matrei opened a new pull request, #16392:
URL: https://github.com/apache/grails-core/pull/16392

   ## Summary
   
   `SpringIOUtils.createParserFactory()` (`grails-gradle-model`) and the HTTP 
test client's `XmlUtils` set their SAX parser features with 
`https://xml.org/...` and `https://apache.org/...` names. The parser only 
recognises the registered `http://` forms, so every `setFeature` call was 
rejected with `SAXNotRecognizedException` and the empty `catch` swallowed it. 
Only `FEATURE_SECURE_PROCESSING` took effect.
   
   Secure processing makes the JDK parser refuse to read external resources, 
but it does so by throwing. As a result, any document that referenced an 
external DTD or an external entity failed to parse instead of having the 
reference skipped. That includes descriptors with a DOCTYPE pointing at a DTD 
URL (for example the JSP 1.2 TLD form), parsed through `createXmlSlurper()`.
   
   This is the narrow 7.0.x counterpart of the identifier correction in #16331 
on `8.0.x`. The rest of #16331 (rejecting DOCTYPE by default, the 
`grails.xml.allowDocTypeDeclaration` setting, the strict/tolerant parser split 
and `XmlParserFeature`) changes behaviour and stays on `8.0.x`.
   
   ## Changes
   
   - `SpringIOUtils` and `XmlUtils` use the registered `http://` feature names. 
Every feature keeps the value 7.0.x already sets:
     - DOCTYPE declarations are still allowed and internal entities still 
expand.
     - External general entities, external parameter entities and external DTDs 
are now skipped rather than causing a parse failure.
   
   ## Testing
   
   - New `SpringIOUtilsSpec` in `grails-gradle/model`, adapted from #16331 to 
7.0.x behaviour. Five of its eight features fail without the fix, with 
"External DTD" or "External Entity" parse errors.
   - `XmlUtilsSpec` and `TestHttpResponseSpec` expected the old parse error for 
an external entity; they now check that the file contents are not included. 
`XmlUtilsSpec` gains the external parameter entity and external DTD cases. The 
four updated features fail without the fix.
   - Test results with the fix:
     - `:grails-gradle-model:test` (57 tests) and 
`:grails-testing-support-http-client:test` (106 tests) pass.
     - The `SpringIOUtils` caller modules pass: `grails-converters`, 
`grails-core`, `grails-web-databinding` and `grails-test-suite-web`.
     - Root `codeStyle` and `grails-gradle`'s `:grails-gradle-model:codeStyle` 
pass.
   
   ## Merge-up note
   
   These files were reworked on `8.0.x` by #16331. When `7.0.x` is merged up, 
keep the `8.0.x` side for `SpringIOUtils.java`, `XmlUtils.groovy`, 
`SpringIOUtilsSpec`, `XmlUtilsSpec` and `TestHttpResponseSpec`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to