ppkarwasz commented on code in PR #2635:
URL: https://github.com/apache/activemq/pull/2635#discussion_r4178610463
##########
activemq-broker/src/main/java/org/apache/activemq/util/XmlFactories.java:
##########
@@ -35,42 +35,11 @@ public final class XmlFactories {
private XmlFactories() { /* Do not instantiate */ }
public static DocumentBuilderFactory getSafeDocumentBuilderFactory() {
- DocumentBuilderFactory builderFactory =
DocumentBuilderFactory.newInstance();
-
- // See
https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.md#java
- trySetFeature(builderFactory, XMLConstants.FEATURE_SECURE_PROCESSING,
true);
-
trySetFeature(builderFactory,"http://apache.org/xml/features/disallow-doctype-decl",
true);
-
trySetFeature(builderFactory,"http://xml.org/sax/features/external-general-entities",
false);
-
trySetFeature(builderFactory,"http://xml.org/sax/features/external-parameter-entities",
false);
-
trySetFeature(builderFactory,"http://apache.org/xml/features/nonvalidating/load-external-dtd",
false);
-
- return builderFactory;
+ return SecureDocumentBuilderFactory.newInstance();
Review Comment:
What about inlinining this method and deprecating this class?
This method has only **two** callers and both could just use
`newNSDocumentBuilder` that we are about to be introduced in version `1.1.0`.
A small difference in the two callers would need to be settled:
- `RuntimeConfigurationBroker#loadConfiguration` uses a namepace-aware
parser and retrieves the broker element via:
```java
doc.getElementsByTagNameNS("*","broker").item(0);
```
- `CreateCommand#copyActivemqConf` uses a namespace-unaware parser and
retrieves the same broker element via `XPath`.
I think both could use a namespace-aware parser
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact