InterviewSolution
| 1. |
Does Xstream Support Entities? |
|
Answer» Entity support is completely DEPENDENT on the XML PARSER. XStream uses by default the Xpp3 parser that does not support ENTITIES at all (like the kXML2 parser). Other parsers support entities, but they might have been turned off to avoid XXE VULNERABILITY. To enable the entities again, you have to overload the individual method of the HierarchicalStreamDriver implementation that generated the parser factory. Entity support is completely dependent on the XML parser. XStream uses by default the Xpp3 parser that does not support entities at all (like the kXML2 parser). Other parsers support entities, but they might have been turned off to avoid XXE vulnerability. To enable the entities again, you have to overload the individual method of the HierarchicalStreamDriver implementation that generated the parser factory. |
|