This is an automated email from the ASF dual-hosted git repository.
dependabot[bot] pushed a change to branch
dependabot/maven/com.fasterxml.woodstox-woodstox-core-7.2.2
in repository https://gitbox.apache.org/repos/asf/ws-wss4j.git
discard 50a3762aa Bump com.fasterxml.woodstox:woodstox-core from 7.1.1 to 7.2.2
add 52d6ae3dc Bump github/codeql-action/analyze from 4.37.7 to 4.37.9
(#664)
add ca3cb9345 Bump actions/setup-java from 5.7.0 to 6.0.0 (#662)
add bf841412e Bump github/codeql-action/init from 4.37.7 to 4.37.9 (#661)
add de3a53f07 Bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9
(#663)
add 447079e99 Group codeql updates (#665)
add 340ff3fce Enforce signature protection as well for SOAP 12 streaming
(#666)
add cc9bf13b2 Put a lower bound of 16 bytes on minimum derived key length
(#667)
add 51272fcf4 Enable and fix derived key WS-SecurityPolicy validation in
the DOM code (#668)
add 7626a1a44 Put a max bound on Derived Key offset + length (#669)
add 5ea75cf71 Fix a potential NPE with HSM based Crypto instances in the
derived key parser (#670)
add 80e7603d1 Align StAX security header processing with the DOM code
(#671)
add d29494dd5 Only set the StAX RSA 1.5 + UsernameToken No Password
properties if we have a corresponding policy (#672)
add debfd9cec Bump org.apache.felix:maven-bundle-plugin from 6.0.2 to
6.1.0 (#659)
add 57534d6de Bump org.apache.maven.plugins:maven-surefire-plugin from
3.5.5 to 3.5.6 (#658)
add 20a13eafc Enforce isAllowRSA15KeyTransportAlgorithm for the StAX layer
(#674)
add a8804c63c Bump org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2
(#675)
add cd7de419d Reject mismatched symmetric key lengths to prevent
cross-algorithm key reuse (#677)
add 1a0a1eee5 Check the SOAPAction matches the body for the StAX policy
case (#678)
add 41c351d24 PMD test fix
add 0c03575b8 Add security documentation for StAX (#679)
add c304f475c Correct XOP javadoc (#680)
add b12975b46 Removing duplicate ReplayCache call
add ef2bb58a7 Fix issues with SignedElements / EncryptedElements (#682)
add b1f77e8da WSS-729 Switch default JasyptPasswordEncryptor algorithm to
PBEWithHmacSHA512AndAES_256 (#683)
add 84e6de096 Reject duplicate C14N settings + Detect unknown top-level
policy assertions (#684)
add 512bf20ed Fix sender-vouches signature referencing (#685)
add bb75f5a85 Docs update
add 144367bb6 Make sure we can't register a fake SOAP Body for lookup
(#686)
add 64c78eeb7 EncryptedHeader child confusion causing wrong
protected-header selection (#687)
add 3ad7085b7 Make sure for Attachment-Complete the mime type is read from
the encrypted header (#688)
add 6c3257a83 Harden Loader to only load from file + jar by default (#689)
add ea0ca8af3 Harden XML parsing via commons-secure-xml (#673)
add b08d04e8e Improving docs for subject cert constraint (#690)
add b621c16e0 Fix bug with signature policy validation for STR Transform
(#691)
add cd7e54d48 Bump com.fasterxml.woodstox:woodstox-core from 7.1.1 to 7.2.2
This update added new revisions after undoing existing revisions.
That is to say, some revisions that were in the old version of the
branch are not in the new version. This situation occurs
when a user --force pushes a change and generates a repository
containing something like this:
* -- * -- B -- O -- O -- O (50a3762aa)
\
N -- N -- N
refs/heads/dependabot/maven/com.fasterxml.woodstox-woodstox-core-7.2.2
(cd7e54d48)
You should already have received notification emails for all of the O
revisions, and so the following emails describe only the N revisions
from the common base, B.
Any revisions marked "omit" are not gone; other references still
refer to them. Any revisions marked "discard" are gone forever.
No new revisions were added by this update.
