View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertThrows;
21  import static org.junit.jupiter.api.Assertions.assertTrue;
22  
23  import java.io.IOException;
24  import java.io.StringReader;
25  
26  import javax.xml.parsers.SAXParserFactory;
27  
28  import org.junit.jupiter.api.Tag;
29  import org.junit.jupiter.api.Test;
30  import org.xml.sax.InputSource;
31  import org.xml.sax.helpers.DefaultHandler;
32  import org.xml.sax.helpers.XMLFilterImpl;
33  
34  @Tag("sax")
35  class SecureXMLReaderTest {
36  
37      private static final class RecordingReader extends XMLFilterImpl {
38  
39          boolean inputSourceParsed;
40  
41          boolean systemIdParsed;
42  
43          @Override
44          public void parse(final InputSource input) {
45              inputSourceParsed = true;
46          }
47  
48          @Override
49          public void parse(final String systemId) {
50              systemIdParsed = true;
51          }
52      }
53  
54      @Test
55      void forwardsBothParseOverloads() throws Exception {
56          final RecordingReader delegate = new RecordingReader();
57          final SecureXMLReader reader = new SecureXMLReader(delegate);
58          reader.parse(new InputSource());
59          reader.parse("system");
60          assertTrue(delegate.inputSourceParsed);
61          assertTrue(delegate.systemIdParsed);
62      }
63  
64      @Test
65      void forwardsReaderConfigurationAndParse() throws Exception {
66          final SecureXMLReader reader = new SecureXMLReader(SAXParserFactory.newInstance().newSAXParser().getXMLReader());
67          final DefaultHandler handler = new DefaultHandler();
68          reader.setContentHandler(handler);
69          reader.setDTDHandler(handler);
70          reader.setErrorHandler(handler);
71          reader.setEntityResolver((publicId, systemId) -> null);
72          reader.getContentHandler();
73          reader.getDTDHandler();
74          reader.getErrorHandler();
75          reader.getEntityResolver();
76          reader.parse(new InputSource(new StringReader("<root/>")));
77          assertThrows(IOException.class, () -> reader.parse("file:/definitely-not-present-commons-secure-xml-test.xml"));
78      }
79  }