Skip to content

Conversation

@joegallo
Copy link
Contributor

@joegallo joegallo commented Sep 17, 2025

At the moment there's only a test caller, but #130337 will add a non-test caller. This PR is related to the recent #133644 in that this is adding yet another method to XmlUtils (and that PR introduced the XmlUtils class to begin with).

So far all I've found is that we probably do indeed want to set XMLConstants.FEATURE_SECURE_PROCESSING to true -- there may be other options that we also want to set, but I haven't found them yet. If you know better than I do please speak up.

@joegallo joegallo requested review from a team as code owners September 17, 2025 15:42
@joegallo joegallo added >refactoring :Security/Security Security issues without another label Team:Security Meta label for security team v9.2.0 labels Sep 17, 2025
@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

@PeteGillinElastic
Copy link
Member

See, I didn't even know this was a thing! Since it's a thing, we should do it, but I think @richard-dennehy is much better placed than me to know whether this is the right thing.

Copy link
Contributor

@richard-dennehy richard-dennehy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As far as I understand, FEATURE_SECURE_PROCESSING is all we can/need to do here

@joegallo joegallo merged commit 1904abb into elastic:main Sep 18, 2025
40 checks passed
@joegallo joegallo deleted the add-xpath-to-xml-utils branch September 18, 2025 13:42
gmjehovich pushed a commit to gmjehovich/elasticsearch that referenced this pull request Sep 18, 2025
szybia added a commit to szybia/elasticsearch that referenced this pull request Sep 18, 2025
* upstream/main: (43 commits)
  Unmute testAckedIndexing to see if it still fails on main (elastic#134682)
  Silence time zone ID deprecation warning for JDK 25 due to log4j2 bug. (elastic#134719)
  Adding a getUnmodifiableSourceAndMetadata() method to IngestDocument (elastic#134816)
  Mark the create-index-from-source action as publicly available on Serverless (elastic#134953)
  ESQL: Rename command from INLINESTATS to INLINE STATS (elastic#134827)
  Document multi index query support for simplified retrievers (elastic#134980)
  [ML] Fix YAMl test to use correct query parameter type (elastic#134999)
  [Transform] Wait for PIT to close (elastic#134955)
  Add XPath to XmlUtils (elastic#134923)
  Fixing conditional processor mutability bugs (elastic#134936)
  [Transform] Lower loglevel of 3 transform-related error messages from ERROR to WARN (elastic#134985)
  Unmute pattern text tests. (elastic#134981)
  Integrate weights into simplified RRF retriever syntax (elastic#132680)
  Mute org.elasticsearch.xpack.esql.qa.mixed.MixedClusterEsqlSpecIT test {csv-spec:stats.CountDistinctWithConditions} elastic#134993
  Update periodic java-ea build to test java 26 pre-release (elastic#134983)
  Mute org.elasticsearch.xpack.esql.ccq.MultiClusterSpecIT test {csv-spec:stats.CountDistinctWithConditions} elastic#134984
  Fix and unmute testIndexSettingProviderPrivateSetting (elastic#134861)
  Add missing common cat params (elastic#134870)
  Support querying multiple indices with the simplified RRF retriever (elastic#134822)
  Allow including semantic field embeddings in _source (elastic#134717)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

>refactoring :Security/Security Security issues without another label Team:Security Meta label for security team v9.2.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants