IJPL-159489 compose: switch to secure document builder

GitOrigin-RevId: 2098ece50ef04beca112d2f4c1605a95d50a4cc3
This commit is contained in:
Vladimir Krivosheev
2026-02-10 08:49:40 +00:00
committed by intellij-monorepo-bot
parent 2c0b7e185b
commit ffb5a64d52
@@ -10,12 +10,12 @@ import com.intellij.openapi.project.Project
import com.intellij.openapi.vfs.VirtualFile
import com.intellij.psi.search.FilenameIndex
import com.intellij.psi.search.GlobalSearchScope
import com.intellij.util.createDocumentBuilder
import org.w3c.dom.Node
import org.xml.sax.InputSource
import java.io.ByteArrayInputStream
import java.nio.file.Files
import java.nio.file.Path
import javax.xml.parsers.DocumentBuilderFactory
import kotlin.io.path.extension
import kotlin.io.path.name
import kotlin.io.path.nameWithoutExtension
@@ -191,7 +191,7 @@ private suspend fun Path.getValueResourceItems(project: Project, qualifiers: Lis
val fileContent = readAction { toPsiFile(project)?.text } ?: return emptyList()
val text = InputSource(ByteArrayInputStream(fileContent.toByteArray()))
// it may throw exceptions if the file is not a valid XML file while the user is typing
val doc = runCatching { DocumentBuilderFactory.newInstance().newDocumentBuilder().parse(text) }.getOrNull() ?: return emptyList()
val doc = runCatching { createDocumentBuilder().parse(text) }.getOrNull() ?: return emptyList()
val items = doc.getElementsByTagName("resources").item(0).childNodes
val records = List(items.length) { items.item(it) }
@@ -220,4 +220,4 @@ internal data class ResourceAccessorItem(
val path: Path,
val offset: Long = -1,
val size: Long = -1,
)
)