Fabio Burzigotti created CXF-9253:
-------------------------------------
Summary: 4.1.9 breaks WSS4J WSHandler:checkSignatureConfirmation
unless 4.0.2 is used
Key: CXF-9253
URL: https://issues.apache.org/jira/browse/CXF-9253
Project: CXF
Issue Type: Bug
Affects Versions: 4.1.9
Reporter: Fabio Burzigotti
Fix For: 4.1.9
WSS4J 4.0.2 introduced two changes related to signature values:
1.
[https://github.com/apache/ws-wss4j/commit/2d4a0e7da15be3e97d83b20b739886cea724b5b4]
- change in WSHandler, to store strings instead of integers for signature
values.
2.
[https://github.com/apache/ws-wss4j/commit/347cead366e516710281d1c2a7b58a1513c28ec5]
- change in WSHandler, to support producers that still use integer signature
values.
Apache CXF 4.1.9 behavior changed from 4.1.8, on order to align with (1), see
[CXF 4.1.9 PR #3529|https://github.com/apache/cxf/pull/3529/changes]
unconditionally changed the _sendSignatureValues_ format. Accordingly WSS4J
[was bumped to 4.0.2|https://github.com/apache/cxf/pull/3527]
The latter represents a hard requirement to depend on such version, but it is
shipped via a micro release, that would usually be integrated with no further
changes expected.
As a confirmation, we've experimented with JBossWS CXF tests and one failure is
caused by the Apache CXF version bump, unless WSS4J is bumped too (4.0.1 ->
4.0.2), since the producer doesn't take the 4.0.1 use case (int signature
values) into account.
It seems reasonable to introduce the new behavior (storing strings) in 4.1.9,
but maybe - given it's a patch release - it could preserve the legacy behavior
as a default, externalize opt-in via configuration property, to eventually
deprecate and then replace in a minor/major update.
An alternative could be to have it documented that users upgrading to Apache
CXF 4.1.9 must also update WSS4J to 4.0.2.
WDYT?
--
This message was sent by Atlassian Jira
(v8.20.10#820010)