[ 
https://issues.apache.org/jira/browse/CAMEL-25224?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen updated CAMEL-25224:
--------------------------------
    Fix Version/s: 4.22.2

> camel-xslt / camel-xslt-saxon: implicitly converted DOM sources select wrong 
> XSLT context node
> ----------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25224
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25224
>             Project: Camel
>          Issue Type: Bug
>            Reporter: Salvatore Mongiardo
>            Assignee: Salvatore Mongiardo
>            Priority: Major
>             Fix For: 4.22.2, 4.23.0
>
>
> When a CXF payload (or any body implicitly converted to a +DOMSource+) 
> reaches the XSLT processor, the resulting +DOMSource+ may wrap the *document 
> element* rather than the *document node*. Saxon and some JDK XSLT 
> implementations then treat the element as the context node, so a stylesheet 
> template matching +/+ is bypassed and the transform produces unwrapped text 
> instead of the expected XML document.
> The failure is non-deterministic: the converter chosen for the CXF payload 
> varies between JVM runs (SAXSource vs DOM fallback), so the bug appears in 
> roughly 5 of 10 fresh JVM starts against the unpatched baseline.
> *Root cause:* {{XmlSourceHandlerFactoryImpl}} does not normalise implicitly 
> converted DOM elements to their owning document before dispatching to the 
> source handler. When the converter returns a +DOMSource+ whose node is the 
> document element, the systemId is silently dropped and the wrong context is 
> used for the transform.
> *Fix:* In {{XmlSourceHandlerFactoryImpl}}, after source-handler dispatch, 
> normalise any implicitly converted document-root DOM element to its owning 
> document node. The original DOM must be left untouched; systemId, explicit 
> {{Source}} bodies, source-expression results, nested elements, detached 
> elements and streaming sources must all retain their existing semantics.
> This also needs to cover Saxon's fallback path, which can return a 
> +DOMSource+ without invoking the superclass conversion method.
> *Scope:*
> - {{camel-xslt}} (JDK processor)
> - {{camel-xslt-saxon}} (Saxon processor)
> Other XML consumers (xpath, xquery, validator) that receive implicitly 
> converted CXF payloads may be affected by the same non-deterministic source 
> selection; a follow-up in {{camel-cxf}} / type-converter registry should be 
> considered.
> *Upgrade note required:* custom implicit converters that intentionally select 
> element context will be affected and need documentation in the 4.x upgrade 
> guide alongside the existing _camel-xslt / camel-xslt-saxon - external 
> document() access is denied by default_ entry.
> *Related PR:* https://github.com/apache/camel/pull/27154



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to