pjfanning opened a new pull request, #131:
URL: https://github.com/apache/poi-xmlbeans/pull/131

   Follow-up to #123.
   
   #123 rejected non-alphabet characters in `JavaBase64Holder.lex`, but two 
gaps remained:
   
   - `XMLStreamReaderExtImpl.getBase64Value` / `getAttributeBase64Value` (both 
overloads) still decoded with `Base64.getMimeDecoder()`, so `SGVsbG8=!!!!` came 
back as `Hello`.
   - The JDK decoders treat padding as optional, so unpadded or wrongly sized 
values such as `SGVsbG8` and `SGVsbG` still validated, although the 
base64Binary lexical space requires 4-char groups with `=` padding only at the 
end.
   
   This adds `org.apache.xmlbeans.impl.util.Base64Bin.decode` (a sibling of 
`HexBin`; it returns null for invalid input). It strips XML whitespace, 
requires length % 4 == 0, then uses the basic `Base64` decoder, which rejects 
non-alphabet chars and misplaced padding. The holder and all three rich parser 
getters use it.
   
   Not enforced: XSD 1.0's restriction on the final char before padding 
(non-zero trailing bits, e.g. `SGW=`). The JDK accepts these, and rejecting 
them looked more likely to break real documents than to catch anything.
   
   Tests: new `Base64BinTest`; `Base64BinaryValidateTest` gains padding/length 
cases and compiles the schema once; `RichParserTests` covers the stray-char and 
unpadded cases on element and attribute getters.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to