coheigea opened a new pull request, #3512:
URL: https://github.com/apache/cxf/pull/3512
The JAXP external access restrictions (ACCESS_EXTERNAL_DTD,
ACCESS_EXTERNAL_SCHEMA, ACCESS_EXTERNAL_STYLESHEET) do not apply to
inputs returned by an application-registered resolver.
EndpointReferenceUtils:
- Re-parse schemas fetched from the sourceURI, or resolved via
ExtendedURIResolver, with the secure StAX parser and re-serialize the
document element, so no DOCTYPE reaches the SchemaFactory.
- Return null from SchemaLSResourceResolver for non-schema (DTD/entity)
requests so the factory's ACCESS_EXTERNAL_DTD restriction applies.
SchemaHandler (JAX-RS):
- Enable secure processing, disallow external DTDs and restrict schema
imports/includes to local schemes. Remote schemas can still be mapped
to local copies with an OASIS catalog.
XSLTJaxbProvider (JAX-RS):
- When secure processing is enabled, only consult a URIResolver set via
setResolver() for local references; others are left to the
TransformerFactory, which rejects them. Archive URLs such as
jar:http:// are checked by their inner scheme. Disabling secure
processing restores the previous behaviour.
URIResolver:
- Add getLocalSchemes(): the allowed schemes plus the OSGi bundle
schemes, minus http, https and ftp. It is used by both JAX-RS classes
and can be extended with the existing allowedSchemes system property.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]