Skip to content

Security and Error Handling

A35G edited this page Sep 10, 2026 · 1 revision

Security and Error Handling

XXE attack protection

When reading XML from untrusted sources (user uploads, external calls, etc.), the library is already protected: parsing uses LIBXML_NONET, which prevents the parser from resolving external entities over the network. No extra configuration is needed for this.

Error handling

Both classes throw clear exceptions instead of failing silently:

Situation Exception
Invalid or empty JSON InvalidArgumentException
Invalid or empty XML InvalidArgumentException
An attribute (@key) has an array as its value InvalidArgumentException
Failed file write RuntimeException
Temp directory not writable at the time of use RuntimeException

Tip: always wrap calls in a try/catch when the incoming JSON or XML is not generated internally by your application.

try {
    $xml = $converter->jsonToXmlString($externalJson);
} catch (\InvalidArgumentException $e) {
    // log it, or return a controlled error to the user
}

"Difficult" tag names

JSON keys that aren't valid XML tag names are automatically sanitized, so you don't need to worry about it upstream:

  • disallowed characters are replaced with _
  • a tag cannot start with a digit, a dot, or a hyphen → an n_ prefix is added
  • a tag cannot start with xml (reserved) → a _ prefix is added

Example: the key "1field" becomes the tag <n_1field>.


⬅️ Previous page: Round-Trip-and-Limitations · ➡️ Next page: Checklist-and-Further-Reading

Clone this wiki locally