cxf-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Colm O hEigeartaigh (JIRA)" <>
Subject [jira] [Commented] (CXF-3484) Password set to null in UsernameTokenValidator
Date Tue, 03 May 2011 13:40:03 GMT


Colm O hEigeartaigh commented on CXF-3484:

The way passwords are validated has changed between WSS4J 1.5.x and 1.6. See this blog post
for more details:

In a nutshell, the CallbackHandler implementation only supplies the password any more, and
does not do any validation, as was the case in 1.5.x. A new "Validator" interface takes care
of the validation of the password supplied by the CallbackHandler, so you can override this
if you want to do some custom validation. See:


> Password set to null in UsernameTokenValidator
> ----------------------------------------------
>                 Key: CXF-3484
>                 URL:
>             Project: CXF
>          Issue Type: Bug
>          Components: WS-* Components
>    Affects Versions: 2.4
>         Environment: Linux, jetty 6.10
>            Reporter: Nicolas Poirot
>            Priority: Minor
>              Labels: UserNameToken, security
>             Fix For: Invalid
> When trying to do basic authentication in Soap header with UserNameToken, token is well
read from XML, but badly passed to password callback.
> Line 165 of :
> WSPasswordCallback pwCb = 
>             new WSPasswordCallback(user, null, pwType, WSPasswordCallback.USERNAME_TOKEN,
> The password is set to null, while it has been correcty read just before.

This message is automatically generated by JIRA.
For more information on JIRA, see:

View raw message