ppkarwasz opened a new pull request, #3537: URL: https://github.com/apache/cxf/pull/3537
Implements a small part of [CXF-9248](https://issues.apache.org/jira/browse/CXF-9248). Replaces the hand-hardened JAXP `DocumentBuilderFactory` and `SAXParserFactory` instances in main code with the factories from [Apache Commons Secure XML](https://commons.apache.org/proper/commons-secure-xml/) 1.1.0, which secure the parser whichever JAXP implementation is found. Previously, each call site set its own features and silently carried on when an implementation did not support one. - **Commit 1:** every DOM and SAX factory now comes from `SecureDocumentBuilderFactory` / `SecureSAXParserFactory`. A [forbidden-apis](https://github.com/policeman-tools/forbidden-apis) check rejects the JAXP factory methods in main code, so new usages cannot creep back in. - **Commit 2:** adds `DOMUtils.createNSDocumentBuilder(Schema)` and uses it in `XMLTypeCreator` and `ExtendedDocumentBuilder`. Both compile a schema that ships in their own artifact and imports nothing, so `SecureSchemaFactory` needs no resolver. A missing or invalid schema now throws `IllegalStateException` instead of silently disabling validation. Behavior changes: - The Xerces-only `disallow-doctype-decl` feature is no longer set. A DOCTYPE is accepted, but the external resources it names are not fetched. This assumes DOCTYPEs were rejected as a security measure, not because CXF considers such documents invalid. If they should be rejected as invalid, a `LexicalHandler` that throws on `startDTD` would do that with a clearer error message. - A validating `ExtendedDocumentBuilder` no longer falls back to the non-validating StAX parser when the DOM implementation does not support `setSchema`. Every currently maintained implementation supports validation. > [!NOTE] > Commons Secure XML 1.1.0 is still being voted on, so `cxf-parent` temporarily adds the Apache staging repository after Maven Central. It must be removed before merging. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
