1 /*
2 * Licensed to the Apache Software Foundation (ASF) under one or more
3 * contributor license agreements. See the NOTICE file distributed with
4 * this work for additional information regarding copyright ownership.
5 * The ASF licenses this file to You under the Apache License, Version 2.0
6 * (the "License"); you may not use this file except in compliance with
7 * the License. You may obtain a copy of the License at
8 *
9 * https://www.apache.org/licenses/LICENSE-2.0
10 *
11 * Unless required by applicable law or agreed to in writing, software
12 * distributed under the License is distributed on an "AS IS" BASIS,
13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 * See the License for the specific language governing permissions and
15 * limitations under the License.
16 */
17
18 package org.apache.commons.xml.secure;
19
20 import org.junit.jupiter.api.Tag;
21 import org.junit.jupiter.api.Test;
22
23 /**
24 * Tests whether the XSLT {@code document()} function is resolved at transform time. Compilation succeeds (the function call is just XPath); the leak vector
25 * fires only when {@code Transformer.transform} is called and the function evaluates its URI argument.
26 */
27 @Tag("trax")
28 class TransformerDocumentTest {
29
30 @Test
31 void secureTransformerBlocks() {
32 AttackTestSupport.assertTemplatesDoesNotLeak(AttackTestSupport.resourceSource("with-document.xsl"));
33 }
34 }