snoopdave opened a new pull request, #201: URL: https://github.com/apache/roller/pull/201
## Summary Roller configured its XML parsers by hand in two places, with two separate feature lists: - `SafeSAXBuilder`, used for JDOM parsing (bookmark import, theme metadata, runtime config definitions, menus). - `WebloggerImpl`, which set features on the XML-RPC library's shared `SAXParserFactory`. If the parser did not accept a setting, it logged an error and continued. This PR moves both onto [Apache Commons Secure XML](https://commons.apache.org/proper/commons-secure-xml/) 1.0.0: - **New `SecureXmlParsers`** returns a namespace-aware, non-validating `SAXParserFactory` from `SecureSAXParserFactory.newNSInstance()`, and refuses document type declarations on top, as Roller did before. It throws if the configuration cannot be applied. - **`SafeSAXBuilder`** now gets its readers from `SecureXmlParsers`. It keeps its existing settings as an overlapping layer, so all its call sites are unchanged. - **`WebloggerImpl`** installs the same factory for XML-RPC with `SAXParsers.setSAXParserFactory(...)`. Startup now fails instead of continuing with an unconfigured parser. The new dependency has no runtime dependencies of its own, and its NOTICE is the standard ASF one, so the release LICENSE and NOTICE files are unchanged. ## Testing - New `SecureXmlParsersTest` (5) and two new `SafeSAXBuilderTest` cases: ordinary namespaced documents parse, document type declarations are refused, declared external entities are not read, and the XML-RPC library uses the same configuration. - `mvn -pl app test` on JDK 11: 332 tests, 0 failures, 1 skipped. The suite starts Roller, so the XML-RPC installation runs during it. - `roller.war` bundles `commons-secure-xml-1.0.0.jar`. Targets `roller-6.1.x` for 6.1.7. A matching change for `master` will follow. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
