1/*
2 * Copyright (c) 2016, Oracle and/or its affiliates. All rights reserved.
3 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
4 *
5 * This code is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License version 2 only, as
7 * published by the Free Software Foundation.
8 *
9 * This code is distributed in the hope that it will be useful, but WITHOUT
10 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
12 * version 2 for more details (a copy is included in the LICENSE file that
13 * accompanied this code).
14 *
15 * You should have received a copy of the GNU General Public License version
16 * 2 along with this work; if not, write to the Free Software Foundation,
17 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
18 *
19 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
20 * or visit www.oracle.com if you need additional information or have any
21 * questions.
22 */
23
24/**
25 * @test
26 * @bug 8151893
27 * @summary Tests for the jdk.xml.dsig.secureValidationPolicy security property
28 * @modules java.xml.crypto/org.jcp.xml.dsig.internal.dom
29 */
30
31import java.security.Security;
32import java.util.List;
33import org.jcp.xml.dsig.internal.dom.Policy;
34
35public class SecureValidationPolicy {
36
37    public static void main(String[] args) throws Exception {
38
39        List<String> restrictedSchemes = List.of("file:/tmp/foo",
40            "http://java.com", "https://java.com");
41        List<String> restrictedAlgs = List.of(
42            "http://www.w3.org/TR/1999/REC-xslt-19991116",
43            "http://www.w3.org/2001/04/xmldsig-more#rsa-md5",
44            "http://www.w3.org/2001/04/xmldsig-more#hmac-md5",
45            "http://www.w3.org/2001/04/xmldsig-more#md5");
46
47        // Test expected defaults
48        System.out.println("Testing defaults");
49        if (!Policy.restrictNumTransforms(6)) {
50            throw new Exception("maxTransforms not enforced");
51        }
52        if (!Policy.restrictNumReferences(31)) {
53            throw new Exception("maxReferences not enforced");
54        }
55        for (String scheme : restrictedSchemes) {
56            if (!Policy.restrictReferenceUriScheme(scheme)) {
57                throw new Exception(scheme + " scheme not restricted");
58            }
59        }
60        for (String alg : restrictedAlgs) {
61            if (!Policy.restrictAlg(alg)) {
62                throw new Exception(alg + " alg not restricted");
63            }
64        }
65        if (!Policy.restrictDuplicateIds()) {
66            throw new Exception("noDuplicateIds not enforced");
67        }
68        if (!Policy.restrictRetrievalMethodLoops()) {
69            throw new Exception("noRetrievalMethodLoops not enforced");
70        }
71    }
72}
73