Repository navigation
Releases: A35G/JSON-to-XML
Release list
v1.3.1
Bug-fix release for the command-line tool.
Fixed
bin/json-to-xmlnow works when the package is installed as a dependency. Since 1.1.0 the script looked forvendor/autoload.phprelative to its own location, which only exists in a checkout of the repository. In a project that installed the package,vendor/bin/json-to-xmlfailed withFailed opening required '.../vendor/autoload.php'. The script now looks for Composer's autoloader in several locations, and a regression test simulates the installed layout.
The library classes (JsonToXmlConverter, XmlToJsonConverter) are not affected: only the CLI was broken.
If you installed 1.1.0 to 1.3.0 and use the CLI from your project's vendor/bin, upgrade to 1.3.1.
Full changelog: v1.3.0...v1.3.1
v1.3.0
This release hardens XmlToJsonConverter against entity-based denial of service and fixes two data-correctness issues in JsonToXmlConverter. Please read "Behavior changes" before upgrading: some inputs that were previously accepted are now rejected.
Behavior changes
XmlToJsonConverternow rejects references to entities declared in the DOCTYPE, both in attribute values and in element content, by throwing anInvalidArgumentException(exit code3from the CLI). Predefined entities (&,<,>,",') and character references (A) are unaffected.- In attribute values, reading the value expanded the entity with quadratic cost, which neither
loadXML()nor libxml2's own limits prevented. On libxml2 2.10.4, 16 MB of expanded content took about 14 s, and a crafted document of ~250 KB did not finish within a 15 s test timeout. - In element content, such references used to be silently dropped, losing data.
- If you rely on custom entities, inline them before passing the XML to the library.
- In attribute values, reading the value expanded the entity with quadratic cost, which neither
- JSON integers beyond the int64 range are now written in full. They are decoded as strings (
JSON_BIGINT_AS_STRING) instead of being rounded to a float, so12345678901234567890is no longer emitted as1.2345678901235E+19. - Characters that are not allowed in XML 1.0 are now rejected.
JsonToXmlConverterthrows anInvalidArgumentExceptionfor values containing control characters other than tab, line feed and carriage return, instead of silently producing a malformed document.
Added
- Regression tests for entity-expansion attacks (Billion Laughs, recursive entities, quadratic blowup in element content and in attribute values). The heavy payloads run in a separate PHP process with a reduced
memory_limitand a timeout, so a regression cannot crash or hang the test suite. - Tests for resource budgets on large documents, nesting depth limits in both directions, namespace handling in XML → JSON, markup and namespace injection through JSON keys and values, and additional file and temporary-file error cases.
Documentation
SECURITY.mdnow documents what the tests do and do not guarantee, the dependency on the libxml2 version bundled with PHP, and the library's limits: no size or time limits of its own, file paths are not validated, and namespaces are not preserved in XML → JSON.README.mddocuments the new behavior for entities, large integers and invalid characters.
Notes
- Entity-expansion protection relies on libxml2's built-in limits, which the library leaves enabled (it never passes
LIBXML_NOENTorLIBXML_PARSEHUGE). Results were verified on libxml2 2.10.4; other versions may behave differently, so running the test suite on your target environment is recommended. - For fully untrusted input, add your own size cap and execution timeout.
Full changelog: v1.2.0...v1.3.0
v1.2.0
Add stylesheet association support (setStylesheet/clearStylesheet)
JsonToXmlConverter::setStylesheet()/clearStylesheet()add an<?xml-stylesheet?>processing instruction before the root element- New
--stylesheet / --stylesheet-typeCLI options for to-xml - Tests, README and CHANGELOG updated accordingly
v1.1.0
Add CLI tool, PHPStan/PHPCS quality tooling, and minor robustness fixes
- Add
bin/json-to-xmlCLI for JSON<->XML conversion from the shell - Add PHPStan (level 8) and PHP_CodeSniffer (PSR-12) configs and composer scripts
- Add dedicated GitHub Actions workflow for static analysis and code style
- Fix
sanitizeTagName()to handlepreg_replace()returning null on regex errors - Simplify redundant type checks flagged by static analysis
- Add
CliTest.phpcovering the CLI as a real subprocess
v1.0.1
Fix: remove temporary file leak, add integrity tests
- Fixed
tempFilename()for non-writable directories - Cross-platform test fixes
- Fixed: removed temporary file leak in
jsonToXmlStdOut() - Added integrity tests for XXE security, PSR-4, and sanitization edge cases
v1.0.0 — First public release
Description
First public release of json-to-xml, a PHP library for converting
JSON to XML and back, with support for attributes, automatic CDATA,
and mixed content.
Key Features
- JSON → XML conversion (
JsonToXmlConverter) - XML → JSON conversion (
XmlToJsonConverter) - Attributes via the
@prefix - Direct text / mixed content via the
#textkey - Repeated lists without an intermediate wrapper
- Automatic CDATA based on content
- Protection against XXE attacks (LIBXML_NONET)
forceArrayTagsto preserve the "list" shape in the XML → JSON round-trip
Requirements
- PHP >= 8.1
domandjsonextensions
Installation
composer require a35g/json-to-xmlDocumentation
Full user guide available in the Wiki.