This is an automated email from the ASF dual-hosted git repository.
coheigea pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/ws-wss4j.git
The following commit(s) were added to refs/heads/master by this push:
new 1e2ec393e WSS-727 - Minor cleanup (#730)
1e2ec393e is described below
commit 1e2ec393edee12d1fb18f8cc7c9b324e5575aad8
Author: Colm O hEigeartaigh <[email protected]>
AuthorDate: Tue Sep 22 13:33:55 2026 +0100
WSS-727 - Minor cleanup (#730)
---
.../wss4j/dom/processor/SignatureProcessor.java | 21 +++++++++++++++------
1 file changed, 15 insertions(+), 6 deletions(-)
diff --git
a/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
b/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
index 83ed92287..2ca7d78da 100644
---
a/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
+++
b/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
@@ -94,6 +94,8 @@ public class SignatureProcessor implements Processor {
private static final org.slf4j.Logger LOG =
org.slf4j.LoggerFactory.getLogger(SignatureProcessor.class);
+ private static final String CACHE_REFERENCE_PROPERTY =
"javax.xml.crypto.dsig.cacheReference";
+
private XMLSignatureFactory signatureFactory;
public SignatureProcessor() {
@@ -374,7 +376,7 @@ public class SignatureProcessor implements Processor {
}
XMLValidateContext context = new DOMValidateContext(key, elem);
- context.setProperty("javax.xml.crypto.dsig.cacheReference",
Boolean.TRUE);
+ context.setProperty(CACHE_REFERENCE_PROPERTY, Boolean.TRUE);
context.setProperty("org.apache.jcp.xml.dsig.secureValidation",
Boolean.TRUE);
context.setProperty("org.jcp.xml.dsig.secureValidation", Boolean.TRUE);
context.setProperty(STRTransform.TRANSFORM_WS_DOC_INFO, wsDocInfo);
@@ -430,8 +432,7 @@ public class SignatureProcessor implements Processor {
// References that validateSignature did not reach are
validated here for the
// first time - all of them when the SignatureValue itself
failed - so keep
// attachment caching off for those too
- context.setProperty("javax.xml.crypto.dsig.cacheReference",
- !isAttachmentReference(reference));
+ setReferenceCaching(context, reference);
boolean referenceValidationCheck =
reference.validate(context);
String id = reference.getId();
if (id == null) {
@@ -469,18 +470,26 @@ public class SignatureProcessor implements Processor {
try {
for (Object referenceObject :
xmlSignature.getSignedInfo().getReferences()) {
Reference reference = (Reference)referenceObject;
- context.setProperty("javax.xml.crypto.dsig.cacheReference",
- !isAttachmentReference(reference));
+ setReferenceCaching(context, reference);
if (!reference.validate(context)) {
return false;
}
}
return true;
} finally {
- context.setProperty("javax.xml.crypto.dsig.cacheReference",
Boolean.TRUE);
+ context.setProperty(CACHE_REFERENCE_PROPERTY, Boolean.TRUE);
}
}
+ /**
+ * Enables Reference caching for every Reference but a SwA attachment one
- see
+ * validateSignature. The property is read per Reference when it is
transformed, so it has to
+ * be set before each Reference.validate call rather than once on the
context.
+ */
+ private static void setReferenceCaching(XMLValidateContext context,
Reference reference) {
+ context.setProperty(CACHE_REFERENCE_PROPERTY,
!isAttachmentReference(reference));
+ }
+
private static boolean isAttachmentReference(Reference reference) {
for (Object transformObject : reference.getTransforms()) {
String algorithm = ((Transform)transformObject).getAlgorithm();