向Solr发送HTML文档遇Zip bomb异常,能否调整Tika的XML嵌套深度限制?
Absolutely! You can adjust Tika's XML element nesting depth limit within Solr to resolve this "Zip bomb detected!" error caused by the default 100-level nesting restriction. Here are the step-by-step configurations for common Solr-Tika integration scenarios:
1. 配置ExtractRequestHandler(直接提取或基础导入)
If you're using Solr's ExtractingRequestHandler (e.g., for direct document uploads via /update/extract), follow these steps:
Step 1: 创建自定义Tika配置文件
Create a tika-config.xml file (place it in your Solr core's conf directory for easy access) with the following content, adjusting the maxDepth value to match your required nesting level:
<?xml version="1.0" encoding="UTF-8"?> <properties> <parsers> <!-- 配置XMLParser的嵌套深度 --> <parser class="org.apache.tika.parser.xml.XMLParser"> <params> <param name="maxDepth" type="int">500</param> <!-- 修改为你需要的嵌套层数 --> </params> </parser> <!-- HTMLParser继承自XMLParser,也可以单独配置 --> <parser class="org.apache.tika.parser.html.HtmlParser"> <params> <param name="maxDepth" type="int">500</param> </params> </parser> </parsers> </properties>
Step 2: 在solrconfig.xml中关联配置文件
Update your core's solrconfig.xml to let the ExtractingRequestHandler use your custom Tika config:
<requestHandler name="/update/extract" class="org.apache.solr.handler.extraction.ExtractingRequestHandler"> <lst name="defaults"> <str name="fmap.content">text</str> <str name="uprefix">ignored_</str> </lst> <!-- 添加初始化参数指向自定义配置 --> <init-param> <name>tika.config</name> <value>./conf/tika-config.xml</value> <!-- 路径对应配置文件的位置 --> </init-param> </requestHandler>
2. 配置Data Import Handler(DIH)中的TikaEntityProcessor
If you're using Tika via Solr's Data Import Handler (DIH) with TikaEntityProcessor, specify the custom Tika config directly in your data-config.xml:
<dataConfig> <dataSource type="BinFileDataSource" /> <document> <entity name="html_doc" processor="TikaEntityProcessor" url="/path/to/your/html/documents" format="html" tikaConfig="./conf/tika-config.xml"> <!-- 关联自定义Tika配置 --> <field column="content" name="text" /> <!-- 其他字段映射 --> </entity> </document> </dataConfig>
注意事项
- 权衡风险: Increasing
maxDepthbeyond the default 100 can expose you to potential memory issues or denial-of-service (DoS) attacks if processing maliciously nested documents. Set a value that matches your actual valid document's nesting structure, not arbitrarily high. - 路径验证: Ensure the
tika-config.xmlpath is accessible to Solr—using a relative path from the core's root (like./conf/tika-config.xml) is the most reliable approach for core-specific configurations. - 重启生效: After making these changes, restart your Solr instance to apply the new configuration.
内容的提问来源于stack exchange,提问作者Harinder

