Harden XML parsing via commons-secure-xml - #288
Draft
ppkarwasz wants to merge 1 commit into
Draft
Conversation
Create XML parsers and transformers through org.apache.commons:commons-secure-xml. The secure factories enable FEATURE_SECURE_PROCESSING and install a non-removable entity-resolver floor on every parser they produce: external DTD, entity, schema and XInclude lookups that a caller-set resolver does not resolve are resolved to empty content instead of being fetched, and internal entity expansion is bounded, regardless of the JAXP implementation on the classpath. Changes: - Add the commons-secure-xml dependency (1.0.0-SNAPSHOT until its first release). - Route factory creation through SecureDocumentBuilderFactory in DOMParser and SecureTransformerFactory in XMLDocumentContainer; the caller-configurable factory settings (validation, namespace awareness, entity expansion, whitespace, comments, coalescing) keep working. - JDOMParser builds its SAX reader through the secure factory as well, by overriding SAXBuilder.createParser(); documents with internal DTD subsets parse as before. - Parsers registered through DocumentContainer.registerXMLParser remain under the control of their authors. - Run the CI and CodeQL builds with -Puse-apache-snapshots (inherited from the org.apache:apache parent POM) so the commons-secure-xml SNAPSHOT resolves; CodeQL's autobuild receives the profile through MAVEN_ARGS. Assisted-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MHgnMnGWHQoH2zD2jFdoMT
ppkarwasz
force-pushed
the
feat/use-commons-xml
branch
from
August 31, 2026 15:06
f9af9ef to
915bc09
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Warning
This PR was submitted automatically to smoke-test
Apache Commons Secure XML
and has not yet been verified by a human.
It will stay a draft until a committer reviews it and marks it ready.
Creates XML parsers and transformers through
org.apache.commons:commons-secure-xml(1.0.0-SNAPSHOT until its first release). The secure factories enable XML secure processing and install a non-removable entity-resolver floor: external DTD, entity, schema and XInclude lookups that a caller-set resolver does not resolve are resolved to empty content instead of being fetched, and internal entity expansion is bounded.DOMParsergoes throughSecureDocumentBuilderFactoryandXMLDocumentContainerthroughSecureTransformerFactory; the caller-configurable settings (validation, namespace awareness, entity expansion, whitespace, comments, coalescing) keep working.JDOMParserbuilds its SAX reader through the secure factory as well, by overridingSAXBuilder.createParser(); documents with internal DTD subsets parse as before.DocumentContainer.registerXMLParserremain under the control of their authors.-Puse-apache-snapshotsso the SNAPSHOT dependency resolves.🤖 Generated with Claude Code