Description
WSS4J cannot find a SAML Assertion that is referenced via a SecurityTokenReference, but is not in the SOAP message. WSS4J can find a SecurityContextToken that is not in the SOAP message by invoking a CallbackHandler to find the token, so this task is to do likewise for a SAML assertion.
See this CXF JIRA: