Made the XML conformance section more succinct - #2451
Conversation
|
The issue was discussed in a meeting on 2022-10-07
View the transcript2. XML security risk: expansion of internal parsed entities (issue epub-specs#2447)See github issue epub-specs#2447. See github issue epub-specs#2433. Murata Makoto: old issue; more than 20 years ago.
Murata Makoto: if an internal reference references a different internal reference, things can get out of hand quickly. See github pull request epub-specs#2451. Ivan Herman: thanks Makoto for raising the issue.
Ivan Herman: which say that RS should be aware of this problem and should deal with it.. Dave Cramer: I don't think we can or should forbid internal entities. Murata Makoto: Basically, not our problem. Brady Duga: this is a known problem in XML. Are there known solutions?.
Ivan Herman: makoto may know about libraries. Murata Makoto: I'm not aware of general solutions. Dave Cramer: I don't think it's entirely fair to say that this implementation is non-conformant because it's not deploying my vulnerability. Wendy Reid: it's like the viewport discussion. Dave Cramer: I think we add something to the security section. Brady Duga: I agree putting this in the security section, maybe mentioning other xml vulnerabilities. Dave Cramer: Some of this is also outside the scope of the WG, we can't ask for people to patch the OS they are running dev machines on. Wendy Reid: consensus: let's look people look at Ivan's PR. |
|
@murata2makoto @mattgarrish we got stalled... are we ready to merge this? Note that the WG has briefly discussed the addition on the security section on its last call and we may get input from there, too. But at least the three of us should be aligned... |
|
Seems fine to me now. |
|
@murata2makoto I intend to merge this on the week end unless you have some further comments. |
|
Sorry for my belated response. This PR looks fine to me. |
This PR is a replacement for #2450, which was mistakenly branched off on an earlier state of the spec.
The PR also adds some text to the security section (also anticipating some WG discussion on #2447 to happen on 2022-10-06).
See: