ppkarwasz opened a new pull request, #4402: URL: https://github.com/apache/hertzbeat/pull/4402
## What's changed? Closes #4401. The sitemap and XPath parsers in `HttpCollectImpl` now obtain their JAXP factories from [Apache Commons Secure XML](https://commons.apache.org/proper/commons-secure-xml/) instead of configuring security features by hand: - `DocumentBuilderFactory.newInstance()` becomes `SecureDocumentBuilderFactory.newInstance()` (both call sites), and the manual `setFeature` / `setXIncludeAware` / `setExpandEntityReferences` calls are removed. - `XPathFactory.newInstance()` becomes `SecureXPathFactory.newInstance()`. - `org.apache.commons:commons-secure-xml:1.0.0` is added to `hertzbeat-collector-basic` and listed in the backend and collector `LICENSE` files. **Behavior change:** a response containing a DOCTYPE is no longer rejected. It is parsed, and any external references in it (DTDs, external entities, XInclude) are ignored. ### Enforcement instead of XXE tests Rather than adding XXE unit tests that would re-test the library's guarantees, the root POM now runs [forbidden-apis](https://github.com/policeman-tools/forbidden-apis) with `script/forbidden-apis/jaxp.txt`, which rejects the plain JAXP factory methods (`DocumentBuilderFactory`, `SAXParserFactory`, `XMLInputFactory`, `TransformerFactory`, `SchemaFactory`, `XPathFactory`) in main code. Run against the current `master`, it reports: ``` [ERROR] Forbidden method invocation: javax.xml.parsers.DocumentBuilderFactory#newInstance() [Use SecureDocumentBuilderFactory from Apache Commons Secure XML] [ERROR] in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl (HttpCollectImpl.java:332) [ERROR] Forbidden method invocation: javax.xml.parsers.DocumentBuilderFactory#newInstance() [Use SecureDocumentBuilderFactory from Apache Commons Secure XML] [ERROR] in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl (HttpCollectImpl.java:487) [ERROR] Forbidden method invocation: javax.xml.xpath.XPathFactory#newInstance() [Use SecureXPathFactory from Apache Commons Secure XML] [ERROR] in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl (HttpCollectImpl.java:500) [ERROR] Scanned 201 class file(s) for forbidden API invocations (in 0.10s), 3 error(s). ``` With this PR the check passes in every module. ### Verification - `./mvnw -pl hertzbeat-collector/hertzbeat-collector-basic -am clean install` (JDK 25): 271 tests pass, including all 15 in `HttpCollectImplTest`; checkstyle and forbidden-apis are clean. - `./mvnw -DskipTests install` on the whole reactor: build succeeds, no forbidden-apis violations. - The native collector build was not tested locally. ## Checklist - [ ] I have read the [Contributing Guide](https://hertzbeat.apache.org/docs/community/code_style_and_quality_guide) - [x] I have written the necessary doc or comment. - [x] I have added the necessary unit tests and all cases have passed. ## Add or update API - [ ] I have added the necessary [e2e tests](https://github.com/apache/hertzbeat/tree/master/e2e) and all cases have passed. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
