1 /*
2 * Licensed to the Apache Software Foundation (ASF) under one or more
3 * contributor license agreements. See the NOTICE file distributed with
4 * this work for additional information regarding copyright ownership.
5 * The ASF licenses this file to You under the Apache License, Version 2.0
6 * (the "License"); you may not use this file except in compliance with
7 * the License. You may obtain a copy of the License at
8 *
9 * https://www.apache.org/licenses/LICENSE-2.0
10 *
11 * Unless required by applicable law or agreed to in writing, software
12 * distributed under the License is distributed on an "AS IS" BASIS,
13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 * See the License for the specific language governing permissions and
15 * limitations under the License.
16 */
17
18 package org.apache.commons.xml.secure;
19
20 import static org.junit.jupiter.api.Assertions.assertEquals;
21 import static org.junit.jupiter.api.Assertions.assertFalse;
22 import static org.junit.jupiter.api.Assertions.assertTrue;
23
24 import javax.xml.xpath.XPathFactory;
25
26 import org.junit.jupiter.api.Tag;
27 import org.junit.jupiter.api.Test;
28 import org.xml.sax.InputSource;
29
30 /**
31 * Tests that the document parse behind {@code XPath.evaluate(String, InputSource)} (and its compiled {@code XPathExpression} counterpart) cannot pull in an
32 * external general entity.
33 * <p>
34 * The stock JDK and Apache Xalan implement the {@link InputSource}-taking {@code evaluate} entry points by provisioning an internal document parser that
35 * {@code FEATURE_SECURE_PROCESSING} on the {@link XPathFactory} does not reach. The {@link SecureXPathFactory} wrapper parses the input through a secure
36 * {@code DocumentBuilder} instead, so the external reference resolves to empty on the floor, while the evaluation itself still works. Tagged {@code xpath}, so
37 * it runs under test-stockjdk, test-jdk-xerces, test-xalan and test-xalan-xerces; the Saxon engine takes the separate {@code SaxonProvider} path covered by
38 * {@code SaxonXPathExternalCallsTest}.
39 * </p>
40 */
41 @Tag("xpath")
42 class XPathInputSourceTest {
43
44 private static final String EXPRESSION = "string(/root/child)";
45
46 /**
47 * {@link AttackTestSupport#xmlBody} content whose single entity reference resolves to {@link AttackTestSupport#LEAKED_MARKER} if the DTD is fetched.
48 */
49 private static String entityPayload() {
50 return "<?xml version=\"1.0\"?>\n"
51 + "<!DOCTYPE root [\n <!ENTITY xxe SYSTEM \"" + AttackTestSupport.resourceUrl("referenced.txt") + "\">\n]>\n"
52 + AttackTestSupport.xmlBody("&xxe;");
53 }
54
55 @Test
56 void secureXPathEvaluateDoesNotLeak() throws Exception {
57 // Deterministic on every engine: the entity is declared in the internal subset and the floor resolves only its
58 // external content — to empty replacement text — so the pre-parse completes and the reference expands to nothing.
59 final String result = SecureXPathFactory.newInstance().newXPath().evaluate(EXPRESSION, AttackTestSupport.inputSource(entityPayload()));
60 assertFalse(result.contains(AttackTestSupport.LEAKED_MARKER), "external entity leaked into the XPath result: " + result);
61 }
62
63 @Test
64 void secureXPathEvaluatesPlainDocument() throws Exception {
65 // Positive control: the secure pre-parse still evaluates an entity-free document end to end.
66 final String result = SecureXPathFactory.newInstance().newXPath().evaluate(EXPRESSION,
67 AttackTestSupport.inputSource(AttackTestSupport.xmlBody("plain text")));
68 assertEquals("plain text", result, "secured XPath should evaluate a plain document");
69 }
70
71 @Test
72 void secureXPathExpressionEvaluateDoesNotLeak() throws Exception {
73 // Same declared-entity outcome as above on the compiled-expression entry point.
74 final String result = SecureXPathFactory.newInstance().newXPath().compile(EXPRESSION).evaluate(AttackTestSupport.inputSource(entityPayload()));
75 assertFalse(result.contains(AttackTestSupport.LEAKED_MARKER), "external entity leaked into the compiled XPath result: " + result);
76 }
77
78 @Test
79 void unconfiguredXPathEvaluateLeaks() throws Exception {
80 // Leak control: the unconfigured engine's internal parser resolves the entity, which is exactly what the wrapper exists to prevent.
81 final String result = XPathFactory.newInstance().newXPath().evaluate(EXPRESSION, AttackTestSupport.inputSource(entityPayload()));
82 assertTrue(result.contains(AttackTestSupport.LEAKED_MARKER), "unconfigured XPath was expected to resolve the external entity, got: " + result);
83 }
84 }