Skip to content

[improve] use Apache Commons Secure XML for the HTTP collector XML parsers - #4402

Open
ppkarwasz wants to merge 1 commit into
apache:masterfrom
ppkarwasz:feat/use-commons-xml
Open

ppkarwasz wants to merge 1 commit into
apache:masterfrom
ppkarwasz:feat/use-commons-xml

Conversation

@ppkarwasz

Copy link
Copy Markdown
Member

What's changed?

Closes #4401.

The sitemap and XPath parsers in HttpCollectImpl now obtain their JAXP factories from Apache Commons Secure XML instead of configuring security features by hand:

  • DocumentBuilderFactory.newInstance() becomes SecureDocumentBuilderFactory.newInstance() (both call sites), and the manual setFeature / setXIncludeAware / setExpandEntityReferences calls are removed.
  • XPathFactory.newInstance() becomes SecureXPathFactory.newInstance().
  • org.apache.commons:commons-secure-xml:1.0.0 is added to hertzbeat-collector-basic and listed in the backend and collector LICENSE files.

Behavior change: a response containing a DOCTYPE is no longer rejected. It is parsed, and any external references in it (DTDs, external entities, XInclude) are ignored.

Enforcement instead of XXE tests

Rather than adding XXE unit tests that would re-test the library's guarantees, the root POM now runs forbidden-apis with script/forbidden-apis/jaxp.txt, which rejects the plain JAXP factory methods (DocumentBuilderFactory, SAXParserFactory, XMLInputFactory, TransformerFactory, SchemaFactory, XPathFactory) in main code.
Run against the current master, it reports:

[ERROR] Forbidden method invocation: javax.xml.parsers.DocumentBuilderFactory#newInstance() [Use SecureDocumentBuilderFactory from Apache Commons Secure XML]
[ERROR]   in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl (HttpCollectImpl.java:332)
[ERROR] Forbidden method invocation: javax.xml.parsers.DocumentBuilderFactory#newInstance() [Use SecureDocumentBuilderFactory from Apache Commons Secure XML]
[ERROR]   in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl (HttpCollectImpl.java:487)
[ERROR] Forbidden method invocation: javax.xml.xpath.XPathFactory#newInstance() [Use SecureXPathFactory from Apache Commons Secure XML]
[ERROR]   in org.apache.hertzbeat.collector.collect.http.HttpCollectImpl (HttpCollectImpl.java:500)
[ERROR] Scanned 201 class file(s) for forbidden API invocations (in 0.10s), 3 error(s).

With this PR the check passes in every module.

Verification

  • ./mvnw -pl hertzbeat-collector/hertzbeat-collector-basic -am clean install (JDK 25): 271 tests pass, including all 15 in HttpCollectImplTest; checkstyle and forbidden-apis are clean.
  • ./mvnw -DskipTests install on the whole reactor: build succeeds, no forbidden-apis violations.
  • The native collector build was not tested locally.

Checklist

  • I have read the Contributing Guide
  • I have written the necessary doc or comment.
  • I have added the necessary unit tests and all cases have passed.

Add or update API

  • I have added the necessary e2e tests and all cases have passed.

🤖 Generated with Claude Code

…rsers

The sitemap and XPath parsers in HttpCollectImpl each configured their own
subset of JAXP security features. Both now obtain their factories from
Apache Commons Secure XML, which ignores external resources regardless of
the JAXP implementation. A forbiddenapis check keeps raw JAXP factory
methods out of the main code.

Assisted-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature] Use Apache Commons Secure XML for the HTTP collector XML parsers

1 participant