Password set to null in UsernameTokenValidator
----------------------------------------------

                 Key: CXF-3484
                 URL: https://issues.apache.org/jira/browse/CXF-3484
             Project: CXF
          Issue Type: Bug
          Components: WS-* Components
    Affects Versions: 2.4
         Environment: Linux, jetty 6.10
            Reporter: Nicolas Poirot
            Priority: Minor



When trying to do basic authentication in Soap header with UserNameToken, token 
is well read from XML, but badly passed to password callback.
Line 165 of org.apache.ws.security.validate.UsernameTokenValidator :

WSPasswordCallback pwCb = 
            new WSPasswordCallback(user, null, pwType, 
WSPasswordCallback.USERNAME_TOKEN, data);

The password is set to null, while it has been correcty read just before.


--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira

Reply via email to