IJPL-159489 jewel: harden XML resource parsing

GitOrigin-RevId: e09c266010aa8664920d2ba59cc904c142680442
This commit is contained in:
Vladimir Krivosheev
2026-02-10 09:10:17 +00:00
committed by intellij-monorepo-bot
parent ffb5a64d52
commit d8932b7abf
@@ -50,8 +50,21 @@ public class ResourcePainterProvider(private val basePath: String, vararg classL
private val cache = ConcurrentHashMap<Int, Painter>()
@Suppress("HttpUrlsUsage")
private val documentBuilderFactory =
DocumentBuilderFactory.newDefaultInstance().apply { setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true) }
DocumentBuilderFactory.newDefaultInstance().apply {
isValidating = false
setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true)
setFeature("http://apache.org/xml/features/disallow-doctype-decl", true)
setFeature("http://xml.org/sax/features/external-general-entities", false)
setFeature("http://xml.org/sax/features/external-parameter-entities", false)
setFeature("http://apache.org/xml/features/nonvalidating/load-dtd-grammar", false)
setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd", false)
setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "")
setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "")
isXIncludeAware = false
isExpandEntityReferences = false
}
private fun Scope.resolveHint(hint: PainterHint) {
with(hint) {