Bug #53063 [Fbk->NoF]: <xsl:include> and <xsl:import> are broken
| From: | php-bugs at lists dot php dot net | Date: | Tue, 30 Dec 2014 10:41:39 +0000 |
| Subject: | Bug #53063 [Fbk->NoF]: <xsl:include> and <xsl:import> are broken | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189400@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=53063&edit=1
ID: 53063
Updated by: php-bugs@lists.php.net
Reported by: robin2008 at altruists dot org
Summary: <xsl:include> and <xsl:import> are broken
-Status: Feedback
+Status: No Feedback
Type: Bug
Package: XSLT related
Operating System: Ubuntu 10.04
PHP Version: 5.3.3
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2013-12-02 13:56:20] r3wald at gmail dot com
Ditto. No problems anymore.
------------------------------------------------------------------------
[2013-12-02 13:32:23] mike@php.net
Cannot reproduce.
------------------------------------------------------------------------
[2010-12-02 09:30:46] r3wald at gmail dot com
Please have a look at: http://bugs.php.net/bug.php?id=52257 .
I had exactly the same issue as you have. Disabling redland.so finally resolved
it.
Robert
------------------------------------------------------------------------
[2010-10-14 08:37:01] robin2008 at altruists dot org
Description:
------------
Somewhere between 5.3.0 and 5.3.2, the security model for XSL has been over tightened. XSL
stylesheets which refer to other stylesheet by <xsl:import> or <xsl:include> now fail to
work.
Test script:
---------------
<?php
// PHP 5.3.2 XSLT BUG - <xsl:import> (and <xsl:include>) are broken
$aDOM= new DOMDocument();
$aDOM->loadXML('<?xml version="1.0"?><etc/>');
$stylesheet= new DOMDocument();
$proc= new XSLTProcessor();
$stylesheet->loadXML('<?xml version="1.0"?><stylesheet
version="1.0" xmlns="http://www.w3.org/1999/XSL/Transform"><import
href="somesheet.xslt"/><template match="/"/></stylesheet>');
$proc->importStyleSheet($stylesheet);
$oops= $proc->transformToDoc($aDOM);
?>
Expected result:
----------------
Assuming there is a valid stylesheet at "somesheet.xslt", the transform should work as per
the W3C spec.
Am I missing something? Is there, for example, a way to set this security default somewhere? Or a
class method for XSLTProcessor to disable this?
Actual result:
--------------
Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: error in
/home/robin/f2f/hardcode/xsl-import.php on line 10
Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: Local file read for
/home/robin/f2f/hardcode/somesheet.xslt refused in /home/robin/f2f/hardcode/xsl-import.php on line
10
Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: error in
/home/robin/f2f/hardcode/xsl-import.php on line 10
Warning: XSLTProcessor::importStylesheet() [xsltprocessor.importstylesheet]: xsl:import: read rights
for /home/robin/f2f/hardcode/somesheet.xslt denied in /home/robin/f2f/hardcode/xsl-import.php on
line 10
Warning: XSLTProcessor::transformToDoc() [xsltprocessor.transformtodoc]: No stylesheet associated to
this object in /home/robin/f2f/hardcode/xsl-import.php on line 11
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=53063&edit=1