Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-4759

No security headers created for policy with no Binding assertion

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Incomplete
    • 2.7
    • NeedMoreInfo
    • WS-* Components
    • None
    • Unknown

    Description

      For instance if a SOAP service has a policy with a supporting token of UsernameToken without a TransportBinding, SymmetricBinding or AsymmetricBinding then CXF will not send any security header.

      In PolicyBasedWSS4JOutInterceptorInternal.handleMessage, there is an attempt to create a dummy TransportBinding, when the policy itself had not specified a binding. However, without a TransportToken, the TransportBindingHandler will ignore any supporting tokens.

      Attachments

        1. UsernameToken-Plain.xml
          0.5 kB
          Paton Wong

        Activity

          People

            Unassigned Unassigned
            pwong.accelrys Paton Wong
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: