View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertNotNull;
21  
22  import java.io.ByteArrayInputStream;
23  import java.io.InputStream;
24  import java.nio.charset.StandardCharsets;
25  
26  import javax.xml.bind.JAXBContext;
27  import javax.xml.bind.Unmarshaller;
28  import javax.xml.bind.annotation.XmlRootElement;
29  import javax.xml.parsers.SAXParserFactory;
30  import javax.xml.stream.XMLInputFactory;
31  import javax.xml.stream.XMLStreamReader;
32  import javax.xml.transform.sax.SAXSource;
33  
34  import org.junit.jupiter.api.Test;
35  import org.xml.sax.InputSource;
36  import org.xml.sax.XMLReader;
37  
38  /**
39   * Tests JAXB integration.
40   * <p>
41   * This class' two public methods serve as examples for the Javadoc {@code overview.html} file.
42   * </p>
43   */
44  public class JaxbTest {
45  
46      @XmlRootElement
47      static class MyJaxbModel {
48          // JAXB model fields and methods
49      }
50  
51      @Test
52      void testUnmarshalSecurelyWithSax() throws Exception {
53          try (InputStream xmlStream = new ByteArrayInputStream("<myJaxbModel/>".getBytes(StandardCharsets.UTF_8))) {
54              assertNotNull(new JaxbTest().unmarshalSecurelyWithSax(xmlStream));
55          }
56      }
57  
58      @Test
59      void testUnmarshalSecurelyWithStax() throws Exception {
60          try (InputStream xmlStream = new ByteArrayInputStream("<myJaxbModel/>".getBytes(StandardCharsets.UTF_8))) {
61              assertNotNull(new JaxbTest().unmarshalSecurelyWithStax(xmlStream));
62          }
63      }
64  
65      public MyJaxbModel unmarshalSecurelyWithSax(final InputStream xmlStream) throws Exception {
66          final JAXBContext context = JAXBContext.newInstance(MyJaxbModel.class);
67          final Unmarshaller unmarshaller = context.createUnmarshaller();
68          // Create a secure SAXParserFactory via Apache Commons Secure XML
69          final SAXParserFactory spf = SecureSAXParserFactory.newDefaultNSInstance();
70          // Generate a hardened XMLReader and wrap the input source
71          final XMLReader xmlReader = spf.newSAXParser().getXMLReader();
72          final SAXSource source = new SAXSource(xmlReader, new InputSource(xmlStream));
73          // With the default resolver configuration, external DTDs and entities are prevented from being fetched or resolved, protecting against XXE attacks, protecting against XXE attacks.
74          // Entity-expansion limits use FEATURE_SECURE_PROCESSING on JDK parsers;
75          // Android support is implementation-dependent and best-effort.
76          return (MyJaxbModel) unmarshaller.unmarshal(source);
77      }
78  
79      public MyJaxbModel unmarshalSecurelyWithStax(final InputStream xmlStream) throws Exception {
80          final JAXBContext context = JAXBContext.newInstance(MyJaxbModel.class);
81          final Unmarshaller unmarshaller = context.createUnmarshaller();
82          // Create a secure XMLInputFactory via Apache Commons Secure XML
83          final XMLInputFactory xif = SecureXMLInputFactory.newDefaultFactory();
84          // Create a hardened cursor reader
85          final XMLStreamReader xmlReader = xif.createXMLStreamReader(xmlStream);
86          try {
87              // With the default resolver configuration, external DTDs and entities are prevented from being fetched or resolved, protecting against XXE attacks, protecting against XXE attacks.
88              // Entity-expansion protection is implementation-dependent and best-effort
89              // because StAX exposes no secure-processing feature.
90              return (MyJaxbModel) unmarshaller.unmarshal(xmlReader);
91          } finally {
92              xmlReader.close();
93          }
94      }
95  }