Class SourceHttpMessageConverter<T extends Source>
- Type Parameters:
T- the converted object type
- All Implemented Interfaces:
HttpMessageConverter<T>
HttpMessageConverter
that can read and write Source objects.
Security considerations: supportDtd
and processExternalEntities only apply
when reading a request body into a DOMSource,
SAXSource or StAXSource. They do not apply to writing.
Spring Framework trusts the application and its data sources, so the XML being written
is assumed to be application-controlled. Only reading untrusted XML is
protected against XXE.
When a handler declares a StreamSource (or a plain Source,
which resolves to it), the application opts in to receiving the raw,
unparsed request body. That body is not processed by this converter
and the application is responsible for any later processing of it, including
writing it back out in a response. Echoing untrusted XML back to the client
is an application-level decision; the application must parse or sanitize
that XML safely first (for example by declaring a DOMSource).
This behavior is by design and is not considered a vulnerability in
Spring Framework. Reports of XXE on the write path, or from raw
StreamSource pass-through, will be closed as such.
- Since:
- 3.0
- Author:
- Arjen Poutsma, Rossen Stoyanchev, Juergen Hoeller
-
Field Summary
Fields inherited from class AbstractHttpMessageConverter
logger -
Constructor Summary
ConstructorsConstructorDescription -
Method Summary
Modifier and TypeMethodDescriptiongetContentLength(T t, @Nullable MediaType contentType) Returns the content length for the given type.booleanReturn whether XML external entities are allowed.booleanReturn whether DTD parsing is supported.protected TreadInternal(Class<? extends T> clazz, HttpInputMessage inputMessage) Abstract template method that reads the actual object.voidsetProcessExternalEntities(boolean processExternalEntities) Indicate whether external XML entities are processed when converting to a Source.voidsetSupportDtd(boolean supportDtd) Indicate whether DTD parsing should be supported when readingDOMSource,SAXSourceandStAXSourcerequest content.booleanIndicates whether the given class is supported by this converter.protected booleanIndicates whether this message converter can write the given object multiple times.protected voidwriteInternal(T t, HttpOutputMessage outputMessage) Abstract template method that writes the actual body.Methods inherited from class AbstractHttpMessageConverter
addDefaultHeaders, canRead, canRead, canWrite, canWrite, getDefaultCharset, getDefaultContentType, getSupportedMediaTypes, read, setDefaultCharset, setSupportedMediaTypes, writeMethods inherited from class Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface HttpMessageConverter
getSupportedMediaTypes
-
Constructor Details
-
SourceHttpMessageConverter
public SourceHttpMessageConverter()
-
-
Method Details
-
setSupportDtd
public void setSupportDtd(boolean supportDtd) Indicate whether DTD parsing should be supported when readingDOMSource,SAXSourceandStAXSourcerequest content.Default is
falsemeaning that DTD is disabled.This setting does not apply to raw
StreamSourcecontent or to writingSourceinstances; see the class-level documentation. -
isSupportDtd
public boolean isSupportDtd()Return whether DTD parsing is supported. -
setProcessExternalEntities
public void setProcessExternalEntities(boolean processExternalEntities) Indicate whether external XML entities are processed when converting to a Source.Default is
false, meaning that external entities are not resolved.This setting does not apply to raw
StreamSourcecontent or to writingSourceinstances; see the class-level documentation.Note: setting this option to
truealso automatically setssetSupportDtd(boolean)totrue. -
isProcessExternalEntities
public boolean isProcessExternalEntities()Return whether XML external entities are allowed. -
supports
Description copied from class:AbstractHttpMessageConverterIndicates whether the given class is supported by this converter.- Specified by:
supportsin classAbstractHttpMessageConverter<T extends Source>- Parameters:
clazz- the class to test for support- Returns:
trueif supported;falseotherwise
-
readInternal
protected T readInternal(Class<? extends T> clazz, HttpInputMessage inputMessage) throws IOException, HttpMessageNotReadableException Description copied from class:AbstractHttpMessageConverterAbstract template method that reads the actual object. Invoked fromAbstractHttpMessageConverter.read(Class, HttpInputMessage).- Specified by:
readInternalin classAbstractHttpMessageConverter<T extends Source>- Parameters:
clazz- the type of object to returninputMessage- the HTTP input message to read from- Returns:
- the converted object
- Throws:
IOException- in case of I/O errorsHttpMessageNotReadableException- in case of conversion errors
-
getContentLength
Description copied from class:AbstractHttpMessageConverterReturns the content length for the given type.By default, this returns
null, meaning that the content length is unknown. Can be overridden in subclasses.- Overrides:
getContentLengthin classAbstractHttpMessageConverter<T extends Source>- Parameters:
t- the type to return the content length for- Returns:
- the content length, or
nullif not known
-
writeInternal
protected void writeInternal(T t, HttpOutputMessage outputMessage) throws IOException, HttpMessageNotWritableException Description copied from class:AbstractHttpMessageConverterAbstract template method that writes the actual body. Invoked fromAbstractHttpMessageConverter.write(T, MediaType, HttpOutputMessage).- Specified by:
writeInternalin classAbstractHttpMessageConverter<T extends Source>- Parameters:
t- the object to write to the output messageoutputMessage- the HTTP output message to write to- Throws:
IOException- in case of I/O errorsHttpMessageNotWritableException- in case of conversion errors
-
supportsRepeatableWrites
Description copied from class:AbstractHttpMessageConverterIndicates whether this message converter can write the given object multiple times.The default implementation returns
false.- Overrides:
supportsRepeatableWritesin classAbstractHttpMessageConverter<T extends Source>- Parameters:
t- the object t- Returns:
trueiftcan be written repeatedly;falseotherwise
-