ppkarwasz opened a new pull request, #4264: URL: https://github.com/apache/logging-log4j2/pull/4264
This is a documentation-only improvement prompted by a report on the security mailing list (see #4263 for context): - Adds an "External entities and validation" section to the migration guide: external XML entities are enabled when parsing Log4j 1 configuration files (kept by the bridge for backward compatibility) but not Log4j 2 ones, with guidance to inline entities or convert them to XIncludes, and the DTD-vs-XML-Schema validation difference. The threat model is linked next to each capability statement, so the statements cannot be quoted out of context. - States the Log4j 2 XML parser features (no external DTD/entity retrieval, XInclude enabled when available) at the top of the XML format documentation. - Makes the `log4j.configuration` and `log4j1.compatibility` property entries self-contained, so neither can be misread as depending on the other when deep-linked. - Improves the class Javadoc of both `XmlConfiguration` classes and corrects their `XXE_DOCUMENT` suppression justifications. User-visible change: the `DOMConfigurator`/`PropertyConfigurator` warning messages now link to `logging.apache.org` instead of `logging.staged.apache.org` (staging link shipped since `2.24.0`). Documentation for behavior that first ships in `2.27.0` (#4198) is deliberately excluded; it follows in a separate stacked PR. Closes #4263 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01LNsw2hhNuJ6tjsEU2tChnn -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
