Skip to content

fix: Allow internal DTD/entities in FVDL parsing while still blocking external XXE - #1118

Closed
jmadhur87 wants to merge 1 commit into
dev/v3.xfrom
fix/fprParsingDTDs
Closed

jmadhur87 wants to merge 1 commit into
dev/v3.xfrom
fix/fprParsingDTDs

Conversation

@jmadhur87

Copy link
Copy Markdown
Contributor

processAuditFvdl() blocked all DOCTYPEs (SUPPORT_DTD=false), breaking FPRs with internal-only entities. Now allows DTD parsing but blocks external entity resolution (IS_SUPPORTING_EXTERNAL_ENTITIES=false), keeping XXE protection while fixing the parsing failure.

@rsenden

rsenden commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

According to Copilot:


Why the test failed:

  • The exception is due to setting XMLConstants ACCESS_EXTERNAL_DTD on a StAX XMLInputFactory implementation that does not recognize that property.
  • That property is not portable for XMLInputFactory across runtimes/providers.
  • audit.fvdl contains no DOCTYPE or ENTITY declarations.

So, the proposed fix seems incorrect; it still sets the unsupported property, and unnecessarily allows DTD parsing. I've already pushed an alternative fix.

@rsenden rsenden closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants