From dc6a863a2d8d97bffe32125d6dab796d14b30b6a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Timon=20F=C3=A4rber?= Date: Thu, 30 Jan 2025 11:07:04 +0100 Subject: [PATCH 1/2] extend ValidationLogVisualizer to not use only filesystem --- .../ZUGFeRD/ValidationLogVisualizer.java | 29 +++++++++++++++++-- 1 file changed, 26 insertions(+), 3 deletions(-) diff --git a/library/src/main/java/org/mustangproject/ZUGFeRD/ValidationLogVisualizer.java b/library/src/main/java/org/mustangproject/ZUGFeRD/ValidationLogVisualizer.java index 686daa7c..d6397e22 100644 --- a/library/src/main/java/org/mustangproject/ZUGFeRD/ValidationLogVisualizer.java +++ b/library/src/main/java/org/mustangproject/ZUGFeRD/ValidationLogVisualizer.java @@ -1,5 +1,13 @@ package org.mustangproject.ZUGFeRD; +import java.io.BufferedOutputStream; +import java.io.ByteArrayInputStream; +import java.io.ByteArrayOutputStream; +import java.io.File; +import java.io.FileOutputStream; +import java.io.IOException; +import java.io.OutputStream; +import java.io.StringReader; import org.apache.fop.apps.*; import org.apache.fop.apps.io.ResourceResolverFactory; import org.apache.fop.configuration.Configuration; @@ -14,7 +22,7 @@ import javax.xml.transform.*; import javax.xml.transform.sax.SAXResult; import javax.xml.transform.stream.StreamResult; import javax.xml.transform.stream.StreamSource; -import java.io.*; + import java.nio.charset.StandardCharsets; public class ValidationLogVisualizer { @@ -70,7 +78,7 @@ public class ValidationLogVisualizer { return baos.toString(StandardCharsets.UTF_8); } - public void toPDF(String xmlLogfileContent, String pdfFilename) { + public byte[] createPDFBytes(String xmlLogfileContent) { // the writing part @@ -111,7 +119,8 @@ public class ValidationLogVisualizer { // Step 2: Set up output stream. // Note: Using BufferedOutputStream for performance reasons (helpful with FileOutputStreams). - try (OutputStream out = new BufferedOutputStream(new FileOutputStream(pdfFilename))) { + ByteArrayOutputStream baos = new ByteArrayOutputStream(); + try (OutputStream out = new BufferedOutputStream(baos)) { // Step 3: Construct fop with desired output format Fop fop = fopFactory.newFop(MimeConstants.MIME_PDF, userAgent, out); @@ -133,6 +142,20 @@ public class ValidationLogVisualizer { } catch (FOPException | IOException | TransformerException e) { LOGGER.error("Failed to create PDF", e); } + return baos.toByteArray(); + } + + public byte[] toPDF(String xmlLogfileContent) { + return createPDFBytes(xmlLogfileContent); + } + + public void toPDF(String xmlLogfileContent, String pdfFilename) { + byte[] pdfData = createPDFBytes(xmlLogfileContent); + try (FileOutputStream fos = new FileOutputStream(pdfFilename)) { + fos.write(pdfData); + } catch (IOException e) { + LOGGER.error("Failed to write PDF to file", e); + } } private static class ClasspathResourceURIResolver implements URIResolver { From d66761b017f3a22c76cc09ba207543d1b7bbc98b Mon Sep 17 00:00:00 2001 From: Jochen Staerk Date: Wed, 5 Mar 2025 11:23:50 +0100 Subject: [PATCH 2/2] Create SECURITY.md upon request :-) --- SECURITY.md | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..38dd608d --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,29 @@ +# Security Policy + +## Supported Versions + +The following versions are currently being supported with security updates. + +| Version | Supported | +| ------- | ------------------ | +| 2.x.x | :white_check_mark: | +| < 2.0 | :x: | + +## Reporting a Vulnerability + +Feel free to submit issues to info at mustangproject.org with [security] indicated in the subject. +We may ask back questions but we usually open (or communicate about) an issue (potentially in a private location you would be provided with access to) and decide on the severity within two working days. + +Please indicate +* a proof of concept, if possible +* If any of the information you submit, e.g. an invoice which can not be [anonymized](https://github.com/ZUGFeRD/einvoice-anonymizer), is confidential +* A quick justification why you require a fix in a older version than he most up to date one, if you can not update to the most recent version +* If you require encrypted communication (our GPG fingerprint will likely be 68F4 2269 8165 F0F5 63CA A13B 7CB7 1548 B596 66A3) + + +## After your Report + +We try to fix critical issues in less than a week, and release a fixed version in less than two weeks. + +Thank you for keeping our software safe! +