Use XMLHelper for secure XML processing in DBWS XRServiceFactory and ProviderHelper - #2736
Conversation
a3552d6 to
3302ea1
Compare
|
@SebTardif The change looks straightforward, and the existing integration coverage provides useful reassurance about normal DBWS behavior. Before merging, could you please:
One test-wiring detail: DBWS currently skips Surefire and explicitly selects Failsafe suites, so please ensure the new tests are included in an execution that CI actually runs. |
…ProviderHelper XRServiceFactory.getDocumentBuilder() and getTransformer() create DocumentBuilderFactory and TransformerFactory via newInstance() without setting FEATURE_SECURE_PROCESSING. The project already has XMLHelper with createDocumentBuilderFactory() and createTransformerFactory() that properly configure secure processing. ProviderHelper.init() also creates a TransformerFactory directly without secure processing. This change replaces all three bare newInstance() calls with their XMLHelper equivalents, ensuring consistent XXE protection across the DBWS module. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
Cover namespaced parse/transform and blocked external entities through getDocumentBuilder() and getTransformer(). Register the suite in the Failsafe include list CI runs. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
3302ea1 to
46a1c6f
Compare
Yes. The branch is rebased on current master, and Failsafe now runs The suite is in the existing |
|
@arjantijms LGTM |
|
Thanks @robertpatrick and @SebTardif The tests pass, so let's merge this |
Summary
XRServiceFactory.getDocumentBuilder()andgetTransformer()createDocumentBuilderFactoryandTransformerFactoryvianewInstance()without settingFEATURE_SECURE_PROCESSING, making them vulnerable to XXE attacks. The project already hasXMLHelperwithcreateDocumentBuilderFactory()andcreateTransformerFactory()that properly configure secure processing.ProviderHelper.init()also creates aTransformerFactorydirectly without secure processing.Changes
XRServiceFactory.getDocumentBuilder(): ReplaceDocumentBuilderFactory.newInstance()withXMLHelper.createDocumentBuilderFactory(false). This also setsnamespaceAware(true)internally, so the explicit call is removed.XRServiceFactory.getTransformer(): ReplaceTransformerFactory.newInstance()withXMLHelper.createTransformerFactory(false).ProviderHelper.init(): ReplaceTransformerFactory.newInstance()withXMLHelper.createTransformerFactory(false).All three changes delegate to the existing
XMLHelperinfrastructure that the rest of the codebase uses for secure XML factory creation.Testing
Related
FileBasedProjectCache), which addressed a similar pattern of missing security configuration in another module.Signed-off-by: Sebastien Tardif SebTardif@ncf.ca