1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18 package org.apache.commons.xml.secure;
19
20 import static org.junit.jupiter.api.Assertions.assertThrows;
21
22 import javax.xml.stream.XMLStreamException;
23 import javax.xml.transform.TransformerException;
24
25 import org.junit.jupiter.api.AfterEach;
26 import org.junit.jupiter.api.BeforeEach;
27 import org.junit.jupiter.api.Test;
28 import org.w3c.dom.ls.LSException;
29 import org.xml.sax.SAXException;
30
31
32
33
34
35
36
37
38
39 class DenyUnresolvedTest {
40
41 private static final String SYSTEM_ID = "http://invalid.example.invalid/external.dtd";
42
43 @AfterEach
44 void clearThrowOnUnresolved() {
45 System.clearProperty(SecureException.THROW_ON_UNRESOLVED);
46 }
47
48 @BeforeEach
49 void enableThrowOnUnresolved() {
50 System.setProperty(SecureException.THROW_ON_UNRESOLVED, "true");
51 }
52
53 @Test
54 void floorsThrowOnUnresolved() {
55 assertThrows(SAXException.class, () -> new FallbackIgnoreEntityResolver2(null).resolveEntity(null, SYSTEM_ID),
56 "EntityResolver2 floor should throw on an unresolved entity");
57 assertThrows(XMLStreamException.class, () -> new FallbackIgnoreXMLResolver(null).resolveEntity(null, SYSTEM_ID, null, null),
58 "XMLResolver floor should throw on an unresolved entity");
59 assertThrows(LSException.class, () -> new FallbackIgnoreLSResourceResolver(null).resolveResource(null, null, null, SYSTEM_ID, null),
60 "LSResourceResolver floor should throw on an unresolved resource");
61 assertThrows(TransformerException.class, () -> new FallbackIgnoreURIResolver(null, null, () -> false).resolve(SYSTEM_ID, null),
62 "URIResolver floor should throw on an unresolved URI");
63 }
64 }