Reviewed 2026-08-28
Safe XML Parsing and XXE Boundaries
Reject external entities and unexpected document declarations before conversion.
Example input
<!DOCTYPE x [<!ENTITY e SYSTEM "file:///secret">]><x>&e;</x>
Expected output
Rejected: external entity declarations are not allowed
Reproducible method
- Preserve the original and create the smallest representative sample.
- Run a strict parse or validation before transformation.
- Record options, compare counts and structure, then test in the receiving system.
Common error
A permissive parser may read local files or make network requests.
Reduce a failure while retaining the problematic structure; this separates malformed input from unsupported behavior.
Technical limitation
Client-side rejection does not configure a separate server parser.
A successful preview does not remove format ambiguity or downstream requirements.
Security and privacy
Use hardened parsers and explicit byte, depth, and entity limits.
Local processing reduces transfer risk but cannot protect a compromised browser, unsafe extensions, clipboard history, or later misuse.
Verification checklist
- Check field, record, page, or byte counts.
- Review edge cases and error output.
- Retain the original until acceptance.
- Document assumptions for automation.