View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import java.util.Objects;
21  
22  import javax.xml.validation.TypeInfoProvider;
23  import javax.xml.validation.ValidatorHandler;
24  
25  import org.w3c.dom.ls.LSResourceResolver;
26  import org.xml.sax.Attributes;
27  import org.xml.sax.ContentHandler;
28  import org.xml.sax.ErrorHandler;
29  import org.xml.sax.Locator;
30  import org.xml.sax.SAXException;
31  import org.xml.sax.SAXNotRecognizedException;
32  import org.xml.sax.SAXNotSupportedException;
33  
34  /**
35   * {@link ValidatorHandler} wrapper that keeps an ignore-all {@link LSResourceResolver} floor a caller cannot remove.
36   *
37   * <p>
38   * Blocks {@code xsi:schemaLocation} resolution during SAX-driven validation. A caller-set resolver is routed through a {@link
39   * FallbackIgnoreLSResourceResolver} rather than replacing the floor, so a schema the caller does not resolve resolves to empty instead of being fetched.
40   * </p>
41   */
42  final class SecureValidatorHandler extends ValidatorHandler {
43  
44      private final ValidatorHandler delegate;
45  
46      private final FallbackIgnoreLSResourceResolver floor = new FallbackIgnoreLSResourceResolver(null);
47  
48      /**
49       * Constructs a new instance.
50       *
51       * @param delegate The delegate to wrap; must not be {@code null}.
52       * @throws NullPointerException Thrown if {@code delegate} is {@code null}.
53       */
54      SecureValidatorHandler(final ValidatorHandler delegate) {
55          this.delegate = Objects.requireNonNull(delegate, "delegate");
56          delegate.setResourceResolver(floor);
57      }
58  
59      @Override
60      public void characters(final char[] ch, final int start, final int length) throws SAXException {
61          delegate.characters(ch, start, length);
62      }
63  
64      @Override
65      public void endDocument() throws SAXException {
66          delegate.endDocument();
67      }
68  
69      @Override
70      public void endElement(final String uri, final String localName, final String qName) throws SAXException {
71          delegate.endElement(uri, localName, qName);
72      }
73  
74      @Override
75      public void endPrefixMapping(final String prefix) throws SAXException {
76          delegate.endPrefixMapping(prefix);
77      }
78  
79      @Override
80      public ContentHandler getContentHandler() {
81          return delegate.getContentHandler();
82      }
83  
84      @Override
85      public ErrorHandler getErrorHandler() {
86          return delegate.getErrorHandler();
87      }
88  
89      @Override
90      public boolean getFeature(final String name) throws SAXNotRecognizedException, SAXNotSupportedException {
91          return delegate.getFeature(name);
92      }
93  
94      @Override
95      public Object getProperty(final String name) throws SAXNotRecognizedException, SAXNotSupportedException {
96          return delegate.getProperty(name);
97      }
98  
99      @Override
100     public LSResourceResolver getResourceResolver() {
101         return floor.getDelegate();
102     }
103 
104     @Override
105     public TypeInfoProvider getTypeInfoProvider() {
106         return delegate.getTypeInfoProvider();
107     }
108 
109     @Override
110     public void ignorableWhitespace(final char[] ch, final int start, final int length) throws SAXException {
111         delegate.ignorableWhitespace(ch, start, length);
112     }
113 
114     @Override
115     public void processingInstruction(final String target, final String data) throws SAXException {
116         delegate.processingInstruction(target, data);
117     }
118 
119     @Override
120     public void setContentHandler(final ContentHandler receiver) {
121         delegate.setContentHandler(receiver);
122     }
123 
124     @Override
125     public void setDocumentLocator(final Locator locator) {
126         delegate.setDocumentLocator(locator);
127     }
128 
129     @Override
130     public void setErrorHandler(final ErrorHandler errorHandler) {
131         delegate.setErrorHandler(errorHandler);
132     }
133 
134     @Override
135     public void setFeature(final String name, final boolean value) throws SAXNotRecognizedException, SAXNotSupportedException {
136         delegate.setFeature(name, value);
137     }
138 
139     @Override
140     public void setProperty(final String name, final Object object) throws SAXNotRecognizedException, SAXNotSupportedException {
141         delegate.setProperty(name, object);
142     }
143 
144     @Override
145     public void setResourceResolver(final LSResourceResolver resourceResolver) {
146         floor.setDelegate(resourceResolver);
147     }
148 
149     @Override
150     public void skippedEntity(final String name) throws SAXException {
151         delegate.skippedEntity(name);
152     }
153 
154 
155     @Override
156     public void startDocument() throws SAXException {
157         delegate.startDocument();
158     }
159 
160     @Override
161     public void startElement(final String uri, final String localName, final String qName, final Attributes atts) throws SAXException {
162         delegate.startElement(uri, localName, qName, atts);
163     }
164 
165     @Override
166     public void startPrefixMapping(final String prefix, final String uri) throws SAXException {
167         delegate.startPrefixMapping(prefix, uri);
168     }
169 }