View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertEquals;
21  import static org.junit.jupiter.api.Assertions.assertInstanceOf;
22  import static org.junit.jupiter.api.Assertions.assertNull;
23  import static org.junit.jupiter.api.Assertions.assertSame;
24  
25  import java.io.StringReader;
26  import java.util.ArrayList;
27  import java.util.List;
28  
29  import javax.xml.transform.Templates;
30  import javax.xml.transform.TransformerFactory;
31  import javax.xml.transform.sax.TemplatesHandler;
32  import javax.xml.transform.stream.StreamSource;
33  
34  import org.junit.jupiter.api.Tag;
35  import org.junit.jupiter.api.Test;
36  import org.xml.sax.Attributes;
37  import org.xml.sax.Locator;
38  import org.xml.sax.helpers.DefaultHandler;
39  
40  @Tag("trax")
41  class SecureTemplatesHandlerTest {
42  
43      private static final class RecordingHandler extends DefaultHandler implements TemplatesHandler {
44  
45          final List<String> calls = new ArrayList<>();
46  
47          Templates templates;
48  
49          String systemId = "initial";
50  
51          @Override
52          public void characters(final char[] ch, final int start, final int length) {
53              calls.add("characters:" + start + ':' + length);
54          }
55  
56          @Override
57          public void endDocument() {
58              calls.add("endDocument");
59          }
60  
61          @Override
62          public void endElement(final String uri, final String localName, final String qName) {
63              calls.add("endElement:" + uri + ':' + localName + ':' + qName);
64          }
65  
66          @Override
67          public void endPrefixMapping(final String prefix) {
68              calls.add("endPrefixMapping:" + prefix);
69          }
70  
71          @Override
72          public String getSystemId() {
73              return systemId;
74          }
75  
76          @Override
77          public Templates getTemplates() {
78              return templates;
79          }
80  
81          @Override
82          public void ignorableWhitespace(final char[] ch, final int start, final int length) {
83              calls.add("ignorableWhitespace:" + start + ':' + length);
84          }
85  
86          @Override
87          public void processingInstruction(final String target, final String data) {
88              calls.add("processingInstruction:" + target + ':' + data);
89          }
90  
91          @Override
92          public void setDocumentLocator(final Locator locator) {
93              calls.add("setDocumentLocator");
94          }
95  
96          @Override
97          public void setSystemId(final String value) {
98              systemId = value;
99              calls.add("setSystemId:" + value);
100         }
101 
102         @Override
103         public void skippedEntity(final String name) {
104             calls.add("skippedEntity:" + name);
105         }
106 
107         @Override
108         public void startDocument() {
109             calls.add("startDocument");
110         }
111 
112         @Override
113         public void startElement(final String uri, final String localName, final String qName, final Attributes atts) {
114             calls.add("startElement:" + uri + ':' + localName + ':' + qName);
115         }
116 
117         @Override
118         public void startPrefixMapping(final String prefix, final String uri) {
119             calls.add("startPrefixMapping:" + prefix + ':' + uri);
120         }
121     }
122 
123     @Test
124     void forwardsEveryTemplatesHandlerMethodAndWrapsTemplates() throws Exception {
125         final RecordingHandler delegate = new RecordingHandler();
126         delegate.templates = TransformerFactory.newInstance()
127                 .newTemplates(new StreamSource(new StringReader("<xsl:stylesheet version='1.0' xmlns:xsl='http://www.w3.org/1999/XSL/Transform'/>")));
128         final SecureTemplatesHandler handler = new SecureTemplatesHandler(delegate, null, null, false);
129         final char[] chars = { 'x', 'y' };
130         handler.characters(chars, 1, 1);
131         handler.endDocument();
132         handler.endElement("u", "l", "q");
133         handler.endPrefixMapping("p");
134         handler.ignorableWhitespace(chars, 0, 2);
135         handler.processingInstruction("target", "data");
136         handler.setDocumentLocator(null);
137         handler.setSystemId("system");
138         handler.skippedEntity("entity");
139         handler.startDocument();
140         handler.startElement("u", "l", "q", null);
141         handler.startPrefixMapping("p", "u");
142         assertEquals("system", handler.getSystemId());
143         assertInstanceOf(SecureTemplates.class, handler.getTemplates());
144         assertEquals(12, delegate.calls.size());
145     }
146 
147     @Test
148     void preservesNullTemplates() {
149         final RecordingHandler delegate = new RecordingHandler();
150         assertNull(new SecureTemplatesHandler(delegate, null, null, false).getTemplates());
151         assertSame(null, delegate.templates);
152     }
153 }