Skip to content

Publishing skips a QTI item whose DOCTYPE declares an entity instead of failing the channel #6226

Description

@rtibblesbot

❌ This issue is not open for contribution. Visit Contributing guidelines to learn about the contributing process and how to find suitable issues.

Target branch: unstable

Observed behavior

validate_qti_item raises lxml.etree.XMLSchemaValidateError: Internal error in XML Schema validation. on an item with an internal-subset entity declaration that the body references.
QTIExerciseGenerator._create_native_qti_item does not catch it, and create_exercise_archive runs the item loop without a try, so it propagates out of the publish.
Every other invalid item is logged and excluded from the package.

Errors and logs

>>> validate_qti_item('<!DOCTYPE qti-assessment-item [<!ENTITY e "zz">]><qti-assessment-item xmlns="http://www.imsglobal.org/xsd/imsqtiasi_v3p0" identifier="i" title="t" adaptive="false" time-dependent="false"><qti-item-body><p>&e;</p></qti-item-body></qti-assessment-item>')
lxml.etree.XMLSchemaValidateError: Internal error in XML Schema validation.

Expected behavior

The item is reported invalid, logged, and left out of the package like any other schema failure. The rest of the channel publishes.

User-facing consequences

One stored type == qti item (ricecooker upload or direct sync write; the parser comment in validation.py treats this input as untrusted) blocks publishing the whole channel.

Steps to reproduce

  1. Store the XML above as raw_data of a qti AssessmentItem on an exercise.
  2. Publish the channel.
  3. Publish fails with XMLSchemaValidateError.

Context

AI usage

I used Claude Code to review the #6223 branch and reproduce this against upstream/unstable with validate_qti_item. I did not run a full publish; the propagation through create_exercise_archive is read from the code.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions