add code injection filter
doesn't protect against "Expression Language Injection", therefore I've added an schema compiler option to activate the copying of the annotation which is by default off

git-svn-id: https://svn.apache.org/repos/asf/xmlbeans/trunk@1890934 13f79535-47bb-0310-9956-ffa450edef68
8 files changed