This is an automated email from the ASF dual-hosted git repository.

coheigea pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/ws-wss4j.git


The following commit(s) were added to refs/heads/master by this push:
     new 1e2ec393e WSS-727 - Minor cleanup (#730)
1e2ec393e is described below

commit 1e2ec393edee12d1fb18f8cc7c9b324e5575aad8
Author: Colm O hEigeartaigh <[email protected]>
AuthorDate: Tue Sep 22 13:33:55 2026 +0100

    WSS-727 - Minor cleanup (#730)
---
 .../wss4j/dom/processor/SignatureProcessor.java     | 21 +++++++++++++++------
 1 file changed, 15 insertions(+), 6 deletions(-)

diff --git 
a/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
 
b/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
index 83ed92287..2ca7d78da 100644
--- 
a/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
+++ 
b/ws-security-dom/src/main/java/org/apache/wss4j/dom/processor/SignatureProcessor.java
@@ -94,6 +94,8 @@ public class SignatureProcessor implements Processor {
     private static final org.slf4j.Logger LOG =
         org.slf4j.LoggerFactory.getLogger(SignatureProcessor.class);
 
+    private static final String CACHE_REFERENCE_PROPERTY = 
"javax.xml.crypto.dsig.cacheReference";
+
     private XMLSignatureFactory signatureFactory;
 
     public SignatureProcessor() {
@@ -374,7 +376,7 @@ public class SignatureProcessor implements Processor {
         }
 
         XMLValidateContext context = new DOMValidateContext(key, elem);
-        context.setProperty("javax.xml.crypto.dsig.cacheReference", 
Boolean.TRUE);
+        context.setProperty(CACHE_REFERENCE_PROPERTY, Boolean.TRUE);
         context.setProperty("org.apache.jcp.xml.dsig.secureValidation", 
Boolean.TRUE);
         context.setProperty("org.jcp.xml.dsig.secureValidation", Boolean.TRUE);
         context.setProperty(STRTransform.TRANSFORM_WS_DOC_INFO, wsDocInfo);
@@ -430,8 +432,7 @@ public class SignatureProcessor implements Processor {
                     // References that validateSignature did not reach are 
validated here for the
                     // first time - all of them when the SignatureValue itself 
failed - so keep
                     // attachment caching off for those too
-                    context.setProperty("javax.xml.crypto.dsig.cacheReference",
-                                        !isAttachmentReference(reference));
+                    setReferenceCaching(context, reference);
                     boolean referenceValidationCheck = 
reference.validate(context);
                     String id = reference.getId();
                     if (id == null) {
@@ -469,18 +470,26 @@ public class SignatureProcessor implements Processor {
         try {
             for (Object referenceObject : 
xmlSignature.getSignedInfo().getReferences()) {
                 Reference reference = (Reference)referenceObject;
-                context.setProperty("javax.xml.crypto.dsig.cacheReference",
-                                    !isAttachmentReference(reference));
+                setReferenceCaching(context, reference);
                 if (!reference.validate(context)) {
                     return false;
                 }
             }
             return true;
         } finally {
-            context.setProperty("javax.xml.crypto.dsig.cacheReference", 
Boolean.TRUE);
+            context.setProperty(CACHE_REFERENCE_PROPERTY, Boolean.TRUE);
         }
     }
 
+    /**
+     * Enables Reference caching for every Reference but a SwA attachment one 
- see
+     * validateSignature. The property is read per Reference when it is 
transformed, so it has to
+     * be set before each Reference.validate call rather than once on the 
context.
+     */
+    private static void setReferenceCaching(XMLValidateContext context, 
Reference reference) {
+        context.setProperty(CACHE_REFERENCE_PROPERTY, 
!isAttachmentReference(reference));
+    }
+
     private static boolean isAttachmentReference(Reference reference) {
         for (Object transformObject : reference.getTransforms()) {
             String algorithm = ((Transform)transformObject).getAlgorithm();

Reply via email to