[
https://issues.apache.org/jira/browse/TIKA-4935?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Gary D. Gregory updated TIKA-4935:
----------------------------------
Description:
Tika maintains custom XML security configuration across SAX, DOM, StAX, and
XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these
protections and reduce duplicated configuration and resolver code.
PR [3261|https://github.com/apache/tika/pull/3261]:
* Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type
loading, and XML-related tests.
* Removes manual SAX/DOM feature configuration, transformer external-access
attributes, and the custom StAX fallback resolver.
* Retains Tika’s configurable entity expansion limits, parser pooling, DOM
entity-reference settings, and StAX restrictions on DTD and external entity
processing.
* Routes async configuration writer document and transformer creation through
{{{}XMLReaderUtils{}}}.
* Adds Maven dependencies and updates the OSGi integration-test setup.
Regression tests cover external entity blocking and external resource access
through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for
both transformer factory getters. They also verify that explicitly supplied
resolvers remain usable and that the async writer can create new XML
configurations and preserve existing configuration content.
was:
Tika maintains custom XML security configuration across SAX, DOM, StAX, and
XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these
protections and reduce duplicated configuration and resolver code.
This change:
* Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type
loading, and XML-related tests.
* Removes manual SAX/DOM feature configuration, transformer external-access
attributes, and the custom StAX fallback resolver.
* Retains Tika’s configurable entity expansion limits, parser pooling, DOM
entity-reference settings, and StAX restrictions on DTD and external entity
processing.
* Routes async configuration writer document and transformer creation through
{{{}XMLReaderUtils{}}}.
* Adds Maven dependencies and updates the OSGi integration-test setup.
Regression tests cover external entity blocking and external resource access
through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for
both transformer factory getters. They also verify that explicitly supplied
resolvers remain usable and that the async writer can create new XML
configurations and preserve existing configuration content.
> Delegate JAXP parser configuration to Apache Commons Secure XML
> ---------------------------------------------------------------
>
> Key: TIKA-4935
> URL: https://issues.apache.org/jira/browse/TIKA-4935
> Project: Tika
> Issue Type: Improvement
> Reporter: Gary D. Gregory
> Priority: Minor
>
> Tika maintains custom XML security configuration across SAX, DOM, StAX, and
> XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these
> protections and reduce duplicated configuration and resolver code.
> PR [3261|https://github.com/apache/tika/pull/3261]:
> * Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type
> loading, and XML-related tests.
> * Removes manual SAX/DOM feature configuration, transformer external-access
> attributes, and the custom StAX fallback resolver.
> * Retains Tika’s configurable entity expansion limits, parser pooling, DOM
> entity-reference settings, and StAX restrictions on DTD and external entity
> processing.
> * Routes async configuration writer document and transformer creation
> through {{{}XMLReaderUtils{}}}.
> * Adds Maven dependencies and updates the OSGi integration-test setup.
> Regression tests cover external entity blocking and external resource access
> through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for
> both transformer factory getters. They also verify that explicitly supplied
> resolvers remain usable and that the async writer can create new XML
> configurations and preserve existing configuration content.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)