Summary of changes:
.github/dependabot.yml | 4 +
.github/workflows/codeql-analysis.yml | 6 +-
.github/workflows/pull-request-build.yaml | 2 +-
.github/workflows/scorecards.yml | 2 +-
THREAT-MODEL.md | 4 +-
integration/pom.xml | 4 +
.../integration/test/kerberos/KerberosTest.java | 13 +-
parent/pom.xml | 7 +-
.../apache/wss4j/policy/model/AlgorithmSuite.java | 7 +
pom.xml | 4 +-
src/site/asciidoc/best_practice.adoc | 10 +-
src/site/asciidoc/config.adoc | 15 +-
src/site/asciidoc/newfeatures20.adoc | 21 +-
src/site/asciidoc/wss4j20.adoc | 15 +-
ws-security-common/pom.xml | 4 +
.../wss4j/common/ConfigurationConstants.java | 18 +-
.../common/crypto/AlgorithmSuiteValidator.java | 22 +-
.../common/crypto/JasyptPasswordEncryptor.java | 61 ++++-
.../wss4j/common/derivedKey/DerivedKeyUtils.java | 42 ++++
.../org/apache/wss4j/common/util/KeyUtils.java | 41 ++--
.../java/org/apache/wss4j/common/util/Loader.java | 122 ++++++++--
.../org/apache/wss4j/common/util/XMLUtils.java | 15 +-
.../wss4j/common/crypto/PasswordEncryptorTest.java | 37 +++
.../common/derivedKey/DerivedKeyUtilsTest.java | 133 +++++++++++
.../org/apache/wss4j/common/util/KeyUtilsTest.java | 126 +++++++++++
.../org/apache/wss4j/common/util/LoaderTest.java | 139 ++++++++++++
.../org/apache/wss4j/common/util/SOAPUtil.java | 8 +-
.../wss4j/dom/callback/DOMCallbackLookup.java | 8 +
.../wss4j/dom/message/WSSecDerivedKeyBase.java | 2 +-
.../wss4j/dom/processor/EncryptedKeyProcessor.java | 13 +-
.../wss4j/dom/str/DerivedKeyTokenSTRParser.java | 9 +-
.../apache/wss4j/dom/str/SignatureSTRParser.java | 25 ++-
.../org/apache/wss4j/dom/util/EncryptionUtils.java | 40 +++-
.../wss4j/dom/validate/SamlAssertionValidator.java | 2 -
.../dom/common/AbstractSAMLCallbackHandler.java | 4 +-
.../dom/common/SAMLElementCallbackHandler.java | 3 +-
.../dom/components/crypto/CryptoProviderTest.java | 7 +-
.../apache/wss4j/dom/handler/CustomTokenTest.java | 4 +-
.../apache/wss4j/dom/message/AttachmentTest.java | 128 ++++++++++-
.../apache/wss4j/dom/message/EncryptionTest.java | 48 ++++
.../wss4j/dom/message/PasswordEncryptorTest.java | 14 ++
.../wss4j/dom/message/SignaturePrefixListTest.java | 4 +-
.../apache/wss4j/dom/message/SignatureTest.java | 4 +-
.../dom/message/token/DerivedKeyTokenTest.java | 6 +-
.../wss4j/dom/message/token/ReferenceTest.java | 4 +-
.../saml/SamlSenderVouchesSecretKeyBypassTest.java | 136 ++++++++++++
.../org/apache/wss4j/dom/saml/SamlTokenTest.java | 7 +-
.../wss4j/dom/saml/SignedSamlTokenHOKTest.java | 4 +-
.../wss4j/dom/saml/ext/AssertionSigningTest.java | 4 +-
.../org/apache/wss4j/policy/stax/PolicyUtils.java | 111 ++++++++-
.../ContentEncryptedElementsAssertionState.java | 14 +-
.../EncryptedElementsAssertionState.java | 14 +-
.../RequiredElementsAssertionState.java | 22 +-
.../SignatureProtectionAssertionState.java | 35 ++-
.../SignedElementsAssertionState.java | 14 +-
.../wss4j/policy/stax/enforcer/PolicyEnforcer.java | 178 ++++++++++++++-
.../stax/enforcer/PolicyEnforcerFactory.java | 28 ++-
.../policy/stax/enforcer/PolicyInputProcessor.java | 16 +-
.../policy/stax/test/AbstractPolicyTestBase.java | 7 +-
.../wss4j/policy/stax/test/AlgorithmSuiteTest.java | 14 +-
.../test/AsymmetricBindingIntegrationTest.java | 66 ++----
.../policy/stax/test/AsymmetricBindingTest.java | 14 +-
