A SchemaFactory compiles an XML Schema, and a Validator checks an XML instance against it. Both stages need an external-resource policy.
Java XML Schema validation: use a trusted schema without external fetches
Operational contract
This method takes a schema path selected by trusted configuration, rejects an oversized XML instance, and sets empty external DTD and schema-access lists on both factory and validator. The supplied schema file is the intended root input; external includes and imports are not allowed by this policy. Create a Validator for each operation instead of sharing mutable validation state across threads. A successful schema check proves conformance to that schema, not authorization to act on the document. The schema itself needs review and version control.
Failure case
A carrier changes its manifest format. The service chooses the approved local schema for that carrier version and validates the received bytes. If the schema tries to import an outside definition, compilation fails instead of fetching it. If XML fails validation, the request is rejected before database writes begin.
Java code
import java.io.ByteArrayInputStream;
import java.nio.file.Path;
import javax.xml.XMLConstants;
import javax.xml.transform.stream.StreamSource;
import javax.xml.validation.Schema;
import javax.xml.validation.SchemaFactory;
import javax.xml.validation.Validator;
public class LocalManifestSchemaGate {
public static void validate(Path approvedSchema, byte[] xml) throws Exception {
if (xml.length > 47_000) throw new IllegalArgumentException("XML exceeds cap");
SchemaFactory factory = SchemaFactory.newInstance(XMLConstants.W3C_XML_SCHEMA_NS_URI);
factory.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);
factory.setProperty(XMLConstants.ACCESS_EXTERNAL_DTD, "");
factory.setProperty(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
Schema schema = factory.newSchema(approvedSchema.toFile());
Validator validator = schema.newValidator();
validator.setProperty(XMLConstants.ACCESS_EXTERNAL_DTD, "");
validator.setProperty(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
validator.validate(new StreamSource(new ByteArrayInputStream(xml)));
}
}Performance and ownership cost
Schema compilation has a setup cost and retains schema structures; a service can reuse an immutable compiled Schema under its version policy. Each validation scans the instance and uses memory according to its grammar and provider. Keep an explicit input cap and processing limits.
Common Mistakes
- Do not accept unreviewed schema paths from a request.
- Do not allow imports merely because the root schema is local.
- Do not share one mutable Validator across concurrent requests.
Connected lessons
- Java DOM parsing: deny external XML access at the factory
- Java JDBC transactions: atomic updates and rollback
- Java file I/O: UTF-8, streaming reads, and path ownership
- Java StAX: pull XML events under a count and entity policy
- Java XPath: compile a fixed selection, not user-supplied code
- Java XML Transformer: bound serialized output and external access
- Java XML namespaces: select by URI and local name
- Java XML and archive boundaries quiz
- Advanced Java
