Skip to content

Releases: A35G/JSON-to-XML

v1.3.1

Choose a tag to compare

@A35G A35G released this 03 Oct 23:42

Bug-fix release for the command-line tool.

Fixed

  • bin/json-to-xml now works when the package is installed as a dependency. Since 1.1.0 the script looked for vendor/autoload.php relative to its own location, which only exists in a checkout of the repository. In a project that installed the package, vendor/bin/json-to-xml failed with Failed opening required '.../vendor/autoload.php'. The script now looks for Composer's autoloader in several locations, and a regression test simulates the installed layout.

The library classes (JsonToXmlConverter, XmlToJsonConverter) are not affected: only the CLI was broken.

If you installed 1.1.0 to 1.3.0 and use the CLI from your project's vendor/bin, upgrade to 1.3.1.

Full changelog: v1.3.0...v1.3.1

v1.3.0

Choose a tag to compare

@A35G A35G released this 03 Oct 23:15

This release hardens XmlToJsonConverter against entity-based denial of service and fixes two data-correctness issues in JsonToXmlConverter. Please read "Behavior changes" before upgrading: some inputs that were previously accepted are now rejected.

Behavior changes

  • XmlToJsonConverter now rejects references to entities declared in the DOCTYPE, both in attribute values and in element content, by throwing an InvalidArgumentException (exit code 3 from the CLI). Predefined entities (&, <, >, ", ') and character references (A) are unaffected.
    • In attribute values, reading the value expanded the entity with quadratic cost, which neither loadXML() nor libxml2's own limits prevented. On libxml2 2.10.4, 16 MB of expanded content took about 14 s, and a crafted document of ~250 KB did not finish within a 15 s test timeout.
    • In element content, such references used to be silently dropped, losing data.
    • If you rely on custom entities, inline them before passing the XML to the library.
  • JSON integers beyond the int64 range are now written in full. They are decoded as strings (JSON_BIGINT_AS_STRING) instead of being rounded to a float, so 12345678901234567890 is no longer emitted as 1.2345678901235E+19.
  • Characters that are not allowed in XML 1.0 are now rejected. JsonToXmlConverter throws an InvalidArgumentException for values containing control characters other than tab, line feed and carriage return, instead of silently producing a malformed document.

Added

  • Regression tests for entity-expansion attacks (Billion Laughs, recursive entities, quadratic blowup in element content and in attribute values). The heavy payloads run in a separate PHP process with a reduced memory_limit and a timeout, so a regression cannot crash or hang the test suite.
  • Tests for resource budgets on large documents, nesting depth limits in both directions, namespace handling in XML → JSON, markup and namespace injection through JSON keys and values, and additional file and temporary-file error cases.

Documentation

  • SECURITY.md now documents what the tests do and do not guarantee, the dependency on the libxml2 version bundled with PHP, and the library's limits: no size or time limits of its own, file paths are not validated, and namespaces are not preserved in XML → JSON.
  • README.md documents the new behavior for entities, large integers and invalid characters.

Notes

  • Entity-expansion protection relies on libxml2's built-in limits, which the library leaves enabled (it never passes LIBXML_NOENT or LIBXML_PARSEHUGE). Results were verified on libxml2 2.10.4; other versions may behave differently, so running the test suite on your target environment is recommended.
  • For fully untrusted input, add your own size cap and execution timeout.

Full changelog: v1.2.0...v1.3.0

v1.2.0

Choose a tag to compare

@A35G A35G released this 17 Sep 23:10

Add stylesheet association support (setStylesheet/clearStylesheet)

  • JsonToXmlConverter::setStylesheet() / clearStylesheet() add an <?xml-stylesheet?> processing instruction before the root element
  • New --stylesheet / --stylesheet-type CLI options for to-xml
  • Tests, README and CHANGELOG updated accordingly

v1.1.0

Choose a tag to compare

@A35G A35G released this 16 Sep 00:01

Add CLI tool, PHPStan/PHPCS quality tooling, and minor robustness fixes

  • Add bin/json-to-xml CLI for JSON<->XML conversion from the shell
  • Add PHPStan (level 8) and PHP_CodeSniffer (PSR-12) configs and composer scripts
  • Add dedicated GitHub Actions workflow for static analysis and code style
  • Fix sanitizeTagName() to handle preg_replace() returning null on regex errors
  • Simplify redundant type checks flagged by static analysis
  • Add CliTest.php covering the CLI as a real subprocess

v1.0.1

Choose a tag to compare

@A35G A35G released this 11 Sep 17:37

Fix: remove temporary file leak, add integrity tests

  • Fixed tempFilename() for non-writable directories
  • Cross-platform test fixes
  • Fixed: removed temporary file leak in jsonToXmlStdOut()
  • Added integrity tests for XXE security, PSR-4, and sanitization edge cases

v1.0.0 — First public release

Choose a tag to compare

@A35G A35G released this 10 Sep 21:13

Description

First public release of json-to-xml, a PHP library for converting
JSON to XML and back, with support for attributes, automatic CDATA,
and mixed content.

Key Features

  • JSON → XML conversion (JsonToXmlConverter)
  • XML → JSON conversion (XmlToJsonConverter)
  • Attributes via the @ prefix
  • Direct text / mixed content via the #text key
  • Repeated lists without an intermediate wrapper
  • Automatic CDATA based on content
  • Protection against XXE attacks (LIBXML_NONET)
  • forceArrayTags to preserve the "list" shape in the XML → JSON round-trip

Requirements

  • PHP >= 8.1
  • dom and json extensions

Installation

composer require a35g/json-to-xml

Documentation

Full user guide available in the Wiki.