diff --git a/build.gradle b/build.gradle index e59c59de..01c38020 100644 --- a/build.gradle +++ b/build.gradle @@ -3,19 +3,23 @@ buildscript { maven { url 'http://repo.springsource.org/plugins-release' } } dependencies { - classpath 'org.springframework.build.gradle:propdeps-plugin:0.0.7' + classpath 'io.spring.gradle:propdeps-plugin:0.0.9.RELEASE' classpath 'io.spring.gradle:docbook-reference-plugin:0.3.1' - classpath 'io.spring.gradle:spring-io-plugin:0.0.4.RELEASE' + classpath 'io.spring.gradle:spring-io-plugin:0.0.8.RELEASE' } } configure(allprojects) { group = "org.springframework.ws" - ext.springVersion = "4.2.9.RELEASE" - ext.springSecurityVersion = "4.0.4.RELEASE" + ext.springVersion = "5.0.0.RELEASE" + ext.springSecurityVersion = "5.0.0.M4" ext.axiomVersion = "1.2.20" - ext.smackVersion = "4.1.9" + ext.smackVersion = "4.2.1" + ext.sunMailVersion = "1.6.0" + ext.xmlSchemaCoreVersion = "2.2.2" + ext.commonsHttpclientVersion = "3.1" + ext.aspectjVersion = "1.8.11" apply plugin: "java" @@ -35,8 +39,8 @@ configure(allprojects) { "-Xlint:-unchecked", "-Xlint:-options"] compileJava { - sourceCompatibility=1.7 - targetCompatibility=1.7 + sourceCompatibility=1.8 + targetCompatibility=1.8 } sourceSets.test.resources.srcDirs = ['src/test/resources', 'src/test/java'] @@ -49,22 +53,19 @@ configure(allprojects) { exclude '**/*Abstract*.*' } - repositories { - maven { url 'https://repo.spring.io/libs-release' } - } - dependencies { - compile("commons-logging:commons-logging:1.1.3") + compile("commons-logging:commons-logging:1.2") compile("org.springframework:spring-core:$springVersion") testCompile("junit:junit:4.12") testCompile("org.easymock:easymock:3.1") testCompile("xmlunit:xmlunit:1.5") - testCompile("com.sun.mail:javax.mail:1.5.4") + testCompile("com.sun.mail:javax.mail:$sunMailVersion") testRuntime("org.codehaus.woodstox:woodstox-core-asl:4.2.0") } ext.javadocLinks = [ + "http://docs.oracle.com/javase/8/docs/api/", "http://docs.oracle.com/javase/7/docs/api/", "http://docs.oracle.com/javaee/6/api/", "http://docs.spring.io/spring/docs/current/javadoc-api/", @@ -84,10 +85,14 @@ configure(subprojects) { subproject -> apply plugin: "propdeps-maven" apply from: "${rootProject.projectDir}/publish-maven.gradle" + repositories { + maven { url "https://repo.spring.io/libs-snapshot" } + maven { url "https://repo.spring.io/libs-release" } + } + /** * To run an alternate profile... - * ./gradlew -Pprofile=spring4-next clean build - * ./gradlew -Pprofile=spring5 clean build + * ./gradlew -Pprofile=springnext clean build */ if (project.hasProperty('profile')) { apply from: "${project.rootDir}/${profile}-profile.gradle" @@ -168,7 +173,7 @@ project('spring-xml') { compile("org.springframework:spring-context:$springVersion") //XML - optional("org.apache.ws.xmlschema:xmlschema-core:2.1.0") + optional("org.apache.ws.xmlschema:xmlschema-core:$xmlSchemaCoreVersion") optional("jaxen:jaxen:1.1.4") } } @@ -187,14 +192,14 @@ project('spring-ws-core') { testCompile("org.springframework:spring-test:$springVersion") // XML - optional("org.jdom:jdom2:2.0.5") + optional("org.jdom:jdom2:2.0.6") optional("dom4j:dom4j:1.6.1") optional("xom:xom:1.2.5") { exclude group: 'xml-apis', module: 'xml-apis' exclude group: 'xerces', module: 