kwin commented on code in PR #112:
URL: 
https://github.com/apache/commons-secure-xml/pull/112#discussion_r4221438701


##########
src/main/java/org/apache/commons/xml/secure/SecureXMLReader.java:
##########
@@ -137,6 +137,8 @@ public void setEntityResolver(final EntityResolver 
resolver) {
 
     @Override
     public void setErrorHandler(final ErrorHandler handler) {
+        // as soon as the error handler is populated (even with a warning), 
the strict Xalan XSLT parser will throw!
+        //floor.setErrorHandler(handler);

Review Comment:
   The reason for that is the usage of 
https://github.com/openjdk/jdk/blob/6edf757bc4152dc62c449ad69f30f7c85a1b4f00/src/java.xml/share/classes/jdk/xml/internal/ErrorHandlerProxy.java#L39
 in XSLTC which just throws every exception passed to 
`ErrorHandler.warning(...)`. So no matter if `warning`, `error` or `fatalError` 
all lead to an exception, despite the contract of 
https://docs.oracle.com/javase/8/docs/api/org/xml/sax/ErrorHandler.html#warning-org.xml.sax.SAXParseException-
 stating:
   
   > The SAX parser must continue to provide normal parsing events after 
invoking this method: it should still be possible for the application to 
process the document through to the end.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to