View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import java.util.Objects;
21  
22  import javax.xml.parsers.SAXParser;
23  import javax.xml.validation.Schema;
24  
25  import org.xml.sax.Parser;
26  import org.xml.sax.SAXException;
27  import org.xml.sax.SAXNotRecognizedException;
28  import org.xml.sax.SAXNotSupportedException;
29  import org.xml.sax.XMLReader;
30  import org.xml.sax.helpers.XMLReaderAdapter;
31  
32  /**
33   * {@link SAXParser} that exposes a secure {@link XMLReader} and a matching SAX 1 {@link Parser}.
34   *
35   * <p>
36   * Both views are produced from the same secure reader, so a caller reaching the parser through either the SAX 2 ({@link #getXMLReader()}) or the legacy
37   * SAX 1 ({@link #getParser()}) path gets the same securing. The SAX 1 view matters because some consumers, such as Xalan's identity transformer, still ask
38   * for a {@link Parser}.
39   * </p>
40   *
41   * <p>
42   * The secure reader is computed lazily on first access and cached: securing an {@link XMLReader} can install a new wrapper (Android's Expat path), so
43   * every parse must run through the same instance. The {@code parse(...)} overloads inherited from {@link SAXParser} dispatch virtually to
44   * {@link #getXMLReader()}
45   * and {@link #getParser()}, so they too run through the secure views without further overrides.
46   * </p>
47   */
48  final class SecureSAXParser extends SAXParser {
49  
50      private final SAXParser delegate;
51  
52      private XMLReader secureXMLReader;
53      private Parser secureParser;
54  
55      /**
56       * Constructs a new instance.
57       *
58       * @param delegate The delegate to wrap; must not be {@code null}.
59       * @throws NullPointerException Thrown if {@code delegate} is {@code null}.
60       */
61      SecureSAXParser(final SAXParser delegate) {
62          this.delegate = Objects.requireNonNull(delegate, "delegate");
63      }
64  
65      @Override
66      @SuppressWarnings("deprecation")
67      public Parser getParser() throws SAXException {
68          if (secureParser == null) {
69              final XMLReader reader = getXMLReader();
70              // Reuse the reader directly if it already is a SAX 1 parser; otherwise adapt it, so the SAX 1 path runs through the same secure reader.
71              secureParser = reader instanceof Parser ? (Parser) reader : new XMLReaderAdapter(reader);
72          }
73          return secureParser;
74      }
75  
76      @Override
77      public Object getProperty(final String name) throws SAXNotRecognizedException, SAXNotSupportedException {
78          return delegate.getProperty(name);
79      }
80  
81      @Override
82      public Schema getSchema() {
83          return delegate.getSchema();
84      }
85  
86      @Override
87      public XMLReader getXMLReader() throws SAXException {
88          if (secureXMLReader == null) {
89              secureXMLReader = SecureSAXParserFactory.secure(delegate.getXMLReader());
90          }
91          return secureXMLReader;
92      }
93  
94      @Override
95      public boolean isNamespaceAware() {
96          return delegate.isNamespaceAware();
97      }
98  
99      @Override
100     public boolean isValidating() {
101         return delegate.isValidating();
102     }
103 
104     @Override
105     public boolean isXIncludeAware() {
106         return delegate.isXIncludeAware();
107     }
108 
109     @Override
110     public void reset() {
111         delegate.reset();
112         // The JAXP reset contract reverts the delegate to its just-created state, which strips the securing from the one reader it hands out for its lifetime.
113         if (secureXMLReader instanceof SecureXMLReader) {
114             ((SecureXMLReader) secureXMLReader).restoreFloor();
115         } else {
116             secureXMLReader = null;
117             secureParser = null;
118         }
119     }
120 
121     @Override
122     public void setProperty(final String name, final Object value) throws SAXNotRecognizedException, SAXNotSupportedException {
123         delegate.setProperty(name, value);
124     }
125 
126 }