mattcasters opened a new pull request, #8164: URL: https://github.com/apache/hop/pull/8164
fixes #8163 `XmlInputStream` created a raw StAX `XMLInputFactory` and never disabled DTD processing or external entity resolution. Other Hop XML parsers already go through `XmlParserFactoryProducer` (DOM/SAX/Schema) or set the two StAX flags locally. This adds `XmlParserFactoryProducer.createSecureXmlInputFactory()` (`SUPPORT_DTD=false`, `IS_SUPPORTING_EXTERNAL_ENTITIES=false`, best-effort `ACCESS_EXTERNAL_DTD/SCHEMA`) and uses it from: - `XmlInputStream` (the reported sink) - `WebService` (SOAP/HTTP responses) - `XmlFormatter` - `AdvancedXmlOutput` and Excel `StaxUtil` (already local flags; they now share the helper) **Behavior change:** XML documents that contain a DOCTYPE will fail to parse. That is the intended trade-off. ## Tests - Factory property assertions and a canary-file external-entity test in `XmlUtilsTest` - `XmlInputStreamTest` regression that the canary is not emitted as row data Targeted unit tests: `./mvnw -pl core,plugins/transforms/xml,plugins/transforms/excel,plugins/transforms/webservices -am test -Pskip-uitest` ------------------------ Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily: - [x] Run `mvn clean install apache-rat:check` to make sure basic checks pass. A more thorough check will be performed on your pull request automatically. - [x] If you have a group of commits related to the same change, please squash your commits into one and force push your branch using `git rebase -i`. - [x] Mention the appropriate issue in your description (for example: `addresses #123`), if applicable. To make clear that you license your contribution under the [Apache License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0) you have to acknowledge this by using the following check-box. - [x] I hereby declare this contribution to be licensed under the [Apache License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0) - [ ] In any other case, please file an [Apache Individual Contributor License Agreement](https://www.apache.org/licenses/icla.pdf). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
