ramanathan1504 commented on code in PR #4265:
URL: https://github.com/apache/logging-log4j2/pull/4265#discussion_r3893099544
##########
log4j-1.2-api/src/main/java/org/apache/log4j/xml/XmlConfiguration.java:
##########
@@ -77,6 +78,12 @@
* Parsing and validation errors do not stop the configuration process;
they are printed as warnings to the status
* logger.
* </p>
+ * <p>
+ * Since version <strong>2.27.0</strong>, external entities are resolved
through
+ * {@link ConfigurationSource#fromUri(URI)}, so they can only be retrieved
from locations allowed by the
Review Comment:
Same wording as the migration guide: `fromUri` resolves local files before
reaching `UrlConnectionFactory`, so the property does not gate `file:` entities.
````suggestion
* {@link ConfigurationSource#fromUri(URI)}, so they can only be
retrieved from local files or over the protocols allowed by the
````
##########
src/site/antora/modules/ROOT/pages/migrate-from-log4j1.adoc:
##########
@@ -360,6 +360,13 @@ and
xref:manual/configuration.adoc#configuration-attribute-schema[`schema`]
attributes of the XML configuration format.
+[NOTE]
+====
+Since version `2.27.0`, the external subset and other external entities can
only be retrieved from locations allowed by the
Review Comment:
`allowedProtocols` only gates the URL branch of
`ConfigurationSource.fromUri` — local files are opened first
(`ConfigurationSource.java:318-321`), so a `file:` entity still resolves even
under `_none`, which the properties page also notes.
````suggestion
Since version `2.27.0`, the external subset and other external entities can
only be retrieved from local files or over the protocols allowed by the
````
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]