cxf-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From cohei...@apache.org
Subject svn commit: r1291815 - in /cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml: AbstractXmlSigInHandler.java EncryptionUtils.java
Date Tue, 21 Feb 2012 14:44:55 GMT
Author: coheigea
Date: Tue Feb 21 14:44:54 2012
New Revision: 1291815

URL: http://svn.apache.org/viewvc?rev=1291815&view=rev
Log:
Enabling secure validation for RS-Security

Modified:
    cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/AbstractXmlSigInHandler.java
    cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/EncryptionUtils.java

Modified: cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/AbstractXmlSigInHandler.java
URL: http://svn.apache.org/viewvc/cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/AbstractXmlSigInHandler.java?rev=1291815&r1=1291814&r2=1291815&view=diff
==============================================================================
--- cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/AbstractXmlSigInHandler.java
(original)
+++ cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/AbstractXmlSigInHandler.java
Tue Feb 21 14:44:54 2012
@@ -88,9 +88,7 @@ public class AbstractXmlSigInHandler ext
         boolean valid = false;
         Reference ref = null;
         try {
-            XMLSignature signature = new XMLSignature(signatureElement, "");
-            // TODO re-enable this line once we pick up xmlsec 1.5.0
-            // XMLSignature signature = new XMLSignature(signatureElement, "", true);  
+            XMLSignature signature = new XMLSignature(signatureElement, "", true);  
             ref = getReference(signature);
             Element signedElement = validateReference(root, ref);
             if (signedElement.hasAttributeNS(null, "ID")) {

Modified: cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/EncryptionUtils.java
URL: http://svn.apache.org/viewvc/cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/EncryptionUtils.java?rev=1291815&r1=1291814&r2=1291815&view=diff
==============================================================================
--- cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/EncryptionUtils.java
(original)
+++ cxf/branches/2.5.x-fixes/rt/rs/security/xml/src/main/java/org/apache/cxf/rs/security/xml/EncryptionUtils.java
Tue Feb 21 14:44:54 2012
@@ -64,6 +64,7 @@ public final class EncryptionUtils {
         throws WSSecurityException {
         try {
             XMLCipher cipher = XMLCipher.getInstance(symEncAlgo);
+            cipher.setSecureValidation(true);
             cipher.init(mode, key);
             return cipher;
         } catch (XMLEncryptionException ex) {



Mime
View raw message