This is an automated email from the ASF dual-hosted git repository.

coheigea pushed a commit to branch 3_0_x-fixes
in repository https://gitbox.apache.org/repos/asf/ws-wss4j.git

commit 66063094df94681d8efd8734c633d88a847c7964
Author: Colm O hEigeartaigh <[email protected]>
AuthorDate: Wed Sep 9 07:49:52 2026 +0100

    Correct XOP javadoc (#680)
---
 .../java/org/apache/wss4j/common/ConfigurationConstants.java     | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git 
a/ws-security-common/src/main/java/org/apache/wss4j/common/ConfigurationConstants.java
 
b/ws-security-common/src/main/java/org/apache/wss4j/common/ConfigurationConstants.java
index d65c5d79b..ff1b447e4 100644
--- 
a/ws-security-common/src/main/java/org/apache/wss4j/common/ConfigurationConstants.java
+++ 
b/ws-security-common/src/main/java/org/apache/wss4j/common/ConfigurationConstants.java
@@ -564,9 +564,12 @@ public class ConfigurationConstants {
     /**
      * Whether to search for and expand xop:Include Elements for encryption 
and signature (on the outbound
      * side) or for signature verification (on the inbound side). The default 
is false on the outbound
-     * side and true on the inbound side. What this means on the inbound side, 
is that the relevant attachment
-     * bytes are BASE-64 encoded and inserted into the Element. This ensures 
that the actual bytes are signed,
-     * and not just the reference.
+     * side. On the inbound side, the default is true when this configuration 
is processed via WSHandler
+     * (e.g. Axis/CXF interceptors); if a RequestData is instead passed 
directly to the DOM security engine
+     * without going through WSHandler, RequestData.expandXopInclude defaults 
to false and this property has
+     * no effect unless RequestData.setExpandXopInclude(true) is called 
explicitly. What "true" means on the
+     * inbound side, is that the relevant attachment bytes are BASE-64 encoded 
and inserted into the Element.
+     * This ensures that the actual bytes are signed, and not just the 
reference.
      */
     public static final String EXPAND_XOP_INCLUDE = "expandXOPInclude";
 

Reply via email to