Class SecureSAXParserFactory
SAXParserFactory instances.
Beyond the three universal guarantees on org.apache.commons.xml.secure, XInclude resolution is denied by default. When
setXIncludeAware(true) is called on the returned factory, the parser will process xi:include
elements but every external resource lookup is rejected. To permit specific trusted resources, install an EntityResolver
on the XMLReader that allow-lists them; any href the resolver does not explicitly allow stays blocked.
This class is not itself a SAXParserFactory, so it inherits none of the static JAXP factory methods. A caller therefore cannot obtain an unsecured
factory through this class by calling a method such as newDefaultInstance(). The secure factories are instances of a nested, non-public wrapper
class.
- See Also:
-
Method Summary
Modifier and TypeMethodDescriptionstatic SAXParserFactoryReturns a new, secureSAXParserFactoryof the system-default implementation.static SAXParserFactoryReturns a new, secure, namespace-awareSAXParserFactoryof the system-default implementation, enabling namespace awareness onnewDefaultInstance(), the behaviorSAXParserFactory.newDefaultNSInstance()(Java 13 or later) is specified to have.static SAXParserFactoryReturns a new, secureSAXParserFactory.static SAXParserFactorynewInstance(String factoryClassName, ClassLoader classLoader) Returns a new, secureSAXParserFactoryof the given implementation class.static SAXParserFactoryReturns a new, secure, namespace-awareSAXParserFactory, enabling namespace awareness onnewInstance(), the behaviorSAXParserFactory.newNSInstance()(Java 13 or later) is specified to have.static SAXParserFactorynewNSInstance(String factoryClassName, ClassLoader classLoader) Returns a new, secure, namespace-awareSAXParserFactoryof the given implementation class, enabling namespace awareness onnewInstance(String, ClassLoader), the behaviorSAXParserFactory.newNSInstance(String, ClassLoader)(Java 13 or later) is specified to have.static SAXParserCreates a new, secure, namespace-awareSAXParserfromnewNSInstance().static XMLReaderCreates a new, secure, namespace-awareXMLReaderfromnewNSInstance(), with no content handler registered.static XMLReadernewNSXMLReader(ContentHandler handler) Creates a new, secure, namespace-awareXMLReaderfromnewNSInstance().
-
Method Details
-
newDefaultInstance
Returns a new, secureSAXParserFactoryof the system-default implementation.Obtained from
SAXParserFactory.newDefaultInstance()where the platform provides it (Java 9 or later), by instantiating the JDK's built-in implementation directly on Java 8, and by the standardnewInstance()lookup where the platform provides neither (for example, Android, whose lookup is itself pinned to the platform implementation).- Returns:
- A secure factory.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation.FactoryConfigurationError- Thrown from thenewInstance()lookup this method falls back to on a platform that provides neithernewDefaultInstance()nor the JDK's built-in implementation (for example, Android).
-
newDefaultNSInstance
Returns a new, secure, namespace-awareSAXParserFactoryof the system-default implementation, enabling namespace awareness onnewDefaultInstance(), the behaviorSAXParserFactory.newDefaultNSInstance()(Java 13 or later) is specified to have.- Returns:
- A secure, namespace-aware factory.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation.FactoryConfigurationError- Thrown from thenewInstance()lookupnewDefaultInstance()falls back to on a platform that provides neithernewDefaultInstance()nor the JDK's built-in implementation (for example, Android).
-
newInstance
Returns a new, secureSAXParserFactory.- Returns:
- A secure factory.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation.FactoryConfigurationError- Thrown fromSAXParserFactoryin case of aservice configuration erroror if the implementation is not available or cannot be instantiated.
-
newInstance
Returns a new, secureSAXParserFactoryof the given implementation class.- Parameters:
factoryClassName- The fully qualified class name of theSAXParserFactoryimplementation.classLoader- The class loader used to load the factory class;nullmeans the current thread's context class loader.- Returns:
- A secure factory.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation.FactoryConfigurationError- Thrown iffactoryClassNameisnullor the factory class cannot be loaded or instantiated.
-
newNSInstance
Returns a new, secure, namespace-awareSAXParserFactory, enabling namespace awareness onnewInstance(), the behaviorSAXParserFactory.newNSInstance()(Java 13 or later) is specified to have.- Returns:
- A secure, namespace-aware factory.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation.FactoryConfigurationError- Thrown fromSAXParserFactoryin case of aservice configuration erroror if the implementation is not available or cannot be instantiated.
-
newNSInstance
Returns a new, secure, namespace-awareSAXParserFactoryof the given implementation class, enabling namespace awareness onnewInstance(String, ClassLoader), the behaviorSAXParserFactory.newNSInstance(String, ClassLoader)(Java 13 or later) is specified to have.- Parameters:
factoryClassName- The fully qualified class name of theSAXParserFactoryimplementation.classLoader- The class loader used to load the factory class;nullmeans the current thread's context class loader.- Returns:
- A secure, namespace-aware factory.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation.FactoryConfigurationError- Thrown iffactoryClassNameisnullor the factory class cannot be loaded or instantiated.
-
newNSSAXParser
Creates a new, secure, namespace-awareSAXParserfromnewNSInstance().No factory is cached: each call configures a fresh one. To parse many documents, keep the returned parser and call
SAXParser.reset()between documents. Reusing the parser saves more than caching the factory would, andreset()costs next to nothing while keeping handler state from leaking between parses. A parser is not thread-safe, so reuse it within one thread.- Returns:
- A secure, namespace-aware parser.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation, or if the implementation cannot create a parser.FactoryConfigurationError- Thrown fromSAXParserFactoryin case of aservice configuration erroror if the implementation is not available or cannot be instantiated.- Since:
- 1.1.0
-
newNSXMLReader
Creates a new, secure, namespace-awareXMLReaderfromnewNSInstance(), with no content handler registered.No factory is cached: each call configures a fresh one. To parse many documents, keep the returned reader and parse each document with it. Reusing the reader saves more than caching the factory would. Handlers set on the reader stay set between parses, and a reader is not thread-safe, so reuse it within one thread.
- Returns:
- A secure, namespace-aware reader.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation, or if the implementation cannot create a reader.FactoryConfigurationError- Thrown fromSAXParserFactoryin case of aservice configuration erroror if the implementation is not available or cannot be instantiated.- Since:
- 1.1.0
-
newNSXMLReader
Creates a new, secure, namespace-awareXMLReaderfromnewNSInstance().No factory is cached: each call configures a fresh one. To parse many documents, keep the returned reader and parse each document with it. Reusing the reader saves more than caching the factory would. Handlers set on the reader stay set between parses, and a reader is not thread-safe, so reuse it within one thread.
- Parameters:
handler- The content handler to register on the reader, ornullto register none.- Returns:
- A secure, namespace-aware reader.
- Throws:
IllegalStateException- Thrown if a required secure setting cannot be applied to the underlying implementation, or if the implementation cannot create a reader.FactoryConfigurationError- Thrown fromSAXParserFactoryin case of aservice configuration erroror if the implementation is not available or cannot be instantiated.- Since:
- 1.1.0
-