Conversation
…rsers The sitemap and XPath parsers in HttpCollectImpl each configured their own subset of JAXP security features. Both now obtain their factories from Apache Commons Secure XML, which ignores external resources regardless of the JAXP implementation. A forbiddenapis check keeps raw JAXP factory methods out of the main code. Assisted-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What's changed?
Closes #4401.
The sitemap and XPath parsers in
HttpCollectImplnow obtain their JAXP factories from Apache Commons Secure XML instead of configuring security features by hand:DocumentBuilderFactory.newInstance()becomesSecureDocumentBuilderFactory.newInstance()(both call sites), and the manualsetFeature/setXIncludeAware/setExpandEntityReferencescalls are removed.XPathFactory.newInstance()becomesSecureXPathFactory.newInstance().org.apache.commons:commons-secure-xml:1.0.0is added tohertzbeat-collector-basicand listed in the backend and collectorLICENSEfiles.Behavior change: a response containing a DOCTYPE is no longer rejected. It is parsed, and any external references in it (DTDs, external entities, XInclude) are ignored.
Enforcement instead of XXE tests
Rather than adding XXE unit tests that would re-test the library's guarantees, the root POM now runs forbidden-apis with
script/forbidden-apis/jaxp.txt, which rejects the plain JAXP factory methods (DocumentBuilderFactory,SAXParserFactory,XMLInputFactory,TransformerFactory,SchemaFactory,XPathFactory) in main code.Run against the current
master, it reports:With this PR the check passes in every module.
Verification
./mvnw -pl hertzbeat-collector/hertzbeat-collector-basic -am clean install(JDK 25): 271 tests pass, including all 15 inHttpCollectImplTest; checkstyle and forbidden-apis are clean../mvnw -DskipTests installon the whole reactor: build succeeds, no forbidden-apis violations.Checklist
Add or update API
🤖 Generated with Claude Code