Bug #53063 [Fbk->NoF]: <xsl:include> and <xsl:import> are broken

From: Date: Tue, 30 Dec 2014 10:41:39 +0000
Subject: Bug #53063 [Fbk->NoF]: <xsl:include> and <xsl:import> are broken
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189400@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=53063&edit=1 ID: 53063 Updated by: php-bugs@lists.php.net Reported by: robin2008 at altruists dot org Summary: <xsl:include> and <xsl:import> are broken -Status: Feedback +Status: No Feedback Type: Bug Package: XSLT related Operating System: Ubuntu 10.04 PHP Version: 5.3.3 Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2013-12-02 13:56:20] r3wald at gmail dot com Ditto. No problems anymore. ------------------------------------------------------------------------ [2013-12-02 13:32:23] mike@php.net Cannot reproduce. ------------------------------------------------------------------------ [2010-12-02 09:30:46] r3wald at gmail dot com Please have a look at: http://bugs.php.net/bug.php?id=52257 . I had exactly the same issue as you have. Disabling redland.so finally resolved it. Robert ------------------------------------------------------------------------ [2010-10-14 08:37:01] robin2008 at altruists dot org Description: ------------ Somewhere between 5.3.0 and 5.3.2, the security model for XSL has been over tightened. XSL stylesheets which refer to other stylesheet by <xsl:import> or <xsl:include> now fail to work. Test script: --------------- <?php // PHP 5.3.2 XSLT BUG - <xsl:import> (and <xsl:include>) are broken $aDOM= new DOMDocument(); $aDOM->loadXML('<?xml version="1.0"?><etc/>'); $stylesheet= new DOMDocument(); $proc= new XSLTProcessor(); $stylesheet->loadXML('<?xml version="1.0"?><stylesheet version="1.0" xmlns="http://www.w3.org/1999/XSL/Transform"><import href="somesheet.xslt"/><template match="/"/></stylesheet>'); $proc->importStyleSheet($stylesheet); $oops= $proc->transformToDoc($aDOM); ?> Expected result: ---------------- Assuming there is a valid stylesheet at "somesheet.xslt", the transform should work as per the W3C spec. Am I missing something? Is there, for example, a way to set this security default somewhere? Or a class method for XSLTProcessor to disable this? Actual result: -------------- Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: error in /home/robin/f2f/hardcode/xsl-import.php on line 10 Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: Local file read for /home/robin/f2f/hardcode/somesheet.xslt refused in /home/robin/f2f/hardcode/xsl-import.php on line 10 Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: error in /home/robin/f2f/hardcode/xsl-import.php on line 10 Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: xsl:import: read rights for /home/robin/f2f/hardcode/somesheet.xslt denied in /home/robin/f2f/hardcode/xsl-import.php on line 10 Warning: XSLTProcessor::transformToDoc() [xsltprocessor.transformtodoc]: No stylesheet associated to this object in /home/robin/f2f/hardcode/xsl-import.php on line 11 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=53063&edit=1

« previous php.bugs (#189400) next »