Skip to content

DocFence 0.54.0

Choose a tag to compare

@SybilGambleyyu SybilGambleyyu released this 06 Aug 09:43

DocFence 0.54 applies OPC §10.5.18's XPath prohibition to every XMLDSIG ds:XPath element in a recognized package signature, not only the bounded static coverage chain.

It rejects XPath in an additional same-document, non-coverage SignedInfo reference as well as in the package-object binding and manifest references.

This is a static stored-markup boundary: DocFence does not parse or execute XPath, resolve namespaces, canonicalize XML, evaluate transforms, recompute digests, verify XMLDSIG, or establish trust.

Validation: 69 tests; a fully declared XPath probe accepted with coverage in 0.53 and raises DocumentFormatError in 0.54; 29 public DOCX profiles unchanged; 22 XML signature parts (21 parseable), no XPath elements; checked wheel and sdist.