Harden XML parsing via commons-secure-xml - #108
Draft
ppkarwasz wants to merge 2 commits into
Draft
Conversation
Create SAX parsers and readers through org.apache.commons:commons-secure-xml. The secure factory enables FEATURE_SECURE_PROCESSING and installs a non-removable entity-resolver floor on every parser it produces: external DTD and entity lookups that a caller-set resolver does not resolve are resolved to empty content instead of being fetched, and internal entity expansion is bounded, regardless of the JAXP implementation on the classpath. Changes: - Add the commons-secure-xml dependency (1.0.0-SNAPSHOT until its first release) to core, jelly-tags/xml and jelly-tags/xmlunit. - core XMLParser keeps the documented JellyContext.setAllowDtdToCallExternalEntities(true) opt-in working by using a plain factory on that path; the default path uses the secure factory, and a factory assigned to the protected static field still wins. The flag-dependent choice is no longer cached in that field. - core ParseTag (which had no hardening at all) now creates its reader through the secure factory. - jelly-tags/xml: TransformTag's readers and ParseTag's dom4j SAXReader are built from the secure factory; dom4j and XMLReaderFactory otherwise provision readers through JAXP at their own defaults, and the deprecated org.xml.sax.driver system property no longer selects the reader class. The TransformerFactory itself stays unsecured for now: Xalan, which this module puts on the class path, drops the attributes of xsl:namespace-alias literal result elements under secure processing (XSLTElementProcessor rejects "foreign" attributes as non-fatal errors), silently breaking stylesheets such as the Schematron skeleton. - jelly-tags/xmlunit: the assertion tags' dom4j SAXReaders are built from the secure factory. - jelly-tags/html is unchanged: NekoHTML is an HTML scanner, not an XML parser. - Run the CI and CodeQL builds with -Puse-apache-snapshots (inherited from the org.apache:apache parent POM) so the commons-secure-xml SNAPSHOT resolves; CodeQL's autobuild receives the profile through MAVEN_ARGS. Assisted-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MHgnMnGWHQoH2zD2jFdoMT
ppkarwasz
force-pushed
the
feat/use-commons-xml
branch
from
August 31, 2026 15:10
7278e24 to
55c5bad
Compare
Bump org.apache.commons:commons-secure-xml from 1.0.0-SNAPSHOT to 1.0.0 and add the temporary staging repository https://repository.apache.org/content/repositories/orgapachecommons-1962/ after Central, so the vote gets downstream CI results. Drop the -Puse-apache-snapshots profile from the CI workflows, which the release version no longer needs. Remove the staging repository once 1.0.0 is released. Assisted-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0167e29ScPEdfzJnEFm95imK
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Warning
This PR was submitted automatically to smoke-test
Apache Commons Secure XML
and has not yet been verified by a human.
It will stay a draft until a committer reviews it and marks it ready.
Creates SAX parsers and readers through
org.apache.commons:commons-secure-xml(1.0.0-SNAPSHOT until its first release) incore,jelly-tags/xmlandjelly-tags/xmlunit. The secure factory enables XML secure processing and installs a non-removable entity-resolver floor: external DTD and entity lookups are resolved to empty content instead of being fetched, and internal entity expansion is bounded.XMLParserkeeps the documentedJellyContext.setAllowDtdToCallExternalEntities(true)opt-in working by using a plain factory on that path; the default path uses the secure factory, and a factory assigned to the protected static field still wins.ParseTag, which had no hardening at all, now creates its reader through the secure factory.jelly-tags/xml:TransformTag's readers andParseTag's dom4jSAXReaderare built from the secure factory (the deprecatedorg.xml.sax.driversystem property no longer selects the reader class). TheTransformerFactoryitself stays unsecured for now: Xalan, which this module puts on the class path, drops the attributes ofxsl:namespace-aliasliteral result elements under secure processing (XSLTElementProcessorrejects "foreign" attributes as non-fatal errors), silently breaking stylesheets such as the Schematron skeleton.jelly-tags/xmlunit: the assertion tags' dom4jSAXReaders are built from the secure factory.jelly-tags/htmlis unchanged (NekoHTML is an HTML scanner, not an XML parser).-Puse-apache-snapshotsso the SNAPSHOT dependency resolves.🤖 Generated with Claude Code