View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertThrows;
21  
22  import javax.xml.stream.XMLStreamException;
23  import javax.xml.transform.TransformerException;
24  
25  import org.junit.jupiter.api.AfterEach;
26  import org.junit.jupiter.api.BeforeEach;
27  import org.junit.jupiter.api.Test;
28  import org.w3c.dom.ls.LSException;
29  import org.xml.sax.SAXException;
30  
31  /**
32   * Tests that the resolver floors reject unresolved references when the {@value SecureException#THROW_ON_UNRESOLVED} system property is set.
33   *
34   * <p>
35   * The floors are exercised directly: with the property set and no caller delegate, each must throw its hook's exception instead of resolving to empty
36   * content. The property is read at resolution time, so setting it around a single test cannot leak into the rest of the suite.
37   * </p>
38   */
39  class DenyUnresolvedTest {
40  
41      private static final String SYSTEM_ID = "http://invalid.example.invalid/external.dtd";
42  
43      @AfterEach
44      void clearThrowOnUnresolved() {
45          System.clearProperty(SecureException.THROW_ON_UNRESOLVED);
46      }
47  
48      @BeforeEach
49      void enableThrowOnUnresolved() {
50          System.setProperty(SecureException.THROW_ON_UNRESOLVED, "true");
51      }
52  
53      @Test
54      void floorsThrowOnUnresolved() {
55          assertThrows(SAXException.class, () -> new FallbackIgnoreEntityResolver2(null).resolveEntity(null, SYSTEM_ID),
56                  "EntityResolver2 floor should throw on an unresolved entity");
57          assertThrows(XMLStreamException.class, () -> new FallbackIgnoreXMLResolver(null).resolveEntity(null, SYSTEM_ID, null, null),
58                  "XMLResolver floor should throw on an unresolved entity");
59          assertThrows(LSException.class, () -> new FallbackIgnoreLSResourceResolver(null).resolveResource(null, null, null, SYSTEM_ID, null),
60                  "LSResourceResolver floor should throw on an unresolved resource");
61          assertThrows(TransformerException.class, () -> new FallbackIgnoreURIResolver(null, null, () -> false).resolve(SYSTEM_ID, null),
62                  "URIResolver floor should throw on an unresolved URI");
63      }
64  }