schema.getElementByName("e").getMetaInfoMap());
+    }
+}

Reply via email to