Hello,
The following stack trace is seen in HtmlUnit running under an access control policy that does not grant HtmlUnit read access to the file system:
java.security.AccessControlException: access denied
("java.io.FilePermission" "[redacted path]" "read")
at
java.security.AccessControlContext.checkPermission(AccessControlContext.java:472)
at
java.security.AccessController.checkPermission(AccessController.java:884)
at
java.lang.SecurityManager.checkPermission(SecurityManager.java:549)
at java.lang.SecurityManager.checkRead(SecurityManager.java:888)
at java.io.File.exists(File.java:814)
at
com.gargoylesoftware.htmlunit.WebClient.makeWebResponseForFileUrl(WebClient.java:1167)
at
com.gargoylesoftware.htmlunit.WebClient.loadWebResponse(WebClient.java:1262)
at
com.gargoylesoftware.htmlunit.WebClient.download(WebClient.java:2076)
at
com.gargoylesoftware.htmlunit.html.HtmlAnchor.doClickStateUpdate(HtmlAnchor.java:142)
at
com.gargoylesoftware.htmlunit.html.HtmlAnchor.doClickStateUpdate(HtmlAnchor.java:179)
at
com.gargoylesoftware.htmlunit.html.DomElement.click(DomElement.java:800)
at
com.gargoylesoftware.htmlunit.html.DomElement.click(DomElement.java:747)
at
com.gargoylesoftware.htmlunit.html.DomElement.click(DomElement.java:694)
This happened in a test case while clicking an anchor with an href attribute containing an URL with a file:// scheme.
I wrote a quick test to replicate the issue outside of the application where the stack trace was seen, by setting document.location to file:///etc/passwd and printing the result to stderr.
Index: com/gargoylesoftware/htmlunit/WebClientTest.java
===================================================================
--- com/gargoylesoftware/htmlunit/WebClientTest.java (revision 12953)
+++ com/gargoylesoftware/htmlunit/WebClientTest.java (working copy)
@@ -2303,4 +2303,24 @@
}
verify(cache);
}
+
+ @Test
+ public void fileAccess() throws Exception {
+ final String html =
+ "<html>\n"
+ + "<head>\n"
+ + "<title>file access test</title>\n"
+ + "</head>\n"
+ + "<body onload=\"document.location='file:///etc/passwd/'\">\n"
+ + "</body>\n"
+ + "</html>";
+
+ final WebClient client = getWebClient();
+ final MockWebConnection conn = new MockWebConnection();
+ conn.setResponse(URL_FIRST, html);
+ client.setWebConnection(conn);
+ UnexpectedPage p = (UnexpectedPage)client.getPage(URL_FIRST);
+ System.err.println(p.getWebResponse().getContentAsString());
+ }
+
}
When I run this, the output of /etc/passwd is printed.
This may cause security issues depending on what context HtmlUnit is used in.
URL_FIRST is an URL with an http scheme.
//Sebastian Cato