...
This compliant solution shows the single argument checkPermission()
method and allows files in the local
directory, with the dtd
extension, to be read. DTDPermission
is a custom permission that enforces this level of access (See SEC08SEC10-J. Define custom security permissions for fine grained security for details on creating custom permissions). Even if the java.io.FilePermission
is granted to the application with the action "read", DTD
files will be subject to additional access control.
...