garydgregory commented on code in PR #1427: URL: https://github.com/apache/knox/pull/1427#discussion_r4098765824
########## gateway-util-common/src/main/java/org/apache/knox/gateway/util/XmlUtils.java: ########## @@ -22,41 +22,81 @@ import java.io.Writer; import java.nio.file.Files; -import javax.xml.XMLConstants; +import jakarta.xml.bind.JAXBException; +import jakarta.xml.bind.Unmarshaller; import javax.xml.parsers.DocumentBuilder; -import javax.xml.parsers.DocumentBuilderFactory; import javax.xml.parsers.ParserConfigurationException; +import javax.xml.stream.XMLStreamException; import javax.xml.transform.OutputKeys; import javax.xml.transform.Transformer; import javax.xml.transform.TransformerException; import javax.xml.transform.TransformerFactory; import javax.xml.transform.dom.DOMSource; import javax.xml.transform.stream.StreamResult; +import org.apache.commons.xml.secure.SecureDocumentBuilderFactory; +import org.apache.commons.xml.secure.SecureTransformerFactory; +import org.apache.commons.xml.secure.SecureXMLInputFactory; import org.w3c.dom.Document; import org.xml.sax.InputSource; import org.xml.sax.SAXException; +/** + * XML parsing and serialization helpers. + * + * <p>Factories come from <a href="https://commons.apache.org/proper/commons-secure-xml/">Apache Commons Secure XML</a>, + * which ignores external resources (DTDs, entities, XInclude, stylesheets).</p> + */ public class XmlUtils { public static Document readXml( File file ) throws ParserConfigurationException, IOException, SAXException { - return readXml(Files.newInputStream(file.toPath())); + try (InputStream input = Files.newInputStream(file.toPath())) { + return readXml(input); + } } public static Document readXml( InputStream input ) throws ParserConfigurationException, IOException, SAXException { - DocumentBuilderFactory f = DocumentBuilderFactory.newInstance(); - f.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, Boolean.TRUE); - f.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); - DocumentBuilder b = f.newDocumentBuilder(); - return b.parse( input ); + return newDocumentBuilder().parse( input ); } public static Document readXml( InputSource source ) throws ParserConfigurationException, IOException, SAXException { - DocumentBuilderFactory f = DocumentBuilderFactory.newInstance(); - f.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, Boolean.TRUE); - f.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); - DocumentBuilder b = f.newDocumentBuilder(); - return b.parse( source ); + return newDocumentBuilder().parse( source ); + } + + /** + * Unmarshals the XML content of a file. + * + * @param unmarshaller the JAXB unmarshaller to use + * @param type the expected type of the root object + * @param file the file to read + * @param <T> the expected type of the root object + * @return the root object of the content tree + * @throws IOException if the file cannot be read + * @throws JAXBException if the content cannot be parsed or unmarshalled + */ Review Comment: @ppkarwasz Use Javadoc `since` tags on new `public` and `protected` elements? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