.../stax/test/ContentEncryptedElementsTest.java | 4 +-
.../wss4j/policy/stax/test/DerivedKeyTests.java | 20 +-
.../policy/stax/test/EncryptedElementsTest.java | 4 +-
.../wss4j/policy/stax/test/EncryptedPartsTest.java | 12 +-
.../wss4j/policy/stax/test/HttpsTokenTest.java | 6 +-
.../wss4j/policy/stax/test/IssuedTokenTest.java | 16 +-
.../wss4j/policy/stax/test/KerberosTokenTest.java | 6 +-
.../wss4j/policy/stax/test/KeyValueTokenTest.java | 6 +-
.../apache/wss4j/policy/stax/test/LayoutTest.java | 10 +-
.../policy/stax/test/ProtectionOrderTest.java | 14 +-
.../wss4j/policy/stax/test/RelTokenTest.java | 4 +-
.../policy/stax/test/RequiredElementsTest.java | 4 +-
.../wss4j/policy/stax/test/RequiredPartsTest.java | 4 +-
.../stax/test/STRTransformSignedPartsTest.java | 183 +++++++++++++++
.../wss4j/policy/stax/test/SamlTokenTest.java | 6 +-
.../stax/test/SecureConversationTokenTest.java | 6 +-
.../policy/stax/test/SecurityContextTokenTest.java | 6 +-
.../wss4j/policy/stax/test/SignedElementsTest.java | 53 ++++-
.../wss4j/policy/stax/test/SignedPartsTest.java | 12 +-
.../policy/stax/test/SpnegoContextTokenTest.java | 4 +-
.../policy/stax/test/SupportingTokensTest.java | 86 ++++---
.../policy/stax/test/SymmetricBindingTest.java | 10 +-
.../policy/stax/test/TokenProtectionTest.java | 20 +-
.../stax/test/TransportBindingIntegrationTest.java | 26 +--
.../policy/stax/test/TransportBindingTest.java | 8 +-
.../policy/stax/test/UnknownAssertionsTest.java | 247 +++++++++++++++++++++
.../wss4j/policy/stax/test/UsernameTokenTest.java | 4 +-
.../policy/stax/test/VulnerabliltyVectorsTest.java | 21 ++
.../wss4j/policy/stax/test/X509TokenTest.java | 4 +-
.../apache/wss4j/stax/ext/DocumentCreatorImpl.java | 8 +-
.../processor/input/DecryptInputProcessor.java | 16 +-
.../input/DerivedKeyTokenInputHandler.java | 22 +-
.../input/SecurityHeaderInputProcessor.java | 25 +--
.../input/WSSEncryptedKeyInputHandler.java | 14 ++
.../WSSSignatureReferenceVerifyInputProcessor.java | 24 +-
.../output/DerivedKeyTokenOutputProcessor.java | 6 +-
.../org/apache/wss4j/stax/setup/InboundWSSec.java | 20 +-
.../java/org/apache/wss4j/stax/setup/WSSec.java | 4 +-
.../apache/wss4j/stax/test/AbstractTestBase.java | 14 +-
.../org/apache/wss4j/stax/test/AttachmentTest.java | 154 ++++++++++++-
.../apache/wss4j/stax/test/EncDecryptionTest.java | 3 +-
.../java/org/apache/wss4j/stax/test/FaultTest.java | 4 +-
.../test/InboundWSSecurityContextImplTest.java | 6 +-
.../wss4j/stax/test/PasswordEncryptorTest.java | 14 ++
.../wss4j/stax/test/SignatureEncryptionTest.java | 3 +
.../stax/test/saml/SAMLCallbackHandlerImpl.java | 4 +-
108 files changed, 2525 insertions(+), 513 deletions(-)
create mode 100644
ws-security-common/src/test/java/org/apache/wss4j/common/derivedKey/DerivedKeyUtilsTest.java
create mode 100644
ws-security-common/src/test/java/org/apache/wss4j/common/util/KeyUtilsTest.java
create mode 100644
ws-security-common/src/test/java/org/apache/wss4j/common/util/LoaderTest.java
create mode 100644
ws-security-dom/src/test/java/org/apache/wss4j/dom/saml/SamlSenderVouchesSecretKeyBypassTest.java
create mode 100644
ws-security-policy-stax/src/test/java/org/apache/wss4j/policy/stax/test/STRTransformSignedPartsTest.java
create mode 100644
ws-security-policy-stax/src/test/java/org/apache/wss4j/policy/stax/test/UnknownAssertionsTest.java