snoopdave commented on code in PR #198:
URL: https://github.com/apache/roller/pull/198#discussion_r4174841687


##########
app/src/main/java/org/apache/roller/weblogger/webservices/atomprotocol/RollerAtomServlet.java:
##########
@@ -0,0 +1,193 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ *  contributor license agreements.  The ASF licenses this file to You
+ * under the Apache License, Version 2.0 (the "License"); you may not
+ * use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.  For additional information regarding
+ * copyright in this work, please see the NOTICE file in the top level
+ * directory of this distribution.
+ */
+
+package org.apache.roller.weblogger.webservices.atomprotocol;
+
+import java.io.BufferedReader;
+import java.io.ByteArrayInputStream;
+import java.io.ByteArrayOutputStream;
+import java.io.IOException;
+import java.io.InputStream;
+import java.io.InputStreamReader;
+import java.nio.charset.StandardCharsets;
+import javax.servlet.ReadListener;
+import javax.servlet.ServletException;
+import javax.servlet.ServletInputStream;
+import javax.servlet.http.HttpServletRequest;
+import javax.servlet.http.HttpServletRequestWrapper;
+import javax.servlet.http.HttpServletResponse;
+
+import com.rometools.propono.atom.server.AtomServlet;
+import org.apache.commons.logging.Log;
+import org.apache.commons.logging.LogFactory;
+import org.apache.roller.weblogger.config.WebloggerRuntimeConfig;
+import org.apache.roller.weblogger.util.SafeSAXBuilder;
+import org.jdom2.JDOMException;
+
+/**
+ * Roller's AtomPub endpoint. It answers only while
+ * <code>webservices.enableAtomPub</code> is on, and it reads each Atom entry
+ * body with Roller's shared XML parser settings before the Propono servlet
+ * handles the request.
+ */
+public class RollerAtomServlet extends AtomServlet {
+
+    private static final long serialVersionUID = 1L;
+
+    private static final Log LOG = LogFactory.getLog(RollerAtomServlet.class);
+
+    /** Largest Atom entry body accepted, in bytes. Media uploads are not 
affected. */
+    static final int MAX_ENTRY_BYTES = 10 * 1024 * 1024;
+
+    private static final String ATOM_CONTENT_TYPE = "application/atom+xml";
+
+    @Override
+    protected void service(HttpServletRequest req, HttpServletResponse res)
+            throws ServletException, IOException {
+
+        if 
(!WebloggerRuntimeConfig.getBooleanProperty("webservices.enableAtomPub")) {
+            LOG.debug("AtomPub service is disabled; rejecting request");
+            sendText(res, HttpServletResponse.SC_NOT_FOUND, "AtomPub service 
is disabled");
+            return;
+        }
+
+        if (!carriesEntry(req)) {
+            forward(req, res);
+            return;
+        }
+
+        byte[] body = readBody(req.getInputStream());

Review Comment:
   🐞Claude Issue: **Important:** The body is now read and parsed before 
authentication. In Propono, `doPost` and `doPut` call 
`createAtomRequestHandler` and check `getAuthenticatedUsername()` first, so an 
anonymous request never reached the body. With this change, any unauthenticated 
client can make the server buffer up to 10 MB and run a full XML parse on every 
request.
   
   Authenticate before `readBody`. Calling `createAtomRequestHandler` twice 
would run authentication twice, which matters for OAuth nonces. So create the 
handler once here, return 401 if no user is authenticated, and store the 
handler in a request attribute that an overridden `createAtomRequestHandler` 
returns. Add a test that an unauthenticated entry POST never reads the input 
stream.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to