snoopdave commented on code in PR #198: URL: https://github.com/apache/roller/pull/198#discussion_r4174841687
########## app/src/main/java/org/apache/roller/weblogger/webservices/atomprotocol/RollerAtomServlet.java: ########## @@ -0,0 +1,193 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor license agreements. The ASF licenses this file to You + * under the Apache License, Version 2.0 (the "License"); you may not + * use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. For additional information regarding + * copyright in this work, please see the NOTICE file in the top level + * directory of this distribution. + */ + +package org.apache.roller.weblogger.webservices.atomprotocol; + +import java.io.BufferedReader; +import java.io.ByteArrayInputStream; +import java.io.ByteArrayOutputStream; +import java.io.IOException; +import java.io.InputStream; +import java.io.InputStreamReader; +import java.nio.charset.StandardCharsets; +import javax.servlet.ReadListener; +import javax.servlet.ServletException; +import javax.servlet.ServletInputStream; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletRequestWrapper; +import javax.servlet.http.HttpServletResponse; + +import com.rometools.propono.atom.server.AtomServlet; +import org.apache.commons.logging.Log; +import org.apache.commons.logging.LogFactory; +import org.apache.roller.weblogger.config.WebloggerRuntimeConfig; +import org.apache.roller.weblogger.util.SafeSAXBuilder; +import org.jdom2.JDOMException; + +/** + * Roller's AtomPub endpoint. It answers only while + * <code>webservices.enableAtomPub</code> is on, and it reads each Atom entry + * body with Roller's shared XML parser settings before the Propono servlet + * handles the request. + */ +public class RollerAtomServlet extends AtomServlet { + + private static final long serialVersionUID = 1L; + + private static final Log LOG = LogFactory.getLog(RollerAtomServlet.class); + + /** Largest Atom entry body accepted, in bytes. Media uploads are not affected. */ + static final int MAX_ENTRY_BYTES = 10 * 1024 * 1024; + + private static final String ATOM_CONTENT_TYPE = "application/atom+xml"; + + @Override + protected void service(HttpServletRequest req, HttpServletResponse res) + throws ServletException, IOException { + + if (!WebloggerRuntimeConfig.getBooleanProperty("webservices.enableAtomPub")) { + LOG.debug("AtomPub service is disabled; rejecting request"); + sendText(res, HttpServletResponse.SC_NOT_FOUND, "AtomPub service is disabled"); + return; + } + + if (!carriesEntry(req)) { + forward(req, res); + return; + } + + byte[] body = readBody(req.getInputStream()); Review Comment: 🐞Claude Issue: **Important:** The body is now read and parsed before authentication. In Propono, `doPost` and `doPut` call `createAtomRequestHandler` and check `getAuthenticatedUsername()` first, so an anonymous request never reached the body. With this change, any unauthenticated client can make the server buffer up to 10 MB and run a full XML parse on every request. Authenticate before `readBody`. Calling `createAtomRequestHandler` twice would run authentication twice, which matters for OAuth nonces. So create the handler once here, return 401 if no user is authenticated, and store the handler in a request attribute that an overridden `createAtomRequestHandler` returns. Add a test that an unauthenticated entry POST never reads the input stream. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
