ramanathan1504 commented on code in PR #4265:
URL: https://github.com/apache/logging-log4j2/pull/4265#discussion_r3893099544


##########
log4j-1.2-api/src/main/java/org/apache/log4j/xml/XmlConfiguration.java:
##########
@@ -77,6 +78,12 @@
  *     Parsing and validation errors do not stop the configuration process; 
they are printed as warnings to the status
  *     logger.
  * </p>
+ * <p>
+ *     Since version <strong>2.27.0</strong>, external entities are resolved 
through
+ *     {@link ConfigurationSource#fromUri(URI)}, so they can only be retrieved 
from locations allowed by the

Review Comment:
   Same wording as the migration guide: `fromUri` resolves local files before 
reaching `UrlConnectionFactory`, so the property does not gate `file:` entities.
   
   ````suggestion
    *     {@link ConfigurationSource#fromUri(URI)}, so they can only be 
retrieved from local files or over the protocols allowed by the
   ````



##########
src/site/antora/modules/ROOT/pages/migrate-from-log4j1.adoc:
##########
@@ -360,6 +360,13 @@ and
 xref:manual/configuration.adoc#configuration-attribute-schema[`schema`]
 attributes of the XML configuration format.
 
+[NOTE]
+====
+Since version `2.27.0`, the external subset and other external entities can 
only be retrieved from locations allowed by the

Review Comment:
   `allowedProtocols` only gates the URL branch of 
`ConfigurationSource.fromUri` — local files are opened first 
(`ConfigurationSource.java:318-321`), so a `file:` entity still resolves even 
under `_none`, which the properties page also notes.
   
   ````suggestion
   Since version `2.27.0`, the external subset and other external entities can 
only be retrieved from local files or over the protocols allowed by the
   ````



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to