View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import static org.junit.jupiter.api.Assertions.assertEquals;
21  import static org.junit.jupiter.api.Assertions.assertFalse;
22  import static org.junit.jupiter.api.Assertions.assertTrue;
23  
24  import javax.xml.xpath.XPathFactory;
25  
26  import org.junit.jupiter.api.Tag;
27  import org.junit.jupiter.api.Test;
28  import org.xml.sax.InputSource;
29  
30  /**
31   * Tests that the document parse behind {@code XPath.evaluate(String, InputSource)} (and its compiled {@code XPathExpression} counterpart) cannot pull in an
32   * external general entity.
33   * <p>
34   * The stock JDK and Apache Xalan implement the {@link InputSource}-taking {@code evaluate} entry points by provisioning an internal document parser that
35   * {@code FEATURE_SECURE_PROCESSING} on the {@link XPathFactory} does not reach. The {@link SecureXPathFactory} wrapper parses the input through a secure
36   * {@code DocumentBuilder} instead, so the external reference resolves to empty on the floor, while the evaluation itself still works. Tagged {@code xpath}, so
37   * it runs under test-stockjdk, test-jdk-xerces, test-xalan and test-xalan-xerces; the Saxon engine takes the separate {@code SaxonProvider} path covered by
38   * {@code SaxonXPathExternalCallsTest}.
39   * </p>
40   */
41  @Tag("xpath")
42  class XPathInputSourceTest {
43  
44      private static final String EXPRESSION = "string(/root/child)";
45  
46      /**
47       * {@link AttackTestSupport#xmlBody} content whose single entity reference resolves to {@link AttackTestSupport#LEAKED_MARKER} if the DTD is fetched.
48       */
49      private static String entityPayload() {
50          return "<?xml version=\"1.0\"?>\n"
51                  + "<!DOCTYPE root [\n  <!ENTITY xxe SYSTEM \"" + AttackTestSupport.resourceUrl("referenced.txt") + "\">\n]>\n"
52                  + AttackTestSupport.xmlBody("&xxe;");
53      }
54  
55      @Test
56      void secureXPathEvaluateDoesNotLeak() throws Exception {
57          // Deterministic on every engine: the entity is declared in the internal subset and the floor resolves only its
58          // external content — to empty replacement text — so the pre-parse completes and the reference expands to nothing.
59          final String result = SecureXPathFactory.newInstance().newXPath().evaluate(EXPRESSION, AttackTestSupport.inputSource(entityPayload()));
60          assertFalse(result.contains(AttackTestSupport.LEAKED_MARKER), "external entity leaked into the XPath result: " + result);
61      }
62  
63      @Test
64      void secureXPathEvaluatesPlainDocument() throws Exception {
65          // Positive control: the secure pre-parse still evaluates an entity-free document end to end.
66          final String result = SecureXPathFactory.newInstance().newXPath().evaluate(EXPRESSION,
67                  AttackTestSupport.inputSource(AttackTestSupport.xmlBody("plain text")));
68          assertEquals("plain text", result, "secured XPath should evaluate a plain document");
69      }
70  
71      @Test
72      void secureXPathExpressionEvaluateDoesNotLeak() throws Exception {
73          // Same declared-entity outcome as above on the compiled-expression entry point.
74          final String result = SecureXPathFactory.newInstance().newXPath().compile(EXPRESSION).evaluate(AttackTestSupport.inputSource(entityPayload()));
75          assertFalse(result.contains(AttackTestSupport.LEAKED_MARKER), "external entity leaked into the compiled XPath result: " + result);
76      }
77  
78      @Test
79      void unconfiguredXPathEvaluateLeaks() throws Exception {
80          // Leak control: the unconfigured engine's internal parser resolves the entity, which is exactly what the wrapper exists to prevent.
81          final String result = XPathFactory.newInstance().newXPath().evaluate(EXPRESSION, AttackTestSupport.inputSource(entityPayload()));
82          assertTrue(result.contains(AttackTestSupport.LEAKED_MARKER), "unconfigured XPath was expected to resolve the external entity, got: " + result);
83      }
84  }