ppkarwasz opened a new pull request, #3537:
URL: https://github.com/apache/cxf/pull/3537

   Implements a small part of 
[CXF-9248](https://issues.apache.org/jira/browse/CXF-9248).
   
   Replaces the hand-hardened JAXP `DocumentBuilderFactory` and 
`SAXParserFactory` instances in main code with the factories from [Apache 
Commons Secure XML](https://commons.apache.org/proper/commons-secure-xml/) 
1.1.0, which secure the parser whichever JAXP implementation is found. 
Previously, each call site set its own features and silently carried on when an 
implementation did not support one.
   
   - **Commit 1:** every DOM and SAX factory now comes from 
`SecureDocumentBuilderFactory` / `SecureSAXParserFactory`. A 
[forbidden-apis](https://github.com/policeman-tools/forbidden-apis) check 
rejects the JAXP factory methods in main code, so new usages cannot creep back 
in.
   - **Commit 2:** adds `DOMUtils.createNSDocumentBuilder(Schema)` and uses it 
in `XMLTypeCreator` and `ExtendedDocumentBuilder`. Both compile a schema that 
ships in their own artifact and imports nothing, so `SecureSchemaFactory` needs 
no resolver. A missing or invalid schema now throws `IllegalStateException` 
instead of silently disabling validation.
   
   Behavior changes:
   
   - The Xerces-only `disallow-doctype-decl` feature is no longer set. A 
DOCTYPE is accepted, but the external resources it names are not fetched. This 
assumes DOCTYPEs were rejected as a security measure, not because CXF considers 
such documents invalid. If they should be rejected as invalid, a 
`LexicalHandler` that throws on `startDTD` would do that with a clearer error 
message.
   - A validating `ExtendedDocumentBuilder` no longer falls back to the 
non-validating StAX parser when the DOM implementation does not support 
`setSchema`. Every currently maintained implementation supports validation.
   
   > [!NOTE]
   > Commons Secure XML 1.1.0 is still being voted on, so `cxf-parent` 
temporarily adds the Apache staging repository after Maven Central. It must be 
removed before merging.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to