[ 
https://issues.apache.org/jira/browse/CALCITE-7790?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated CALCITE-7790:
------------------------------------
    Labels: pull-request-available  (was: )

> XmlFunctions: XMLTRANSFORM should parse its XML argument through the shared 
> DocumentBuilder and set explicit JAXP external-access attributes on the 
> TransformerFactory
> ----------------------------------------------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: CALCITE-7790
>                 URL: https://issues.apache.org/jira/browse/CALCITE-7790
>             Project: Calcite
>          Issue Type: Task
>            Reporter: Ruben Q L
>            Assignee: Ruben Q L
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 1.43.0
>
>
> {{XmlFunctions.xmlTransform}} currently hands its XML argument to 
> {{TransformerFactory}} as a raw StreamSource wrapping a StringReader, unlike 
> the other functions in this class ({{EXTRACT_VALUE}}, {{EXTRACT_XML}}, 
> {{EXISTSNODE}}) which parse the XML argument through the shared, hardened 
> {{DocumentBuilder}} set up in CALCITE-5263. This inconsistency means the 
> DOCTYPE and entity-handling policy configured on {{DOCUMENT_BUILDER_FACTORY}} 
> does not apply to XMLTRANSFORM; DTD and entity handling on the transform path 
> is governed entirely by the reader defaults of whichever JAXP provider is 
> resolved by {{TransformerFactory.newInstance()}}. Route the XML argument 
> through {{getDocumentNode}} (as a {{DOMSource}}) so all XML inputs in 
> {{XmlFunctions}} are parsed with the same configuration.
> Separately, the shared {{TransformerFactory}} initializer sets 
> {{FEATURE_SECURE_PROCESSING=true}} but does not set the JAXP 1.5 attributes 
> {{ACCESS_EXTERNAL_DTD}} and {{ACCESS_EXTERNAL_STYLESHEET}}. On the JDK's 
> built-in transformer, secure processing already restricts those attributes to 
> the empty string as a documented side effect, but 
> {{TransformerFactory.newInstance()}} is a {{ServiceLoader}} lookup and may 
> resolve a different implementation on some classpaths where that side effect 
> does not apply. Set the attributes explicitly, and fail the initializer if 
> the provider does not accept them (the same fail-closed pattern that 
> {{DOCUMENT_BUILDER_FACTORY}} already uses for disallow-doctype-decl).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to