ppkarwasz commented on code in PR #3262:
URL: https://github.com/apache/tika/pull/3262#discussion_r4115612600


##########
tika-core/src/main/java/org/apache/tika/utils/XMLReaderUtils.java:
##########
@@ -290,12 +290,8 @@ public static XMLInputFactory getXMLInputFactory() {
             LOG.debug("XMLInputFactory class {}", factory.getClass());
         }
 
-        tryToSetStaxProperty(factory, XMLInputFactory.IS_NAMESPACE_AWARE, 
true);
-
-        //try to configure secure processing
-        tryToSetStaxProperty(factory, XMLInputFactory.IS_VALIDATING, false);
+        //try to cause DTDs to throw exceptions
         tryToSetStaxProperty(factory, XMLInputFactory.SUPPORT_DTD, false);

Review Comment:
   I don't think the intention of #2294 was to throw whenever `DOCTYPE` is 
encountered: https://github.com/apache/tika/pull/3261#discussion_r4115582847
   
   Keeping this setting introduces a difference between the DOM / SAX and StAX 
paths. Since Commons Secure XML is about delegating responsibility about 
security-related configuration, I would remove all these settings,
   
   @tballison: could you clarify the maintainers' position regarding `DOCTYPE`? 
Do you want to actively ban them or are they acceptable as long as they don't 
generate security issues?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to