Class SourceHttpMessageConverter<T extends Source>

java.lang.Object
org.springframework.http.converter.AbstractHttpMessageConverter<T>
org.springframework.http.converter.xml.SourceHttpMessageConverter<T>
Type Parameters:
T - the converted object type
All Implemented Interfaces:
HttpMessageConverter<T>

public class SourceHttpMessageConverter<T extends Source> extends AbstractHttpMessageConverter<T>
Implementation of HttpMessageConverter that can read and write Source objects.

Security considerations: supportDtd and processExternalEntities only apply when reading a request body into a DOMSource, SAXSource or StAXSource. They do not apply to writing. Spring Framework trusts the application and its data sources, so the XML being written is assumed to be application-controlled. Only reading untrusted XML is protected against XXE.

When a handler declares a StreamSource (or a plain Source, which resolves to it), the application opts in to receiving the raw, unparsed request body. That body is not processed by this converter and the application is responsible for any later processing of it, including writing it back out in a response. Echoing untrusted XML back to the client is an application-level decision; the application must parse or sanitize that XML safely first (for example by declaring a DOMSource).

This behavior is by design and is not considered a vulnerability in Spring Framework. Reports of XXE on the write path, or from raw StreamSource pass-through, will be closed as such.

Since:
3.0
Author:
Arjen Poutsma, Rossen Stoyanchev, Juergen Hoeller