[ 
https://issues.apache.org/jira/browse/TIKA-4935?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18119849#comment-18119849
 ] 

ASF GitHub Bot commented on TIKA-4935:
--------------------------------------

Copilot commented on code in PR #3262:
URL: https://github.com/apache/tika/pull/3262#discussion_r4115687601


##########
tika-core/src/main/java/org/apache/tika/utils/XMLReaderUtils.java:
##########
@@ -290,12 +290,8 @@ public static XMLInputFactory getXMLInputFactory() {
             LOG.debug("XMLInputFactory class {}", factory.getClass());
         }
 
-        tryToSetStaxProperty(factory, XMLInputFactory.IS_NAMESPACE_AWARE, 
true);
-
-        //try to configure secure processing
-        tryToSetStaxProperty(factory, XMLInputFactory.IS_VALIDATING, false);
+        //try to cause DTDs to throw exceptions
         tryToSetStaxProperty(factory, XMLInputFactory.SUPPORT_DTD, false);

Review Comment:
   This keeps `SUPPORT_DTD` disabled, so any input containing a `DOCTYPE` with 
an internal declaration is rejected even when it has no external resource. That 
is a compatibility regression: the SAX/DOM paths accept the declaration and 
rely on the secure resolver to block external access, and the StAX factory 
should follow the same behavior. Please leave DTD support enabled and test that 
internal declarations are parsed while external entities remain unreadable.





> Delegate JAXP parser configuration to Apache Commons Secure XML
> ---------------------------------------------------------------
>
>                 Key: TIKA-4935
>                 URL: https://issues.apache.org/jira/browse/TIKA-4935
>             Project: Tika
>          Issue Type: Improvement
>            Reporter: Gary D. Gregory
>            Priority: Minor
>             Fix For: 4.1.0
>
>
> Tika maintains custom XML security configuration across SAX, DOM, StAX, and 
> XSLT processing. Adopt Apache Commons Secure XML 1.0.0 to centralize these 
> protections and reduce duplicated configuration and resolver code.
> PR [3261|https://github.com/apache/tika/pull/3261]:
>  * Uses Commons Secure XML factories in {{{}XMLReaderUtils{}}}, MIME type 
> loading, and XML-related tests.
>  * Removes manual SAX/DOM feature configuration, transformer external-access 
> attributes, and the custom StAX fallback resolver.
>  * Retains Tika’s configurable entity expansion limits, parser pooling, DOM 
> entity-reference settings, and StAX restrictions on DTD and external entity 
> processing.
>  * Routes async configuration writer document and transformer creation 
> through {{{}XMLReaderUtils{}}}.
>  * Adds Maven dependencies and updates the OSGi integration-test setup.
> Regression tests cover external entity blocking and external resource access 
> through XSLT {{{}document(){}}}, {{{}xsl:include{}}}, and {{xsl:import}} for 
> both transformer factory getters. They also verify that explicitly supplied 
> resolvers remain usable and that the async writer can create new XML 
> configurations and preserve existing configuration content.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to