View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one or more
3    * contributor license agreements.  See the NOTICE file distributed with
4    * this work for additional information regarding copyright ownership.
5    * The ASF licenses this file to You under the Apache License, Version 2.0
6    * (the "License"); you may not use this file except in compliance with
7    * the License.  You may obtain a copy of the License at
8    *
9    *      https://www.apache.org/licenses/LICENSE-2.0
10   *
11   * Unless required by applicable law or agreed to in writing, software
12   * distributed under the License is distributed on an "AS IS" BASIS,
13   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14   * See the License for the specific language governing permissions and
15   * limitations under the License.
16   */
17  
18  package org.apache.commons.xml.secure;
19  
20  import java.io.IOException;
21  import java.util.Objects;
22  
23  import org.xml.sax.ContentHandler;
24  import org.xml.sax.DTDHandler;
25  import org.xml.sax.EntityResolver;
26  import org.xml.sax.ErrorHandler;
27  import org.xml.sax.InputSource;
28  import org.xml.sax.SAXException;
29  import org.xml.sax.SAXNotRecognizedException;
30  import org.xml.sax.SAXNotSupportedException;
31  import org.xml.sax.XMLReader;
32  
33  /**
34   * {@link XMLReader} wrapper that keeps a {@link FallbackIgnoreEntityResolver2} floor as the reader's entity resolver, non-overridable by the caller.
35   *
36   * <p>
37   * The floor is installed once and stays the reader's entity resolver for the wrapper's lifetime; {@link #setEntityResolver(EntityResolver)} routes the
38   * caller's resolver through {@link FallbackIgnoreEntityResolver2#setDelegate} instead of replacing it. This includes the {@code DefaultHandler} that
39   * {@link javax.xml.parsers.SAXParser#parse(org.xml.sax.InputSource, org.xml.sax.helpers.DefaultHandler) SAXParser.parse(source, handler)} installs as the
40   * reader's entity resolver, which would otherwise silently replace the floor. {@link #getEntityResolver()} reports the caller's resolver unwrapped.
41   * </p>
42   *
43   * <p>
44   * Every other method forwards to the wrapped delegate; subclasses (e.g., {@code SecureExpatXMLReader}) add per-implementation fixups on top of the
45   * floor.
46   * </p>
47   */
48  class SecureXMLReader implements XMLReader {
49  
50      private final XMLReader delegate;
51  
52      private final FallbackIgnoreEntityResolver2 floor;
53  
54      /**
55       * Constructs a new instance.
56       *
57       * @param delegate The delegate to wrap; must not be {@code null}.
58       * @throws NullPointerException Thrown if {@code delegate} is {@code null}.
59       */
60      SecureXMLReader(final XMLReader delegate) {
61          this.delegate = Objects.requireNonNull(delegate, "delegate");
62          this.floor = new FallbackIgnoreEntityResolver2(null);
63          delegate.setEntityResolver(floor);
64      }
65  
66      @Override
67      public ContentHandler getContentHandler() {
68          return delegate.getContentHandler();
69      }
70  
71      /**
72       * Gets the wrapped reader, so tests can observe which parser implementation a rewrite picked.
73       *
74       * @return The wrapped reader.
75       */
76      XMLReader getDelegate() {
77          return delegate;
78      }
79  
80      @Override
81      public DTDHandler getDTDHandler() {
82          return delegate.getDTDHandler();
83      }
84  
85      @Override
86      public EntityResolver getEntityResolver() {
87          return floor.getDelegate();
88      }
89  
90      @Override
91      public ErrorHandler getErrorHandler() {
92          return delegate.getErrorHandler();
93      }
94  
95      @Override
96      public boolean getFeature(final String name) throws SAXNotRecognizedException, SAXNotSupportedException {
97          return delegate.getFeature(name);
98      }
99  
100     @Override
101     public Object getProperty(final String name) throws SAXNotRecognizedException, SAXNotSupportedException {
102         return delegate.getProperty(name);
103     }
104 
105     @Override
106     public void parse(final InputSource input) throws IOException, SAXException {
107         delegate.parse(input);
108     }
109 
110     @Override
111     public void parse(final String systemId) throws IOException, SAXException {
112         delegate.parse(systemId);
113     }
114 
115     /**
116      * Re-installs the floor as the wrapped reader's entity resolver and drops any caller-supplied resolver, restoring the just-created state.
117      */
118     void restoreFloor() {
119         floor.setDelegate(null);
120         delegate.setEntityResolver(floor);
121     }
122 
123     @Override
124     public void setContentHandler(final ContentHandler handler) {
125         delegate.setContentHandler(handler);
126     }
127 
128     @Override
129     public void setDTDHandler(final DTDHandler handler) {
130         delegate.setDTDHandler(handler);
131     }
132 
133     @Override
134     public void setEntityResolver(final EntityResolver resolver) {
135         floor.setDelegate(resolver);
136     }
137 
138     @Override
139     public void setErrorHandler(final ErrorHandler handler) {
140         delegate.setErrorHandler(handler);
141     }
142 
143     @Override
144     public void setFeature(final String name, final boolean value) throws SAXNotRecognizedException, SAXNotSupportedException {
145         delegate.setFeature(name, value);
146     }
147 
148     @Override
149     public void setProperty(final String name, final Object value) throws SAXNotRecognizedException, SAXNotSupportedException {
150         delegate.setProperty(name, value);
151     }
152 
153 }