Details
-
Improvement
-
Status: Closed
-
Trivial
-
Resolution: Done
-
Upcoming Branch
-
None
Description
It's about XslTransform.java. A part of its code was marked as deprecated with OFBIZ-6274, ie at least 8 years ago. I confirm this part is not used at all.
I did not spot it by chance. This was bring to my attention by codeQL as a possible XXE. Even if in our case it's impossible since we don't use this code. Semantic code analysis engine like codeQL are not able to discover that, would be far too long anyway. Whatever, it's good to get rid of it now.