View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertEquals;
21  import static org.junit.jupiter.api.Assertions.assertInstanceOf;
22  import static org.junit.jupiter.api.Assertions.assertSame;
23  
24  import java.io.StringWriter;
25  
26  import javax.xml.transform.TransformerFactory;
27  import javax.xml.transform.URIResolver;
28  import javax.xml.transform.sax.SAXTransformerFactory;
29  import javax.xml.transform.sax.TransformerHandler;
30  import javax.xml.transform.stream.StreamResult;
31  
32  import org.junit.jupiter.api.Tag;
33  import org.junit.jupiter.api.Test;
34  import org.xml.sax.helpers.AttributesImpl;
35  import org.xml.sax.helpers.LocatorImpl;
36  
37  @Tag("trax")
38  class SecureTransformerHandlerTest {
39  
40      @Test
41      void adoptsAResolverTheHandlersTransformerCarries() throws Exception {
42          final SAXTransformerFactory factory = (SAXTransformerFactory) TransformerFactory.newInstance();
43          final TransformerHandler delegate = factory.newTransformerHandler();
44          // An implementation may seed the handler's transformer from the Templates it was built with; that resolver must survive the wrapping.
45          final URIResolver carried = (href, base) -> null;
46          delegate.getTransformer().setURIResolver(carried);
47          final SecureTransformerHandler handler = new SecureTransformerHandler(delegate, null, null, false);
48          assertSame(carried, handler.getTransformer().getURIResolver(), "the resolver the handler's transformer carried must survive the wrapping");
49      }
50  
51      @Test
52      void forwardsEveryTransformerHandlerMethod() throws Exception {
53          final SAXTransformerFactory factory = (SAXTransformerFactory) TransformerFactory.newInstance();
54          final SecureTransformerHandler handler = new SecureTransformerHandler(factory.newTransformerHandler(), null, null, false);
55          final char[] chars = { 'x' };
56          handler.setResult(new StreamResult(new StringWriter()));
57          handler.setDocumentLocator(new LocatorImpl());
58          handler.setSystemId("system");
59          handler.startDocument();
60          handler.startDTD("root", null, null);
61          handler.endDTD();
62          handler.startPrefixMapping("p", "urn:test");
63          handler.startElement("", "root", "root", new AttributesImpl());
64          handler.startCDATA();
65          handler.characters(chars, 0, 1);
66          handler.ignorableWhitespace(chars, 0, 1);
67          handler.comment(chars, 0, 1);
68          handler.endCDATA();
69          handler.processingInstruction("t", "d");
70          handler.notationDecl("n", "p", "s");
71          handler.unparsedEntityDecl("e", "p", "s", "n");
72          handler.startEntity("e");
73          handler.endEntity("e");
74          handler.skippedEntity("e");
75          handler.endElement("", "root", "root");
76          handler.endPrefixMapping("p");
77          handler.endDocument();
78          assertEquals("system", handler.getSystemId());
79          assertInstanceOf(SecureTransformer.class, handler.getTransformer());
80      }
81  }