matrei opened a new pull request, #16392: URL: https://github.com/apache/grails-core/pull/16392
## Summary `SpringIOUtils.createParserFactory()` (`grails-gradle-model`) and the HTTP test client's `XmlUtils` set their SAX parser features with `https://xml.org/...` and `https://apache.org/...` names. The parser only recognises the registered `http://` forms, so every `setFeature` call was rejected with `SAXNotRecognizedException` and the empty `catch` swallowed it. Only `FEATURE_SECURE_PROCESSING` took effect. Secure processing makes the JDK parser refuse to read external resources, but it does so by throwing. As a result, any document that referenced an external DTD or an external entity failed to parse instead of having the reference skipped. That includes descriptors with a DOCTYPE pointing at a DTD URL (for example the JSP 1.2 TLD form), parsed through `createXmlSlurper()`. This is the narrow 7.0.x counterpart of the identifier correction in #16331 on `8.0.x`. The rest of #16331 (rejecting DOCTYPE by default, the `grails.xml.allowDocTypeDeclaration` setting, the strict/tolerant parser split and `XmlParserFeature`) changes behaviour and stays on `8.0.x`. ## Changes - `SpringIOUtils` and `XmlUtils` use the registered `http://` feature names. Every feature keeps the value 7.0.x already sets: - DOCTYPE declarations are still allowed and internal entities still expand. - External general entities, external parameter entities and external DTDs are now skipped rather than causing a parse failure. ## Testing - New `SpringIOUtilsSpec` in `grails-gradle/model`, adapted from #16331 to 7.0.x behaviour. Five of its eight features fail without the fix, with "External DTD" or "External Entity" parse errors. - `XmlUtilsSpec` and `TestHttpResponseSpec` expected the old parse error for an external entity; they now check that the file contents are not included. `XmlUtilsSpec` gains the external parameter entity and external DTD cases. The four updated features fail without the fix. - Test results with the fix: - `:grails-gradle-model:test` (57 tests) and `:grails-testing-support-http-client:test` (106 tests) pass. - The `SpringIOUtils` caller modules pass: `grails-converters`, `grails-core`, `grails-web-databinding` and `grails-test-suite-web`. - Root `codeStyle` and `grails-gradle`'s `:grails-gradle-model:codeStyle` pass. ## Merge-up note These files were reworked on `8.0.x` by #16331. When `7.0.x` is merged up, keep the `8.0.x` side for `SpringIOUtils.java`, `XmlUtils.groovy`, `SpringIOUtilsSpec`, `XmlUtilsSpec` and `TestHttpResponseSpec`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
