View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import java.util.Objects;
21  import java.util.function.Supplier;
22  
23  import javax.xml.transform.Source;
24  import javax.xml.transform.Templates;
25  import javax.xml.transform.URIResolver;
26  import javax.xml.transform.sax.TemplatesHandler;
27  
28  import org.xml.sax.Attributes;
29  import org.xml.sax.Locator;
30  import org.xml.sax.SAXException;
31  
32  /**
33   * {@link TemplatesHandler} wrapper whose only purpose is to return a {@link SecureTemplates} from {@link TemplatesHandler#getTemplates()}.
34   *
35   * <p>
36   * The handler itself only compiles: the caller drives the stylesheet's SAX events, and {@code xsl:include}/{@code xsl:import} hrefs already resolve through
37   * the delegate factory's resolver, which is the secure floor. What the raw handler lacks is the runtime side: the {@link Templates} it compiles produce
38   * Transformers without a {@link URIResolver} floor. Wrapping {@code getTemplates()} closes that, exactly as
39   * {@link javax.xml.transform.TransformerFactory#newTemplates newTemplates} does.
40   * </p>
41   */
42  final class SecureTemplatesHandler implements TemplatesHandler {
43  
44      private final TemplatesHandler delegate;
45  
46      /**
47       * Compile-time URIResolver snapshot, restored onto Transformers produced from the compiled Templates.
48       */
49      private final URIResolver factoryUriResolver;
50  
51      /**
52       * Empty-{@link Source} supplier for the produced Templates' floor; {@code null} means the default empty DOM.
53       */
54      private final Supplier<Source> emptySource;
55  
56      /**
57       * Snapshot of the factory's {@value SecureSAXParserFactory#OVERRIDE_DEFAULT_PARSER} outcome, carried onto the produced Templates.
58       */
59      private final boolean overrideDefaultParser;
60  
61      /**
62       * Constructs a new instance.
63       *
64       * @param delegate The delegate to wrap; must not be {@code null}.
65       * @param factoryUriResolver The factory's compile-time URIResolver snapshot to restore onto Transformers produced from the compiled Templates; may be
66       * {@code null}.
67       * @param emptySource The empty-{@link Source} supplier for the produced Templates; may be {@code null} for the default empty DOM document.
68       * @param overrideDefaultParser whether the produced Templates' source rewrites should use the pluggable parser lookup instead of the platform's built-in
69       * parser.
70       * @throws NullPointerException Thrown if {@code delegate} is {@code null}.
71       */
72      SecureTemplatesHandler(final TemplatesHandler delegate, final URIResolver factoryUriResolver, final Supplier<Source> emptySource,
73              final boolean overrideDefaultParser) {
74          this.delegate = Objects.requireNonNull(delegate, "delegate");
75          this.factoryUriResolver = factoryUriResolver;
76          this.emptySource = emptySource;
77          this.overrideDefaultParser = overrideDefaultParser;
78      }
79  
80      @Override
81      public void characters(final char[] ch, final int start, final int length) throws SAXException {
82          delegate.characters(ch, start, length);
83      }
84  
85      @Override
86      public void endDocument() throws SAXException {
87          delegate.endDocument();
88      }
89  
90      @Override
91      public void endElement(final String uri, final String localName, final String qName) throws SAXException {
92          delegate.endElement(uri, localName, qName);
93      }
94  
95      @Override
96      public void endPrefixMapping(final String prefix) throws SAXException {
97          delegate.endPrefixMapping(prefix);
98      }
99  
100     @Override
101     public String getSystemId() {
102         return delegate.getSystemId();
103     }
104 
105     @Override
106     public Templates getTemplates() {
107         // Null before the stylesheet's endDocument (and on a failed compile in some implementations).
108         final Templates templates = delegate.getTemplates();
109         return templates == null ? null : new SecureTemplates(templates, factoryUriResolver, emptySource, overrideDefaultParser);
110     }
111 
112     @Override
113     public void ignorableWhitespace(final char[] ch, final int start, final int length) throws SAXException {
114         delegate.ignorableWhitespace(ch, start, length);
115     }
116 
117     @Override
118     public void processingInstruction(final String target, final String data) throws SAXException {
119         delegate.processingInstruction(target, data);
120     }
121 
122     @Override
123     public void setDocumentLocator(final Locator locator) {
124         delegate.setDocumentLocator(locator);
125     }
126 
127     @Override
128     public void setSystemId(final String systemID) {
129         delegate.setSystemId(systemID);
130     }
131 
132     @Override
133     public void skippedEntity(final String name) throws SAXException {
134         delegate.skippedEntity(name);
135     }
136 
137 
138     @Override
139     public void startDocument() throws SAXException {
140         delegate.startDocument();
141     }
142 
143     @Override
144     public void startElement(final String uri, final String localName, final String qName, final Attributes atts) throws SAXException {
145         delegate.startElement(uri, localName, qName, atts);
146     }
147 
148     @Override
149     public void startPrefixMapping(final String prefix, final String uri) throws SAXException {
150         delegate.startPrefixMapping(prefix, uri);
151     }
152 }