[ 
https://issues.apache.org/jira/browse/TIKA-4935?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Gary D. Gregory updated TIKA-4935:
----------------------------------
    Description: 
Tika maintains custom XML security configuration across SAX, DOM, StAX, and 
XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these 
protections and reduce duplicated configuration and resolver code.

PR [3261|https://github.com/apache/tika/pull/3261]:
 * Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type 
loading, and XML-related tests.
 * Removes manual SAX/DOM feature configuration, transformer external-access 
attributes, and the custom StAX fallback resolver.
 * Retains Tika’s configurable entity expansion limits, parser pooling, DOM 
entity-reference settings, and StAX restrictions on DTD and external entity 
processing.
 * Routes async configuration writer document and transformer creation through 
{{{}XMLReaderUtils{}}}.
 * Adds Maven dependencies and updates the OSGi integration-test setup.

Regression tests cover external entity blocking and external resource access 
through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for 
both transformer factory getters. They also verify that explicitly supplied 
resolvers remain usable and that the async writer can create new XML 
configurations and preserve existing configuration content.

  was:
Tika maintains custom XML security configuration across SAX, DOM, StAX, and 
XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these 
protections and reduce duplicated configuration and resolver code.

This change:
 * Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type 
loading, and XML-related tests.
 * Removes manual SAX/DOM feature configuration, transformer external-access 
attributes, and the custom StAX fallback resolver.
 * Retains Tika’s configurable entity expansion limits, parser pooling, DOM 
entity-reference settings, and StAX restrictions on DTD and external entity 
processing.
 * Routes async configuration writer document and transformer creation through 
{{{}XMLReaderUtils{}}}.
 * Adds Maven dependencies and updates the OSGi integration-test setup.

Regression tests cover external entity blocking and external resource access 
through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for 
both transformer factory getters. They also verify that explicitly supplied 
resolvers remain usable and that the async writer can create new XML 
configurations and preserve existing configuration content.


> Delegate JAXP parser configuration to Apache Commons Secure XML
> ---------------------------------------------------------------
>
>                 Key: TIKA-4935
>                 URL: https://issues.apache.org/jira/browse/TIKA-4935
>             Project: Tika
>          Issue Type: Improvement
>            Reporter: Gary D. Gregory
>            Priority: Minor
>
> Tika maintains custom XML security configuration across SAX, DOM, StAX, and 
> XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these 
> protections and reduce duplicated configuration and resolver code.
> PR [3261|https://github.com/apache/tika/pull/3261]:
>  * Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type 
> loading, and XML-related tests.
>  * Removes manual SAX/DOM feature configuration, transformer external-access 
> attributes, and the custom StAX fallback resolver.
>  * Retains Tika’s configurable entity expansion limits, parser pooling, DOM 
> entity-reference settings, and StAX restrictions on DTD and external entity 
> processing.
>  * Routes async configuration writer document and transformer creation 
> through {{{}XMLReaderUtils{}}}.
>  * Adds Maven dependencies and updates the OSGi integration-test setup.
> Regression tests cover external entity blocking and external resource access 
> through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for 
> both transformer factory getters. They also verify that explicitly supplied 
> resolvers remain usable and that the async writer can create new XML 
> configurations and preserve existing configuration content.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to