【问题标题】:Apache CXF Password Type Always Sets DigestApache CXF 密码类型始终设置为摘要
【发布时间】:2019-09-10 11:23:53
【问题描述】:

我正在开发一个 Web 服务客户端项目,并使用 Apache CXF 向 Web 服务发送请求。 我需要将密码类型设置为密码文本。但即使我在 OutInterceptor 属性中设置它,它总是将密码类型设置为摘要。我该如何解决这个问题?

我的代码是这样的:

        JaxWsProxyFactoryBean factory = new JaxWsProxyFactoryBean();
        factory.setServiceClass(Test.class);
        factory.setAddress(url);
        factory.getInInterceptors().add(new SoapActionInInterceptor(action));
        factory.getOutInterceptors().add(new SoapActionOutInterceptor());
        Map<String, Object> outProps = new HashMap<String, Object>();
        outProps.put(WSHandlerConstants.ACTION, WSHandlerConstants.USERNAME_TOKEN);
        outProps.put(WSHandlerConstants.USER, username);
        outProps.put(WSHandlerConstants.PASSWORD_TYPE, WSConstants.PASSWORD_TEXT);

        ClientPasswordHandler handler = new ClientPasswordHandler();
        handler.setPassword(password);
        outProps.put(WSHandlerConstants.PW_CALLBACK_REF, handler);

        WSS4JStaxOutInterceptor wssOut = new WSS4JStaxOutInterceptor(outProps);
        factory.getOutInterceptors().add(wssOut);
        T serviceClient = (T) factory.create();
        Client client = ClientProxy.getClient(serviceClient);

        setClientPolicy(client);

clientPolicy 就是这个

   protected synchronized void setClientPolicy(Client client) {
    if (client != null) {
        HTTPConduit httpConduit = (HTTPConduit) client.getConduit();
        httpConduit.setAuthSupplier(null);
        httpConduit.setAuthorization(null);
        HTTPClientPolicy clientPolicy = new HTTPClientPolicy();
        clientPolicy.setConnectionTimeout(60000L);
        clientPolicy.setReceiveTimeout(60000L);
        httpConduit.setClient(clientPolicy);
    }
   }

org.apache.cxf -> 版本 3.1.6

org.apache.wss4j -> 版本 2.1.7

【问题讨论】:

    标签: apache web-services soap cxf


    【解决方案1】:

    我找到了解决方案。 WSS4JStaxOutInterceptor 扩展了 AbstractWSS4JStaxInterceptor 并且它具有设置我们发送的传入属性的功能。当它尝试设置密码属性时,它会使用“PasswordText”字符串检查传入属性,当我们使用 WSConstants 时,它的值是不同的。这就是为什么当我们使用“PasswordText”字符串设置属性值时它可以正常工作。拦截器的最终代码是:

    private WSS4JStaxOutInterceptor createSecurityInterceptor() {
        Map<String, Object> outProps = new HashMap<>();
        outProps.put(WSHandlerConstants.ACTION, WSHandlerConstants.USERNAME_TOKEN);
        outProps.put(WSHandlerConstants.USER, username);
        // AbstractWSS4JStaxInterceptor class parseNonBooleanProperties require "PasswordText" check this function before changing this line
        outProps.put(WSHandlerConstants.PASSWORD_TYPE, "PasswordText");
        // AbstractWSS4JStaxInterceptor class parseNonBooleanProperties require "PasswordText" check this function before changing this line
    
        ClientPasswordHandler handler = new ClientPasswordHandler();
        handler.setPassword(password);
        outProps.put(WSHandlerConstants.PW_CALLBACK_REF, handler);
        return new WSS4JStaxOutInterceptor(outProps);
    }
    

    这解决了问题。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2021-05-20
      • 1970-01-01
      • 1970-01-01
      • 2015-05-27
      • 1970-01-01
      • 1970-01-01
      • 2012-05-15
      相关资源
      最近更新 更多