ppkarwasz commented on code in PR #766:
URL: https://github.com/apache/commons-text/pull/766#discussion_r3945049686
##########
src/main/java/org/apache/commons/text/lookup/XmlStringLookup.java:
##########
@@ -128,14 +130,21 @@ public String lookup(final String key) {
}
final String documentPath = keys[0];
final String xpath = StringUtils.substringAfterLast(key, SPLIT_CH);
- final DocumentBuilderFactory dbFactory =
DocumentBuilderFactory.newInstance();
+ // The secure factory installs a non-removable resolver floor that
ignores the JAXP access properties,
+ // so the documented opt-outs keep a plain factory: a feature map
without secure processing, or the
+ // standard javax.xml.accessExternalDTD system property re-allowing
external access.
+ final boolean secure =
Boolean.TRUE.equals(xmlFactoryFeatures.get(XMLConstants.FEATURE_SECURE_PROCESSING))
Review Comment:
Yes, although right now there is not way to have a test with “external
entities on”.
In one of the tests I see a property `XmlStringLookup.secure` being set, but
I don't see that property being used anywhere in the code: was there every such
a property?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]