Mercurial > prosody-hg
comparison core/xmlhandlers.lua @ 4287:ee6a18f10a8d
xmlhandlers/xmppstream: Stop the parser when encountering restricted XML, completing the fix for the billion laughs attack
| author | Matthew Wild <mwild1@gmail.com> |
|---|---|
| date | Thu, 02 Jun 2011 15:19:05 +0100 |
| parents | 65e2c089d138 |
| children | 8fde6b6b4919 |
comparison
equal
deleted
inserted
replaced
| 4280:65e2c089d138 | 4287:ee6a18f10a8d |
|---|---|
| 143 else | 143 else |
| 144 stanza:up(); | 144 stanza:up(); |
| 145 end | 145 end |
| 146 end | 146 end |
| 147 | 147 |
| 148 local function restricted_handler() | 148 local function restricted_handler(parser) |
| 149 cb_error(session, "parse-error", "restricted-xml", "Restricted XML, see RFC 6120 section 11.1."); | 149 cb_error(session, "parse-error", "restricted-xml", "Restricted XML, see RFC 6120 section 11.1."); |
| 150 if not parser:stop() then | |
| 151 error("Failed to abort parsing"); | |
| 152 end | |
| 150 end | 153 end |
| 151 | 154 |
| 152 if lxp_supports_doctype then | 155 if lxp_supports_doctype then |
| 153 xml_handlers.StartDoctypeDecl = restricted_handler; | 156 xml_handlers.StartDoctypeDecl = restricted_handler; |
| 154 end | 157 end |
