This is an automated email from the ASF dual-hosted git repository.

ashishvijaywargiya pushed a commit to branch release24.09
in repository https://gitbox.apache.org/repos/asf/ofbiz-framework.git


The following commit(s) were added to refs/heads/release24.09 by this push:
     new 3008785904 Improved: Build an explicit DocumentBuilder for XML-typed 
content rendering in ContentWorker (#1731) (#1733)
3008785904 is described below

commit 30087859042cf6f13b911e93429b6a5ea93cab99
Author: Ashish Vijaywargiya <[email protected]>
AuthorDate: Tue Aug 25 17:46:04 2026 +0530

    Improved: Build an explicit DocumentBuilder for XML-typed content rendering 
in ContentWorker (#1731) (#1733)
    
    - Parse XML-typed DataResource content in
    ContentWorker.renderContentAsText with a DocumentBuilder that is built
    and configured directly here, instead of relying on FreeMarker's default
    NodeModel.parse setup.
    
    - Hand the resulting Document to NodeModel.wrap.
    
    - Aligns the XML parser configuration used for stored content with the
    explicit parser setup already used elsewhere in the codebase
    (EntitySaxReader, UtilXml).
    
    Thank you Krishna Uprit for the contribution.
    
    (cherry picked from commit 3160607a42d835a813061866a32316bbbb1897b0)
    
    Co-authored-by: Krishna Uprit <[email protected]>
    Co-authored-by: Krishnauprit18 <[email protected]>
---
 .../ofbiz/content/content/ContentWorker.java       | 22 +++++++++++++++++++++-
 1 file changed, 21 insertions(+), 1 deletion(-)

diff --git 
a/applications/content/src/main/java/org/apache/ofbiz/content/content/ContentWorker.java
 
b/applications/content/src/main/java/org/apache/ofbiz/content/content/ContentWorker.java
index 3309d90528..f7895cb53a 100644
--- 
a/applications/content/src/main/java/org/apache/ofbiz/content/content/ContentWorker.java
+++ 
b/applications/content/src/main/java/org/apache/ofbiz/content/content/ContentWorker.java
@@ -29,6 +29,8 @@ import java.util.List;
 import java.util.Locale;
 import java.util.Map;
 
+import javax.xml.XMLConstants;
+import javax.xml.parsers.DocumentBuilderFactory;
 import javax.xml.parsers.ParserConfigurationException;
 
 import org.apache.ofbiz.base.util.Debug;
@@ -59,6 +61,7 @@ import org.apache.ofbiz.service.GenericServiceException;
 import org.apache.ofbiz.service.LocalDispatcher;
 import org.apache.ofbiz.service.ModelService;
 import org.apache.ofbiz.service.ServiceUtil;
+import org.w3c.dom.Document;
 import org.xml.sax.InputSource;
 import org.xml.sax.SAXException;
 
@@ -317,7 +320,24 @@ public class ContentWorker implements 
org.apache.ofbiz.widget.content.ContentWor
                         if 
("FTL".equals(templateDataResource.getString("dataTemplateTypeId"))) {
                             StringReader sr = new StringReader(textData);
                             try {
-                                NodeModel nodeModel = NodeModel.parse(new 
InputSource(sr));
+                                // NodeModel.parse(InputSource) uses 
FreeMarker's default, unhardened
+                                // DocumentBuilderFactory, which resolves 
external entities/DTDs (XXE, CWE-611).
+                                // Parse with a hardened factory ourselves and 
wrap the resulting DOM instead,
+                                // matching the entity-resolution lockdown 
already used by EntitySaxReader.
+                                // 
namespaceAware/ignoringElementContentWhitespace are kept identical to
+                                // FreeMarker's own NodeModel default factory 
to preserve existing template
+                                // behavior for namespaced or 
whitespace-sensitive XML content.
+                                DocumentBuilderFactory factory = 
DocumentBuilderFactory.newInstance();
+                                factory.setNamespaceAware(true);
+                                
factory.setIgnoringElementContentWhitespace(true);
+                                
factory.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);
+                                
factory.setFeature("http://xml.org/sax/features/external-general-entities";, 
false);
+                                
factory.setFeature("http://xml.org/sax/features/external-parameter-entities";, 
false);
+                                
factory.setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd";,
 false);
+                                factory.setXIncludeAware(false);
+                                factory.setExpandEntityReferences(false);
+                                Document document = 
factory.newDocumentBuilder().parse(new InputSource(sr));
+                                NodeModel nodeModel = NodeModel.wrap(document);
                                 templateContext.put("doc", nodeModel);
                             } catch (SAXException | 
ParserConfigurationException e) {
                                 throw new GeneralException(e.getMessage());

Reply via email to