ppkarwasz opened a new pull request, #4402:
URL: https://github.com/apache/hertzbeat/pull/4402

   ## What's changed?
   
   Closes #4401.
   
   The sitemap and XPath parsers in `HttpCollectImpl` now obtain their JAXP 
factories from [Apache Commons Secure 
XML](https://commons.apache.org/proper/commons-secure-xml/) instead of 
configuring security features by hand:
   
   - `DocumentBuilderFactory.newInstance()` becomes 
`SecureDocumentBuilderFactory.newInstance()` (both call sites), and the manual 
`setFeature` / `setXIncludeAware` / `setExpandEntityReferences` calls are 
removed.
   - `XPathFactory.newInstance()` becomes `SecureXPathFactory.newInstance()`.
   - `org.apache.commons:commons-secure-xml:1.0.0` is added to 
`hertzbeat-collector-basic` and listed in the backend and collector `LICENSE` 
files.
   
   **Behavior change:** a response containing a DOCTYPE is no longer rejected. 
It is parsed, and any external references in it (DTDs, external entities, 
XInclude) are ignored.
   
   ### Enforcement instead of XXE tests
   
   Rather than adding XXE unit tests that would re-test the library's 
guarantees, the root POM now runs 
[forbidden-apis](https://github.com/policeman-tools/forbidden-apis) with 
`script/forbidden-apis/jaxp.txt`, which rejects the plain JAXP factory methods 
(`DocumentBuilderFactory`, `SAXParserFactory`, `XMLInputFactory`, 
`TransformerFactory`, `SchemaFactory`, `XPathFactory`) in main code.
   Run against the current `master`, it reports:
   
   ```
   [ERROR] Forbidden method invocation: 
javax.xml.parsers.DocumentBuilderFactory#newInstance() [Use 
SecureDocumentBuilderFactory from Apache Commons Secure XML]
   [ERROR]   in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl 
(HttpCollectImpl.java:332)
   [ERROR] Forbidden method invocation: 
javax.xml.parsers.DocumentBuilderFactory#newInstance() [Use 
SecureDocumentBuilderFactory from Apache Commons Secure XML]
   [ERROR]   in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl 
(HttpCollectImpl.java:487)
   [ERROR] Forbidden method invocation: 
javax.xml.xpath.XPathFactory#newInstance() [Use SecureXPathFactory from Apache 
Commons Secure XML]
   [ERROR]   in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl 
(HttpCollectImpl.java:500)
   [ERROR] Scanned 201 class file(s) for forbidden API invocations (in 0.10s), 
3 error(s).
   ```
   
   With this PR the check passes in every module.
   
   ### Verification
   
   - `./mvnw -pl hertzbeat-collector/hertzbeat-collector-basic -am clean 
install` (JDK 25): 271 tests pass, including all 15 in `HttpCollectImplTest`; 
checkstyle and forbidden-apis are clean.
   - `./mvnw -DskipTests install` on the whole reactor: build succeeds, no 
forbidden-apis violations.
   - The native collector build was not tested locally.
   
   ## Checklist
   
   - [ ]  I have read the [Contributing 
Guide](https://hertzbeat.apache.org/docs/community/code_style_and_quality_guide)
   - [x]  I have written the necessary doc or comment.
   - [x]  I have added the necessary unit tests and all cases have passed.
   
   ## Add or update API
   
   - [ ] I have added the necessary [e2e 
tests](https://github.com/apache/hertzbeat/tree/master/e2e) and all cases have 
passed.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to