davsclaus commented on code in PR #26904:
URL: https://github.com/apache/camel/pull/26904#discussion_r4112512185


##########
docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc:
##########
@@ -2921,3 +2921,28 @@ This is the intended behaviour and makes the `keepOpen` 
toggle deterministic, bu
 relied on the setter being inert until an exchange arrived must be aware of 
the change.
 Setting `keepOpen` back to `false` remains deferred: the half-open timer 
attempts to close the circuit on
 its next tick (after `halfOpenAfter` milliseconds, default 30 s).
+
+=== camel-xslt - external document() access is denied by default

Review Comment:
   This lands under `== ThrottlingExceptionRoutePolicy` (a level-2 heading), so 
it shows as a subsection of that policy. Please move it into the 4.22 → 4.23 
section. Also worth mentioning that `camel-xslt-saxon` is affected: 
`XsltSaxonEndpoint` sets the same deny-all attribute and Saxon reports it 
through `getAttribute`.



##########
components/camel-xslt/src/main/java/org/apache/camel/component/xslt/XsltUriResolver.java:
##########
@@ -74,6 +123,14 @@ public Source resolve(String href, String base) throws 
TransformerException {
         String scheme = ResourceHelper.getScheme(href);
 
         if (scheme != null) {
+            if (isExternalAccessDenied(scheme)) {
+                // refuse the external resource by returning an empty 
document; document() then yields an empty
+                // node-set rather than the resource content, and the 
processor does not fall back to its own resolver
+                LOG.warn("Refusing to resolve external resource {} for the 
XSLT document() function: it is not permitted"
+                         + " by the transformer factory's 
ACCESS_EXTERNAL_STYLESHEET restriction",
+                        href);
+                return new StreamSource(new StringReader(DENIED_DOCUMENT));

Review Comment:
   Could this throw a `TransformerException` instead? In the JDK's XSLTC, 
`TransformerImpl.retrieveDocument` catches a `TransformerException` from the 
resolver and returns `null`, and `LoadDocument` then fails with 
`FileNotFoundException` / the access error. Only a `null` return from the 
resolver falls back to reading the resource, so throwing is also safe. It also 
matches what JAXP does on its own with `ACCESS_EXTERNAL_STYLESHEET=""`, and it 
avoids a legitimate transform silently producing empty values after the upgrade.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to