View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertEquals;
21  import static org.junit.jupiter.api.Assertions.assertNull;
22  import static org.junit.jupiter.api.Assertions.assertSame;
23  import static org.junit.jupiter.api.Assertions.assertThrows;
24  import static org.junit.jupiter.api.Assertions.assertTrue;
25  
26  import java.io.IOException;
27  import java.util.Locale;
28  
29  import javax.xml.XMLConstants;
30  import javax.xml.transform.Result;
31  import javax.xml.transform.Source;
32  import javax.xml.validation.SchemaFactory;
33  import javax.xml.validation.Validator;
34  
35  import org.junit.jupiter.api.Tag;
36  import org.junit.jupiter.api.Test;
37  import org.w3c.dom.ls.LSResourceResolver;
38  import org.xml.sax.ErrorHandler;
39  import org.xml.sax.SAXException;
40  import org.xml.sax.SAXNotRecognizedException;
41  import org.xml.sax.SAXNotSupportedException;
42  import org.xml.sax.helpers.DefaultHandler;
43  
44  @Tag("schema")
45  class SecureValidatorTest {
46  
47      private static final class PropertyValidator extends Validator {
48  
49          private final Validator delegate;
50  
51          PropertyValidator() throws SAXException {
52              delegate = SchemaFactory.newInstance(XMLConstants.W3C_XML_SCHEMA_NS_URI).newSchema().newValidator();
53          }
54  
55          @Override
56          public ErrorHandler getErrorHandler() {
57              return delegate.getErrorHandler();
58          }
59  
60          @Override
61          public boolean getFeature(final String name) throws SAXNotRecognizedException, SAXNotSupportedException {
62              return delegate.getFeature(name);
63          }
64  
65          @Override
66          public Object getProperty(final String name) {
67              return "value";
68          }
69  
70          @Override
71          public LSResourceResolver getResourceResolver() {
72              return delegate.getResourceResolver();
73          }
74  
75          @Override
76          public void reset() {
77              delegate.reset();
78          }
79  
80          @Override
81          public void setErrorHandler(final ErrorHandler errorHandler) {
82              delegate.setErrorHandler(errorHandler);
83          }
84  
85          @Override
86          public void setFeature(final String name, final boolean value) throws SAXNotRecognizedException, SAXNotSupportedException {
87              delegate.setFeature(name, value);
88          }
89  
90          @Override
91          public void setProperty(final String name, final Object object) {
92              // This test double only needs to supply a property value.
93          }
94  
95          @Override
96          public void setResourceResolver(final LSResourceResolver resourceResolver) {
97              delegate.setResourceResolver(resourceResolver);
98          }
99  
100         @Override
101         public void validate(final Source source, final Result result)
102                 throws SAXException, IOException {
103             delegate.validate(source, result);
104         }
105     }
106 
107     @Test
108     void getsPropertiesFromTheDelegate() throws Exception {
109         assertEquals("value", new SecureValidator(new PropertyValidator(), false).getProperty("property"));
110     }
111 
112     @Test
113     void preservesNonRemovableResolverFloorAndForwardsConfiguration() throws Exception {
114         final SecureValidator validator = new SecureValidator(SchemaFactory.newInstance(XMLConstants.W3C_XML_SCHEMA_NS_URI).newSchema().newValidator(), false);
115         final DefaultHandler errorHandler = new DefaultHandler();
116         final LSResourceResolver resolver = (type, namespace, publicId, systemId, base) -> null;
117         validator.setErrorHandler(errorHandler);
118         assertSame(errorHandler, validator.getErrorHandler());
119         assertNull(validator.getResourceResolver());
120         validator.setResourceResolver(resolver);
121         validator.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);
122         validator.setProperty(TestConstants.LOCALE_PROPERTY, Locale.ROOT);
123         assertEquals(Locale.ROOT, validator.getProperty(TestConstants.LOCALE_PROPERTY));
124         assertSame(resolver, validator.getResourceResolver());
125         assertTrue(validator.getFeature(XMLConstants.FEATURE_SECURE_PROCESSING));
126         assertThrows(SAXNotRecognizedException.class, () -> validator.getProperty(TestConstants.ACCESS_EXTERNAL_SCHEMA));
127         validator.reset();
128         assertNull(validator.getResourceResolver());
129     }
130 }