View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import javax.xml.transform.Source;
21  import javax.xml.validation.Validator;
22  
23  import org.junit.jupiter.api.Assumptions;
24  import org.junit.jupiter.api.Tag;
25  import org.junit.jupiter.api.Test;
26  
27  /**
28   * Tests whether parsers can pull in an external DTD declared via {@code <!DOCTYPE root SYSTEM "...">}.
29   *
30   * <p>
31   * The wrapper points at {@code src/test/resources/leaked/referenced.dtd}, which declares a {@code leaked} entity. Each wrapper body references
32   * {@code &leaked;}, so the entity can only resolve if the DTD is actually fetched: a secure parser resolves the external subset to empty, leaving
33   * {@code &leaked;} undeclared, and skips the undefined reference (per XML 1.0 section 4.1 an undeclared reference is a validity constraint when the DOCTYPE
34   * has a system IDentifier, so a non-validating parse completes); an unconfigured parser fetches the DTD, the entity resolves, and the parse succeeds. The one
35   * exception is Woodstox, which rejects undeclared references unconditionally, so the StAX case accepts a block as well.
36   * </p>
37   *
38   * <p>
39   * Each parser type is exercised twice as a pair (unconfigured factory, expected to parse; secure factory, expected to complete without leaked
40   * content):
41   * </p>
42   *
43   * <ul>
44   *   <li>DOM, SAX and StAX direct XML parsing.</li>
45   *   <li>{@code SchemaFactory.newSchema(Source)} compilation of an XSD whose source has the DOCTYPE.</li>
46   *   <li>{@link Validator#validate(Source)} of an instance whose source has the DOCTYPE.</li>
47   *   <li>Identity {@code Transformer} reading the input XML.</li>
48   *   <li>{@code TransformerFactory.newTransformer(Source)} compilation of a stylesheet whose source has the DOCTYPE.</li>
49   * </ul>
50   */
51  class ExternalDtdTest {
52  
53      private static final String INSERTION = "&leaked;";
54  
55      private static String withDoctype(final String rootQName, final String body) {
56          return "<?xml version=\"1.0\"?>\n"
57                  + "<!DOCTYPE " + rootQName + " SYSTEM \"" + AttackTestSupport.resourceUrl("referenced.dtd") + "\">\n"
58                  + body + "\n";
59      }
60  
61      private static String xmlPayload() {
62          return withDoctype("root", AttackTestSupport.xmlBody(INSERTION));
63      }
64  
65      private static String xsdPayload() {
66          return withDoctype("xs:schema", AttackTestSupport.xsdBody(INSERTION));
67      }
68  
69      private static String xsltPayload() {
70      return withDoctype("xsl:stylesheet", AttackTestSupport.xsltBody(INSERTION));
71      }
72  
73      @Test
74      @Tag("dom")
75      void secureDomDoesNotLeak() {
76          Assumptions.assumeTrue(AttackTestSupport.DOM_RESOLVES_INTERNAL_ENTITIES,
77                  "Skipped: platform DOM does not resolve user-defined entities");
78          AttackTestSupport.assertDomDoesNotLeak(xmlPayload());
79      }
80  
81      @Test
82      @Tag("sax")
83      void secureSaxDoesNotLeak() {
84          AttackTestSupport.assertSaxDoesNotLeak(xmlPayload());
85      }
86  
87      @Test
88      @Tag("schema")
89      void secureSchemaDoesNotLeak() {
90          AttackTestSupport.assertSchemaDoesNotLeak(AttackTestSupport.streamSource(xsdPayload()));
91      }
92  
93      @Test
94      @Tag("stax")
95      void secureStaxBlocksOrDoesNotLeak() {
96          // Woodstox rejects a reference to an entity declared only in the emptied external subset; the Xerces lineage skips it as an unreported validity
97          // constraint because the DOCTYPE has a system identifier.
98          AttackTestSupport.assertStaxBlocksOrDoesNotLeak(xmlPayload());
99      }
100 
101     @Test
102     @Tag("trax")
103     void secureTemplatesDoesNotLeak() {
104         AttackTestSupport.assertTemplatesDoesNotLeak(AttackTestSupport.streamSource(xsltPayload()));
105     }
106 
107     @Test
108     @Tag("trax")
109     void secureTransformerDoesNotLeak() {
110         AttackTestSupport.assertTransformerDoesNotLeak(xmlPayload());
111     }
112 
113     @Test
114     @Tag("schema")
115     void secureValidatorDoesNotLeak() {
116         AttackTestSupport.assertValidatorDoesNotLeak(xmlPayload());
117     }
118 
119     @Test
120     @Tag("sax")
121     void secureXmlReaderDoesNotLeak() {
122         AttackTestSupport.assertXmlReaderDoesNotLeak(xmlPayload());
123     }
124 
125     @Test
126     @Tag("dom")
127     void unconfiguredDomParses() {
128         Assumptions.assumeTrue(AttackTestSupport.DOM_RESOLVES_INTERNAL_ENTITIES,
129                 "Skipped: platform DOM does not resolve user-defined entities");
130         AttackTestSupport.assertPermissiveDomParses(xmlPayload());
131     }
132 
133     @Test
134     @Tag("sax")
135     void unconfiguredSaxParses() {
136         AttackTestSupport.assertPermissiveSaxParses(xmlPayload());
137     }
138 
139     @Test
140     @Tag("schema")
141     void unconfiguredSchemaCompiles() {
142         AttackTestSupport.assertPermissiveSchemaCompiles(AttackTestSupport.streamSource(xsdPayload()));
143     }
144 
145     @Test
146     @Tag("stax")
147     void unconfiguredStaxParses() {
148         AttackTestSupport.assertPermissiveStaxParses(xmlPayload());
149     }
150 
151     @Test
152     @Tag("trax")
153     void unconfiguredTemplatesCompiles() {
154         AttackTestSupport.assertPermissiveTemplatesCompiles(xsltPayload());
155     }
156 
157     @Test
158     @Tag("trax")
159     void unconfiguredTransformerTransforms() {
160         AttackTestSupport.assertPermissiveTransformerTransforms(xmlPayload());
161     }
162 
163     @Test
164     @Tag("schema")
165     void unconfiguredValidatorValidates() {
166         AttackTestSupport.assertPermissiveValidatorValidates(xmlPayload());
167     }
168 }