Gary D. Gregory created TIKA-4935:
-------------------------------------

             Summary: Delegate JAXP parser configuration to Apache Commons 
Secure XML
                 Key: TIKA-4935
                 URL: https://issues.apache.org/jira/browse/TIKA-4935
             Project: Tika
          Issue Type: Improvement
            Reporter: Gary D. Gregory


Tika maintains custom XML security configuration across SAX, DOM, StAX, and 
XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these 
protections and reduce duplicated configuration and resolver code.

This change:
 * Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type 
loading, and XML-related tests.
 * Removes manual SAX/DOM feature configuration, transformer external-access 
attributes, and the custom StAX fallback resolver.
 * Retains Tika’s configurable entity expansion limits, parser pooling, DOM 
entity-reference settings, and StAX restrictions on DTD and external entity 
processing.
 * Routes async configuration writer document and transformer creation through 
{{{}XMLReaderUtils{}}}.
 * Adds Maven dependencies and updates the OSGi integration-test setup.

Regression tests cover external entity blocking and external resource access 
through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for 
both transformer factory getters. They also verify that explicitly supplied 
resolvers remain usable and that the async writer can create new XML 
configurations and preserve existing configuration content.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to