On Sun, 20 Sep 2026 07:48:04 GMT, Alan Bateman <[email protected]> wrote:

>> expandedSystemId is the URI resolved by the parser (with base id or working 
>> dir if not absolute), and against which the property checks. If the resource 
>> requested by the XML document is permitted by the specified rule, the parser 
>> proceeds to establish the connection. HTTP redirects occur after this check 
>> and are outside the parser's control.
>> 
>> A redirect will work as expected if access rule is specified against the 
>> originally requested resource. For example, if a site hosting DTDs is moved 
>> or retired, requests to those DTDs can continue to work when they are 
>> redirected to a new host.
>
> Thanks, I need to mull over this and whether disabling redirects might be 
> required in some cases.

An example: http://java.sun.com/dtd/web-app_2_3.dtd is now redirected to 
https://www.oracle.com/webfolder/technetwork/jsc/dtd/web-app_2_3.dtd

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/32098#discussion_r4057766897

Reply via email to