This is an automated email from the ASF dual-hosted git repository. coheigea pushed a commit to branch 4.1.x-fixes in repository https://gitbox.apache.org/repos/asf/cxf.git
commit f6dd9646c9803173ee286ab53505b9396667f53b Author: Colm O hEigeartaigh <[email protected]> AuthorDate: Wed Sep 30 15:20:45 2026 +0100 Store the whole Signature value for SignatureConfirmation (#3529) (cherry picked from commit 5d3864f1c8c48088bcea8d91e020f55d5c65e971) --- .../ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java | 6 ++++-- .../org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java | 4 ++-- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java b/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java index 59d76a1f919..923cab1db45 100644 --- a/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java +++ b/rt/ws/security/src/main/java/org/apache/cxf/ws/security/wss4j/policyhandlers/AbstractBindingBuilder.java @@ -24,6 +24,7 @@ import java.security.cert.X509Certificate; import java.time.Instant; import java.util.ArrayList; import java.util.Arrays; +import java.util.Base64; import java.util.Collection; import java.util.HashSet; import java.util.Iterator; @@ -177,7 +178,7 @@ public abstract class AbstractBindingBuilder extends AbstractCommonBindingHandle protected Set<WSEncryptionPart> encryptedTokensList = new HashSet<>(); - protected Set<Integer> signatures = new HashSet<>(); + protected Set<String> signatures = new HashSet<>(); protected Element bottomUpElement; protected Element topDownElement; @@ -2396,7 +2397,8 @@ public abstract class AbstractBindingBuilder extends AbstractCommonBindingHandle protected void addSig(byte[] val) { if (val != null && val.length > 0) { - signatures.add(Arrays.hashCode(val)); + // Store the whole value (as WSS4J's WSHandler does) rather than a collidable 32-bit hash + signatures.add(Base64.getEncoder().encodeToString(val)); } } diff --git a/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java b/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java index 8f584d9458d..c8addc3cf80 100644 --- a/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java +++ b/rt/ws/security/src/test/java/org/apache/cxf/ws/security/wss4j/SignatureConfirmationTest.java @@ -83,7 +83,7 @@ public class SignatureConfirmationTest extends AbstractSecurityTest { // // Save the signature for future confirmation // - Set<Integer> sigv = CastUtils.cast((Set<?>)msg.get(WSHandlerConstants.SEND_SIGV)); + Set<String> sigv = CastUtils.cast((Set<?>)msg.get(WSHandlerConstants.SEND_SIGV)); assertNotNull(sigv); assertFalse(sigv.isEmpty()); @@ -116,7 +116,7 @@ public class SignatureConfirmationTest extends AbstractSecurityTest { private void testSignatureConfirmationResponse( - Set<Integer> sigSaved, + Set<String> sigSaved, List<WSHandlerResult> sigReceived ) throws Exception { Document doc = readDocument("wsse-request-clean.xml");
