ppkarwasz commented on code in PR #766:
URL: https://github.com/apache/commons-text/pull/766#discussion_r3955523232


##########
src/main/java/org/apache/commons/text/lookup/XmlStringLookup.java:
##########
@@ -128,14 +130,21 @@ public String lookup(final String key) {
         }
         final String documentPath = keys[0];
         final String xpath = StringUtils.substringAfterLast(key, SPLIT_CH);
-        final DocumentBuilderFactory dbFactory = 
DocumentBuilderFactory.newInstance();
+        // The secure factory installs a non-removable resolver floor that 
ignores the JAXP access properties,
+        // so the documented opt-outs keep a plain factory: a feature map 
without secure processing, or the
+        // standard javax.xml.accessExternalDTD system property re-allowing 
external access.
+        final boolean secure = 
Boolean.TRUE.equals(xmlFactoryFeatures.get(XMLConstants.FEATURE_SECURE_PROCESSING))

Review Comment:
   In 
https://github.com/apache/commons-text/pull/766/commits/bc9c20447a11dfbde21defdcc7713a62a0ba7ee8
 I solved the problem by documenting that external entities can **not** be 
reenabled. Tests that relied on external entities where disabled, instead of 
being removed.
   
   We'll need a follow-up PR, if we think users need to access external 
entities.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to