View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertFalse;
21  import static org.junit.jupiter.api.Assertions.assertNotNull;
22  import static org.junit.jupiter.api.Assertions.assertNull;
23  import static org.junit.jupiter.api.Assertions.assertTrue;
24  
25  import javax.xml.parsers.DocumentBuilderFactory;
26  
27  import org.junit.jupiter.api.Tag;
28  import org.junit.jupiter.api.Test;
29  
30  @Tag("dom")
31  class SecureDocumentBuilderTest {
32  
33      @Test
34      void createsDocument() throws Exception {
35          assertNotNull(new SecureDocumentBuilder(DocumentBuilderFactory.newInstance().newDocumentBuilder()).newDocument());
36      }
37  
38      @Test
39      void forwardsDocumentBuilderStateAndDomImplementation() throws Exception {
40          final DocumentBuilderFactory factory = DocumentBuilderFactory.newInstance();
41          factory.setNamespaceAware(true);
42          factory.setValidating(false);
43          if (AttackTestSupport.DOM_SUPPORTS_XINCLUDE) {
44              factory.setXIncludeAware(false);
45          }
46          if (AttackTestSupport.DOM_SUPPORTS_SCHEMA) {
47              factory.setSchema(null);
48          }
49          final SecureDocumentBuilder builder = new SecureDocumentBuilder(factory.newDocumentBuilder());
50          assertTrue(builder.isNamespaceAware());
51          assertFalse(builder.isValidating());
52          if (AttackTestSupport.DOM_SUPPORTS_XINCLUDE) {
53              assertFalse(builder.isXIncludeAware());
54          }
55          if (AttackTestSupport.DOM_SUPPORTS_SCHEMA) {
56              assertNull(builder.getSchema());
57          }
58          assertNotNull(builder.getDOMImplementation());
59      }
60  }