Completely disable xml entity resolution

This commit is contained in:
mae 2023-08-05 14:13:49 +02:00
commit 48b1e9bdc7
4 changed files with 22 additions and 1 deletions

View file

@ -3,6 +3,11 @@ defmodule Pleroma.Web.XMLTest do
alias Pleroma.Web.XML
test "refuses to parse any entities from XML" do
data = File.read!("test/fixtures/xml_billion_laughs.xml")
assert(:error == XML.parse_document(data))
end
test "refuses to load external entities from XML" do
data = File.read!("test/fixtures/xml_external_entities.xml")
assert(:error == XML.parse_document(data))