vp340 opened a new pull request, #3541:
URL: https://github.com/apache/cxf/pull/3541

   alternative solution CXF-9251
   
   **_2nd Scenario (log delayed + memory leak) (still present also in 4.0.11)_**
   So I only have time to do a quick test.
   I setup my java client to reset on purpose the connection and print the 
resulting response in InputStream (incoming response). 
   Here the result:
   <img width="1783" height="269" alt="image" 
src="https://github.com/user-attachments/assets/bdffa579-2deb-407d-a858-1be74189aafe";
 />
   
   So I think that those bytes that are in the CachedOutputStream **should** be 
log because this is proof  we actually sent them. 
   A owner of his server should be able to see what his service produce and 
sent onto the http socket... for audit purpose!
   Whether the client processes those bytes or discards them afterward is 
outside our scope, but on the server side, having a complete audit trail I 
think it'is crucial.
   
   For example (a little bit borderline) a malicious client could call and 
reset the connection to receive the first bytes of the response and have no 
response trace on the server side. 
   
   The logging with this solution is:
   
   > 05/10/2026 21:53:09.226 INFO  [http-nio-8080-exec-2] 
org.apache.cxf.services.ExampleServicePortType_v1.RESP_OUT - RESP_OUT
       Address: http://localhost:8080/example/cxf/ExampleService_v1
       Content-Type: text/xml
       ResponseCode: 200
       ExchangeId: 0357f765-bb44-4680-aaf4-84f8ee4ce68c
       ServiceName: ExampleService_v1
       PortName: ExampleServicePortType_v1
       PortTypeName: ExampleServicePortType_v1
       Headers: {}
       Payload: <soap:Envelope xmlns:soap="http://schemas.xmlsoap.or...etc...
   05/10/2026 21:53:09.230 WARN  [http-nio-8080-exec-2] 
org.apache.cxf.phase.PhaseInterceptorChain - Interceptor for 
{http://ws.schema/example/v1}ExampleService_v1#{http://ws.schema/example/v1}pluto
 has thrown exception, unwinding now
   org.apache.cxf.interceptor.Fault: java.io.IOException: Connection reset by 
peer
        at 
org.apache.cxf.interceptor.AbstractOutDatabindingInterceptor.writeParts(A


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to