Copilot commented on code in PR #3262:
URL: https://github.com/apache/tika/pull/3262#discussion_r4115687601


##########
tika-core/src/main/java/org/apache/tika/utils/XMLReaderUtils.java:
##########
@@ -290,12 +290,8 @@ public static XMLInputFactory getXMLInputFactory() {
             LOG.debug("XMLInputFactory class {}", factory.getClass());
         }
 
-        tryToSetStaxProperty(factory, XMLInputFactory.IS_NAMESPACE_AWARE, 
true);
-
-        //try to configure secure processing
-        tryToSetStaxProperty(factory, XMLInputFactory.IS_VALIDATING, false);
+        //try to cause DTDs to throw exceptions
         tryToSetStaxProperty(factory, XMLInputFactory.SUPPORT_DTD, false);

Review Comment:
   This keeps `SUPPORT_DTD` disabled, so any input containing a `DOCTYPE` with 
an internal declaration is rejected even when it has no external resource. That 
is a compatibility regression: the SAX/DOM paths accept the declaration and 
rely on the secure resolver to block external access, and the StAX factory 
should follow the same behavior. Please leave DTD support enabled and test that 
internal declarations are parsed while external entities remain unreadable.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to