security(quick-xml): bump version to 0.41.0
- and protect amount of properties - azure_core 0.21.0 is using quick-xml 0.31.0 which is Dos-able azure_core is no more maintained, would migrte to official azure lib later
This commit is contained in:
@@ -243,7 +243,10 @@ fn collect_xml_text<R: std::io::BufRead>(
|
||||
}
|
||||
match xml.read_event_into(&mut buf) {
|
||||
Ok(Event::Text(t)) => {
|
||||
if let Ok(decoded) = t.xml_content() {
|
||||
// quick-xml 0.41+ makes XmlVersion explicit on xml_content()
|
||||
// so callers pick 1.0 vs 1.1 entity-normalization rules. Text
|
||||
// extraction is version-agnostic — 1.0 is the sane default.
|
||||
if let Ok(decoded) = t.xml_content(quick_xml::XmlVersion::Implicit1_0) {
|
||||
out.push_str(&decoded);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -203,7 +203,10 @@ impl WopiDiscoveryService {
|
||||
|
||||
for attr in e.attributes().flatten() {
|
||||
let value = attr
|
||||
.decode_and_unescape_value(reader.decoder())
|
||||
.decoded_and_normalized_value(
|
||||
quick_xml::XmlVersion::Implicit1_0,
|
||||
reader.decoder(),
|
||||
)
|
||||
.map(|value| value.into_owned())
|
||||
.unwrap_or_else(|_| String::from_utf8_lossy(&attr.value).to_string());
|
||||
|
||||
|
||||
Reference in New Issue
Block a user