Skip to content

xml.dom.minidom should raise exception on invalid input #56338

Description

@KyleKeating
BPO 12129
Nosy @terryjreedy, @vadmium, @prodo56
Files
  • xmlNameVerification.py: code to validate xml element/attribute names
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2011-05-20.22:02:10.486>
    labels = ['expert-XML', 'type-bug']
    title = 'Document Object Model API - validation'
    updated_at = <Date 2016-12-23.08:39:36.590>
    user = 'https://bugs.python.org/KyleKeating'

    bugs.python.org fields:

    activity = <Date 2016-12-23.08:39:36.590>
    actor = 'pdeep5693'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['XML']
    creation = <Date 2011-05-20.22:02:10.486>
    creator = 'Kyle.Keating'
    dependencies = []
    files = ['31060']
    hgrepos = []
    issue_num = 12129
    keywords = []
    message_count = 7.0
    messages = ['136402', '137142', '137487', '137488', '193804', '258344', '283873']
    nosy_count = 5.0
    nosy_names = ['terry.reedy', 'Kyle.Keating', 'martin.panter', 'jocassid', 'pdeep5693']
    pr_nums = []
    priority = 'normal'
    resolution = None
    stage = None
    status = 'open'
    superseder = None
    type = 'behavior'
    url = 'https://bugs.python.org/issue12129'
    versions = ['Python 2.7', 'Python 3.5', 'Python 3.6']

    Activity

    1. KyleKeating commented on May 20, 2011

      KyleKeatingmannequin
      MannequinAuthor

      I was doing some tests on using this library and I noticed xml elements and attribute names could be created with mal-formed xml because special characters which can break validation are not cleaned or converted from their literal forms. Only the attribute values are cleaned, but not the names.

      For example

      import xml.dom
      
      
      doc.createElement("p\>\</p\>") 
      ...

      will just embed a pair of p tags in the xml result. I thought that the xml spec did not permit <, >, &, \n etc. in the element name or attribute name? Could I get some clarification on this, thanks!

    2. added
      stdlibStandard Library Python modules in the Lib/ directory
      type-bugAn unexpected behavior, bug, or error
      on May 20, 2011
    3. terryjreedy commented on May 28, 2011

      @terryjreedy
      Member

      I suspect you are right, but do not know the rules, and have never used the module. There is no particular person maintaining xml.dom.X at present.

      Could you please fill in the ... after the import to give a complete minimal example that fails? Someone could then test it on 3.2

    4. KyleKeating commented on Jun 2, 2011

      KyleKeatingmannequin
      MannequinAuthor

      This looks to break pretty good... I did confirm this on 3.0, I'm guessing 3.2 is the same.

      import sys
      import xml.dom
      
      doc = xml.dom.getDOMImplementation().createDocument(None, 'xml', None)
      doc.firstChild.appendChild(doc.createElement('element00'))
      
      element01 = doc.createElement('element01')
      element01.setAttribute('attribute', "script><![CDATA[alert('script!');]]></script>")
      doc.firstChild.appendChild(element01)
      
      element02 = doc.createElement("script><![CDATA[alert('script!');]]></script>")
      doc.firstChild.appendChild(element02)
      
      element03 = doc.createElement("new line \n")
      
      element03.setAttribute('attribute-name','new line \n')
      doc.firstChild.appendChild(element03)
      
      
      print (doc.toprettyxml(indent="  "))

      >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
      output:

      <?xml version="1.0" ?>
      <xml>
      <element/>
      <element01 attribute="script><![CDATA[alert('script!');]]></script
      >"/>
      <script><![CDATA[alert('script!');]]></script>/>
      <new line
      attribute-name="new line
      "/>
      </xml>

    5. KyleKeating commented on Jun 2, 2011

      KyleKeatingmannequin
      MannequinAuthor

      oops, the first xml element in the output should read "<element00/>" not "<element/>"

      just a typo! don't get confused!

    6. jocassid commented on Jul 28, 2013

      jocassidmannequin
      Mannequin

      I added the line print(str(doc)) after the call to getDomImplementation and verified that the errors that I'm seeing are coming from the xml.dom.minidom implemenation of xml.dom. Checking minidom.py I did not see any validation on the tagName that gets passed to createElement. http://www.w3.org/TR/xml11/#NT-NameStartChar lists the format of allowed names. Attached is a file containing the functions I was working on. My thinking is that if the tagName is not valid a ValueError should be thrown.

    7. vadmium commented on Jan 16, 2016

      @vadmium
      Member

      My limited understanding is that xml.dom and minidom are supposed to implement particular interfaces. So do these DOM interfaces specify if this validation should be done? If so, this would be a bug. Or is it just a question of whether Python should do extra validation not specified by the underlying DOM API?

    8. added and removed
      stdlibStandard Library Python modules in the Lib/ directory
      on Jan 16, 2016
    9. prodo56 commented on Dec 23, 2016

      prodo56mannequin
      Mannequin

      xml minidom.py needs extra validation in setAttributes for certain special characters depending on the attribute name. Attribute values cannot have special characters like <,> and cant be nested as described in the example below

      element01 = doc.createElement('element01')
      element01.setAttribute('attribute', "script><![CDATA[alert('script!');]]></script>")
      doc.firstChild.appendChild(element01)

      script shouldn't be allowed as a value for an attribute and I feel it should throw an exception (Value Exception) and as described above <,> shouldn't be allowed as attributes are more like key-value pairs. Could someone tell me if this is right? If it is, then minidom.py needs this extra level of validation for the same

    10. transferred this issue fromon Apr 10, 2022
    11. changed the title [-]Document Object Model API - validation[/-] [+]xml.dom.minidom should raise exception on invalid input[/+] on Oct 28, 2023
    12. added
      type-featureA feature request or enhancement
      3.13only security fixes
      and removed
      type-bugAn unexpected behavior, bug, or error
      on Oct 28, 2023
    13. serhiy-storchaka commented on Aug 30, 2026

      @serhiy-storchaka
      Member

      Fixed in 3.16 by GH-155641. createElement(), createAttribute(), setAttribute() and the other methods taking a name now raise InvalidCharacterErr if it is not a valid XML name, as the DOM requires.

      Attribute values are not affected: special characters in them are escaped when the document is serialized.

    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      3.13only security fixestopic-XMLtype-featureA feature request or enhancement

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions