1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19 package org.apache.maven.repository.internal.metadata;
20
21 import java.io.IOException;
22 import java.io.InputStream;
23 import java.io.Reader;
24
25 import org.apache.maven.artifact.repository.metadata.Metadata;
26 import org.apache.maven.artifact.repository.metadata.Plugin;
27 import org.apache.maven.artifact.repository.metadata.SnapshotVersion;
28 import org.apache.maven.artifact.repository.metadata.Versioning;
29 import org.apache.maven.artifact.repository.metadata.io.xpp3.MetadataXpp3Reader;
30 import org.codehaus.plexus.util.xml.pull.XmlPullParserException;
31 import org.eclipse.aether.util.PathUtils;
32
33
34
35
36
37
38 public final class ValidatingMetadataXpp3Reader {
39 private final MetadataXpp3Reader mr = new MetadataXpp3Reader();
40
41
42
43
44 public Metadata read(Reader reader, boolean strict) throws IOException, XmlPullParserException {
45 try {
46 return validate(mr.read(reader, strict));
47 } catch (IllegalArgumentException e) {
48 throw new IOException("Invalid metadata detected: " + e.getMessage(), e);
49 }
50 }
51
52
53
54
55 public Metadata read(InputStream in, boolean strict) throws IOException, XmlPullParserException {
56 try {
57 return validate(mr.read(in, strict));
58 } catch (IllegalArgumentException e) {
59 throw new IOException("Invalid metadata detected: " + e.getMessage(), e);
60 }
61 }
62
63
64
65
66 private static Metadata validate(Metadata metadata) {
67 if (metadata != null) {
68 PathUtils.validatePathComponent(metadata.getVersion(), "version");
69 for (Plugin plugin : metadata.getPlugins()) {
70 PathUtils.validatePathComponent(plugin.getArtifactId(), "plugin/artifactId");
71 PathUtils.validatePathComponent(plugin.getPrefix(), "plugin/prefix");
72 }
73 Versioning versioning = metadata.getVersioning();
74 if (versioning != null) {
75 PathUtils.validatePathComponent(versioning.getLatest(), "versioning/latest");
76 PathUtils.validatePathComponent(versioning.getRelease(), "versioning/release");
77 for (int i = 0; i < versioning.getVersions().size(); i++) {
78 PathUtils.validatePathComponent(versioning.getVersions().get(i), "versioning/versions[" + i + "]");
79 }
80 if (versioning.getSnapshot() != null) {
81 PathUtils.validatePathComponent(
82 versioning.getSnapshot().getTimestamp(), "versioning/snapshot/timestamp");
83 }
84 for (int i = 0; i < versioning.getSnapshotVersions().size(); i++) {
85 SnapshotVersion snapshotVersion =
86 versioning.getSnapshotVersions().get(i);
87 PathUtils.validatePathComponent(
88 snapshotVersion.getVersion(), "versioning/snapshotVersions[" + i + "]/version");
89 }
90 }
91 }
92 return metadata;
93 }
94 }