github-advanced-security[bot] commented on code in PR #198:
URL: https://github.com/apache/roller/pull/198#discussion_r4177558270


##########
app/src/main/java/org/apache/roller/weblogger/webservices/atomprotocol/RollerAtomServlet.java:
##########
@@ -0,0 +1,215 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ *  contributor license agreements.  The ASF licenses this file to You
+ * under the Apache License, Version 2.0 (the "License"); you may not
+ * use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.  For additional information regarding
+ * copyright in this work, please see the NOTICE file in the top level
+ * directory of this distribution.
+ */
+
+package org.apache.roller.weblogger.webservices.atomprotocol;
+
+import java.io.BufferedReader;
+import java.io.ByteArrayInputStream;
+import java.io.ByteArrayOutputStream;
+import java.io.IOException;
+import java.io.InputStream;
+import java.io.InputStreamReader;
+import java.nio.charset.StandardCharsets;
+import javax.servlet.ReadListener;
+import javax.servlet.ServletException;
+import javax.servlet.ServletInputStream;
+import javax.servlet.http.HttpServletRequest;
+import javax.servlet.http.HttpServletRequestWrapper;
+import javax.servlet.http.HttpServletResponse;
+
+import com.rometools.propono.atom.server.AtomHandler;
+import com.rometools.propono.atom.server.AtomServlet;
+import org.apache.commons.logging.Log;
+import org.apache.commons.logging.LogFactory;
+import org.apache.roller.weblogger.config.WebloggerRuntimeConfig;
+import org.apache.roller.weblogger.util.SafeSAXBuilder;
+import org.jdom2.JDOMException;
+
+/**
+ * Roller's AtomPub endpoint. It answers only while
+ * <code>webservices.enableAtomPub</code> is on, and it reads each Atom entry
+ * body with Roller's shared XML parser settings before the Propono servlet
+ * handles the request.
+ */
+public class RollerAtomServlet extends AtomServlet {
+
+    private static final long serialVersionUID = 1L;
+
+    private static final Log LOG = LogFactory.getLog(RollerAtomServlet.class);
+
+    /** Largest Atom entry body accepted, in bytes. Media uploads are not 
affected. */
+    static final int MAX_ENTRY_BYTES = 10 * 1024 * 1024;
+
+    private static final String ATOM_CONTENT_TYPE = "application/atom+xml";
+
+    /**
+     * Request attribute that carries the handler authenticated by this servlet
+     * to {@link RollerAtomHandlerFactory}, so Propono does not authenticate 
the
+     * request a second time.
+     */
+    static final String HANDLER_ATTRIBUTE = RollerAtomServlet.class.getName() 
+ ".handler";
+
+    @Override
+    protected void service(HttpServletRequest req, HttpServletResponse res)
+            throws ServletException, IOException {
+
+        if 
(!WebloggerRuntimeConfig.getBooleanProperty("webservices.enableAtomPub")) {
+            LOG.debug("AtomPub service is disabled; rejecting request");
+            sendText(res, HttpServletResponse.SC_NOT_FOUND, "AtomPub service 
is disabled");
+            return;
+        }
+
+        if (!carriesEntry(req)) {
+            forward(req, res);
+            return;
+        }
+
+        // Authenticate before reading the body, as Propono does.
+        AtomHandler handler = createHandler(req, res);
+        if (handler.getAuthenticatedUsername() == null) {
+            res.setHeader("WWW-Authenticate", "BASIC realm=\"AtomPub\"");
+            res.sendError(HttpServletResponse.SC_UNAUTHORIZED);
+            return;
+        }
+        req.setAttribute(HANDLER_ATTRIBUTE, handler);
+
+        byte[] body = readBody(req.getInputStream());
+        if (body == null) {
+            sendText(res, HttpServletResponse.SC_REQUEST_ENTITY_TOO_LARGE, 
"Entry is too large");
+            return;
+        }
+        try {
+            // Propono reads the entry as UTF-8 text, so check the same text.
+            new SafeSAXBuilder().build(new InputStreamReader(
+                    new ByteArrayInputStream(body), StandardCharsets.UTF_8));

Review Comment:
   ## CodeQL / Resolving XML external entity in user-controlled data
   
   XML parsing depends on a [user-provided value](1) without guarding against 
external entity expansion.
   
   [Show more 
details](https://github.com/apache/roller/security/code-scanning/133)



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to