coheigea opened a new pull request, #3512:
URL: https://github.com/apache/cxf/pull/3512

   The JAXP external access restrictions (ACCESS_EXTERNAL_DTD,
   ACCESS_EXTERNAL_SCHEMA, ACCESS_EXTERNAL_STYLESHEET) do not apply to
   inputs returned by an application-registered resolver.
   
   EndpointReferenceUtils:
   - Re-parse schemas fetched from the sourceURI, or resolved via
     ExtendedURIResolver, with the secure StAX parser and re-serialize the
     document element, so no DOCTYPE reaches the SchemaFactory.
   - Return null from SchemaLSResourceResolver for non-schema (DTD/entity)
     requests so the factory's ACCESS_EXTERNAL_DTD restriction applies.
   
   SchemaHandler (JAX-RS):
   - Enable secure processing, disallow external DTDs and restrict schema
     imports/includes to local schemes. Remote schemas can still be mapped
     to local copies with an OASIS catalog.
   
   XSLTJaxbProvider (JAX-RS):
   - When secure processing is enabled, only consult a URIResolver set via
     setResolver() for local references; others are left to the
     TransformerFactory, which rejects them. Archive URLs such as
     jar:http:// are checked by their inner scheme. Disabling secure
     processing restores the previous behaviour.
   
   URIResolver:
   - Add getLocalSchemes(): the allowed schemes plus the OSGi bundle
     schemes, minus http, https and ftp. It is used by both JAX-RS classes
     and can be extended with the existing allowedSchemes system property.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to