-
-
Notifications
You must be signed in to change notification settings - Fork 0
Security and Error Handling
A35G edited this page Sep 10, 2026
·
1 revision
When reading XML from untrusted sources (user uploads, external calls, etc.), the library is already protected: parsing uses LIBXML_NONET, which prevents the parser from resolving external entities over the network. No extra configuration is needed for this.
Both classes throw clear exceptions instead of failing silently:
| Situation | Exception |
|---|---|
| Invalid or empty JSON | InvalidArgumentException |
| Invalid or empty XML | InvalidArgumentException |
An attribute (@key) has an array as its value |
InvalidArgumentException |
| Failed file write | RuntimeException |
| Temp directory not writable at the time of use | RuntimeException |
Tip: always wrap calls in a try/catch when the incoming JSON or XML is not generated internally by your application.
try {
$xml = $converter->jsonToXmlString($externalJson);
} catch (\InvalidArgumentException $e) {
// log it, or return a controlled error to the user
}JSON keys that aren't valid XML tag names are automatically sanitized, so you don't need to worry about it upstream:
- disallowed characters are replaced with
_ - a tag cannot start with a digit, a dot, or a hyphen → an
n_prefix is added - a tag cannot start with
xml(reserved) → a_prefix is added
Example: the key "1field" becomes the tag <n_1field>.
⬅️ Previous page: Round-Trip-and-Limitations · ➡️ Next page: Checklist-and-Further-Reading