Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 7 additions & 10 deletions oiosaml/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -163,19 +163,16 @@
<dependency>
<groupId>javax.xml.bind</groupId>
<artifactId>jaxb-api</artifactId>
<version>2.3.0</version>
<version>2.3.1</version>
</dependency>

<!-- JAXB reference implementation for the javax.xml.bind API. The 2.3.0 com.sun.xml.bind
artifacts generate accessors by reflecting into ClassLoader.defineClass, which JDK 16 and
later refuse -->
<dependency>
<groupId>com.sun.xml.bind</groupId>
<artifactId>jaxb-core</artifactId>
<version>2.3.0</version>
</dependency>

<dependency>
<groupId>com.sun.xml.bind</groupId>
<artifactId>jaxb-impl</artifactId>
<version>2.3.0</version>
<groupId>org.glassfish.jaxb</groupId>
<artifactId>jaxb-runtime</artifactId>
<version>2.3.9</version>
</dependency>

<dependency>
Expand Down
6 changes: 6 additions & 0 deletions oiosaml/src/main/java/dk/gov/oio/saml/oiobpp/OIOBPPUtil.java
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
import java.nio.charset.Charset;
import java.util.Base64;

import javax.xml.XMLConstants;
import javax.xml.bind.JAXBContext;
import javax.xml.bind.JAXBElement;
import javax.xml.bind.JAXBException;
Expand Down Expand Up @@ -59,6 +60,11 @@ private static Source getSecureSource(String object) throws JAXBException {
private static SAXParserFactory getSecureSAXParserFactory() throws SAXNotRecognizedException, SAXNotSupportedException, ParserConfigurationException {
SAXParserFactory spf = SAXParserFactory.newInstance();
spf.setNamespaceAware(true);

// Rejecting the document type declaration outright also rules out internal entities, which external
// entity handling alone does not cover
spf.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
spf.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);
spf.setFeature("http://xml.org/sax/features/external-general-entities", false);
spf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
spf.setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd", false);
Expand Down
22 changes: 22 additions & 0 deletions oiosaml/src/test/java/dk/gov/oio/saml/oiobpp/OIOBPPUtilTest.java
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,14 @@ public void testInvalidString() {
Assertions.assertEquals(null, result);
}

@DisplayName("Test OIOBPP string with a document type declaration")
@Test
public void testStringWithDoctype() {
PrivilegeList result = OIOBPPUtil.parse(doctypeString);

Assertions.assertEquals(null, result);
}

private static final String validString = "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n" +
"<bpp:PrivilegeList xmlns:bpp=\"http://digst.dk/oiosaml/basic_privilege_profile\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\">\n" +
" <PrivilegeGroup Scope=\"urn:dk:gov:saml:cvrNumberIdentifier:12345678\">\n" +
Expand All @@ -42,6 +50,20 @@ public void testInvalidString() {
" </PrivilegeGroup>\n" +
"</bpp:PrivilegeList>";

// Entities declared in the document type declaration expand into each other, so a short document turns
// into a very large one while it is parsed
private static final String doctypeString = "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n" +
"<!DOCTYPE bpp:PrivilegeList [\n" +
" <!ENTITY a \"aaaaaaaaaa\">\n" +
" <!ENTITY b \"&a;&a;&a;&a;&a;&a;&a;&a;&a;&a;\">\n" +
" <!ENTITY c \"&b;&b;&b;&b;&b;&b;&b;&b;&b;&b;\">\n" +
"]>\n" +
"<bpp:PrivilegeList xmlns:bpp=\"http://digst.dk/oiosaml/basic_privilege_profile\">\n" +
" <PrivilegeGroup Scope=\"urn:dk:gov:saml:cvrNumberIdentifier:12345678\">\n" +
" <Privilege>&c;</Privilege>\n" +
" </PrivilegeGroup>\n" +
"</bpp:PrivilegeList>";

private static final String invalidString = "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n" +
"<bpp:PrivilegeList xmlns:bpp=\"http://digst.dk/oiosaml/basic_privilege_profile\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\">\n" +
" <PrivilegeGroup Scope=\"urn:dk:gov:saml:cvrNumberIdentifier:12345678\">\n" +
Expand Down