This is an automated email from the ASF dual-hosted git repository.

coheigea pushed a commit to branch coheigea/sigconf
in repository https://gitbox.apache.org/repos/asf/cxf.git

commit 99185572afd5b14c582a38e017c622143e173690
Author: Colm O hEigeartaigh <[email protected]>
AuthorDate: Wed Sep 30 12:56:50 2026 +0100

    Store the whole Signature value for SignatureConfirmation
---
 .../ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java    | 6 ++++--
 .../org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java | 4 ++--
 2 files changed, 6 insertions(+), 4 deletions(-)

diff --git 
a/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java
 
b/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java
index 59d76a1f919..923cab1db45 100644
--- 
a/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java
+++ 
b/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java
@@ -24,6 +24,7 @@ import java.security.cert.X509Certificate;
 import java.time.Instant;
 import java.util.ArrayList;
 import java.util.Arrays;
+import java.util.Base64;
 import java.util.Collection;
 import java.util.HashSet;
 import java.util.Iterator;
@@ -177,7 +178,7 @@ public abstract class AbstractBindingBuilder extends 
AbstractCommonBindingHandle
 
     protected Set<WSEncryptionPart> encryptedTokensList = new HashSet<>();
 
-    protected Set<Integer> signatures = new HashSet<>();
+    protected Set<String> signatures = new HashSet<>();
 
     protected Element bottomUpElement;
     protected Element topDownElement;
@@ -2396,7 +2397,8 @@ public abstract class AbstractBindingBuilder extends 
AbstractCommonBindingHandle
 
     protected void addSig(byte[] val) {
         if (val != null && val.length > 0) {
-            signatures.add(Arrays.hashCode(val));
+            // Store the whole value (as WSS4J's WSHandler does) rather than a 
collidable 32-bit hash
+            signatures.add(Base64.getEncoder().encodeToString(val));
         }
     }
 
diff --git 
a/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java
 
b/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java
index 8f584d9458d..c8addc3cf80 100644
--- 
a/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java
+++ 
b/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java
@@ -83,7 +83,7 @@ public class SignatureConfirmationTest extends 
AbstractSecurityTest {
         //
         // Save the signature for future confirmation
         //
-        Set<Integer> sigv = 
CastUtils.cast((Set<?>)msg.get(WSHandlerConstants.SEND_SIGV));
+        Set<String> sigv = 
CastUtils.cast((Set<?>)msg.get(WSHandlerConstants.SEND_SIGV));
         assertNotNull(sigv);
         assertFalse(sigv.isEmpty());
 
@@ -116,7 +116,7 @@ public class SignatureConfirmationTest extends 
AbstractSecurityTest {
 
 
     private void testSignatureConfirmationResponse(
-        Set<Integer> sigSaved,
+        Set<String> sigSaved,
         List<WSHandlerResult> sigReceived
     ) throws Exception {
         Document doc = readDocument("wsse-request-clean.xml");

Reply via email to