ppkarwasz opened a new pull request, #4264:
URL: https://github.com/apache/logging-log4j2/pull/4264

   This is a documentation-only improvement prompted by a report on the 
security mailing list (see #4263 for context):
   
   - Adds an "External entities and validation" section to the migration guide: 
external XML entities are enabled when parsing Log4j 1 configuration files 
(kept by the bridge for backward compatibility) but not Log4j 2 ones, with 
guidance to inline entities or convert them to XIncludes, and the 
DTD-vs-XML-Schema validation difference. The threat model is linked next to 
each capability statement, so the statements cannot be quoted out of context.
   - States the Log4j 2 XML parser features (no external DTD/entity retrieval, 
XInclude enabled when available) at the top of the XML format documentation.
   - Makes the `log4j.configuration` and `log4j1.compatibility` property 
entries self-contained, so neither can be misread as depending on the other 
when deep-linked.
   - Improves the class Javadoc of both `XmlConfiguration` classes and corrects 
their `XXE_DOCUMENT` suppression justifications.
   
   User-visible change: the `DOMConfigurator`/`PropertyConfigurator` warning 
messages now link to `logging.apache.org` instead of 
`logging.staged.apache.org` (staging link shipped since `2.24.0`).
   
   Documentation for behavior that first ships in `2.27.0` (#4198) is 
deliberately excluded; it follows in a separate stacked PR.
   
   Closes #4263
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   
   https://claude.ai/code/session_01LNsw2hhNuJ6tjsEU2tChnn


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to