'xercesImpl' exclude group: 'xalan', module: 'xalan' } - optional("org.apache.ws.xmlschema:xmlschema-core:2.1.0") + optional("org.apache.ws.xmlschema:xmlschema-core:$xmlSchemaCoreVersion") // SOAP optional("org.apache.ws.commons.axiom:axiom-api:$axiomVersion") @@ -203,17 +208,19 @@ project('spring-ws-core') { } // WSDL - optional("wsdl4j:wsdl4j:1.6.1") + optional("wsdl4j:wsdl4j:1.6.3") // Transport - provided("javax.servlet:javax.servlet-api:3.0.1") - optional("org.apache.httpcomponents:httpclient:4.3.4") - optional("commons-httpclient:commons-httpclient:3.1") - testCompile("org.mortbay.jetty:jetty:6.1.26") + provided("javax.servlet:javax.servlet-api:3.1.0") + optional("org.apache.httpcomponents:httpclient:4.5.3") + optional("commons-httpclient:commons-httpclient:$commonsHttpclientVersion") + testCompile("org.mortbay.jetty:jetty:6.1.26") { + exclude group: 'org.mortbay.jetty', module: 'servlet-api' + } - testCompile("log4j:log4j:1.2.16") - testCompile("org.aspectj:aspectjrt:1.6.9") - testRuntime("org.aspectj:aspectjweaver:1.6.9") + testCompile("log4j:log4j:1.2.17") + testCompile("org.aspectj:aspectjrt:$aspectjVersion") + testRuntime("org.aspectj:aspectjweaver:$aspectjVersion") } } @@ -229,17 +236,17 @@ project('spring-ws-support') { testCompile("org.springframework:spring-test:$springVersion") // Transport - provided("javax.jms:jms-api:1.1-rev-1") - provided("javax.mail:javax.mail-api:1.4.7") - provided("com.sun.mail:javax.mail:1.4.7") + provided("javax.jms:javax.jms-api:2.0.1") + provided("javax.mail:javax.mail-api:1.6.0") + provided("com.sun.mail:javax.mail:$sunMailVersion") optional("org.igniterealtime.smack:smack-tcp:$smackVersion") optional("org.igniterealtime.smack:smack-java7:$smackVersion") optional("org.igniterealtime.smack:smack-extensions:$smackVersion") - testCompile("commons-httpclient:commons-httpclient:3.1") - testRuntime("org.apache.activemq:activemq-core:4.1.2") { + testCompile("commons-httpclient:commons-httpclient:$commonsHttpclientVersion") + testRuntime("org.apache.activemq:activemq-core:5.7.0") { exclude group:'org.apache.geronimo.specs', module:'geronimo-jms_1.1_spec' } - testCompile("org.jvnet.mock-javamail:mock-javamail:1.6") { + testCompile("org.jvnet.mock-javamail:mock-javamail:1.9") { exclude group:'javax.mail', module:'mail' } } @@ -258,18 +265,17 @@ project('spring-ws-security') { // Spring Security compile("org.springframework.security:spring-security-core:$springSecurityVersion") - optional("net.sf.ehcache:ehcache:2.8.4") + optional("net.sf.ehcache:ehcache:2.10.4") // WS-Security optional("com.sun.xml.wss:xws-security:3.0") { exclude group: 'javax.xml.crypto', module: 'xmldsig' } - compile("org.apache.ws.security:wss4j:1.6.19") - compile("org.apache.wss4j:wss4j-ws-security-dom:2.1.4") + compile("org.apache.wss4j:wss4j-ws-security-dom:2.2.0") // SOAP - provided("com.sun.xml.messaging.saaj:saaj-impl:1.3.19") // required for XWSS + provided("com.sun.xml.messaging.saaj:saaj-impl:1.3.28") // required for XWSS optional("org.apache.ws.commons.axiom:axiom-api:$axiomVersion") optional("org.apache.ws.commons.axiom:axiom-impl:$axiomVersion") { exclude group: 'org.codehaus.woodstox', module: 'wstx-asl' @@ -461,9 +467,4 @@ configure(rootProject) { archives schemaZip archives distZip } - - task wrapper(type: Wrapper) { - description = 'Generates gradlew[.bat] scripts' - gradleVersion = '2.8' - } } diff --git a/circle.yml b/circle.yml index 61e4b874..ddb9c9ab 100644 --- a/circle.yml +++ b/circle.yml @@ -1,3 +1,12 @@ +version: 2 +jobs: + build: + docker: + - image: circleci/openjdk:8u141 + steps: + - checkout + - run: ./gradlew clean build + - run: ./gradlew -Pprofile=springnext clean build general: branches: ignore: @@ -6,15 +15,3 @@ general: dependencies: cache_directories: - "~/.m2" - -machine: - java: - version: oraclejdk8 - environment: - _JAVA_OPTIONS: "-Xms1024m -Xmx2048m" - -test: - override: - - ./gradlew clean build - - ./gradlew -Pprofile=spring4-next clean build - - ./gradlew -Pprofile=spring5 clean build diff --git a/gradle.properties b/gradle.properties index 063615bb..7645a9fa 100644 --- a/gradle.properties +++ b/gradle.properties @@ -1 +1 @@ -version=2.4.1.BUILD-SNAPSHOT +version=3.0.0.BUILD-SNAPSHOT diff --git a/gradle/wrapper/gradle-wrapper.jar b/gradle/wrapper/gradle-wrapper.jar index 05ef575b..f14b21e7 100644 Binary files a/gradle/wrapper/gradle-wrapper.jar and b/gradle/wrapper/gradle-wrapper.jar differ diff --git a/gradle/wrapper/gradle-wrapper.properties b/gradle/wrapper/gradle-wrapper.properties index ea06ca28..d75e5df7 100644 --- a/gradle/wrapper/gradle-wrapper.properties +++ b/gradle/wrapper/gradle-wrapper.properties @@ -1,6 +1,6 @@ -#Wed Jan 20 16:03:00 CST 2016 +#Wed Oct 04 12:56:30 CDT 2017 distributionBase=GRADLE_USER_HOME distributionPath=wrapper/dists zipStoreBase=GRADLE_USER_HOME zipStorePath=wrapper/dists -distributionUrl=https\://services.gradle.org/distributions/gradle-2.8-bin.zip +distributionUrl=https\://services.gradle.org/distributions/gradle-4.0.2-bin.zip diff --git a/gradlew b/gradlew index 9d82f789..cccdd3d5 100755 --- a/gradlew +++ b/gradlew @@ -1,4 +1,4 @@ -#!/usr/bin/env bash +#!/usr/bin/env sh ############################################################################## ## @@ -6,42 +6,6 @@ ## ############################################################################## -# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. -DEFAULT_JVM_OPTS="" - -APP_NAME="Gradle" -APP_BASE_NAME=`basename "$0"` - -# Use the maximum available, or set MAX_FD != -1 to use that value. -MAX_FD="maximum" - -warn ( ) { - echo "$*" -} - -die ( ) { - echo - echo "$*" - echo - exit 1 -} - -# OS specific support (must be 'true' or 'false'). -cygwin=false -msys=false -darwin=false -case "`uname`" in - CYGWIN* ) - cygwin=true - ;; - Darwin* ) - darwin=true - ;; - MINGW* ) - msys=true - ;; -esac - # Attempt to set APP_HOME # Resolve links: $0 may be a link PRG="$0" @@ -60,6 +24,46 @@ cd "`dirname \"$PRG\"`/" >/dev/null APP_HOME="`pwd -P`" cd "$SAVED" >/dev/null +APP_NAME="Gradle" +APP_BASE_NAME=`basename "$0"` + +# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +DEFAULT_JVM_OPTS="" + +# Use the maximum available, or set MAX_FD != -1 to use that value. +MAX_FD="maximum" + +warn () { + echo "$*" +} + +die () { + echo + echo "$*" + echo + exit 1 +} + +# OS specific support (must be 'true' or 'false'). +cygwin=false +msys=false +darwin=false +nonstop=false +case "`uname`" in + CYGWIN* ) + cygwin=true + ;; + Darwin* ) + darwin=true + ;; + MINGW* ) + msys=true + ;; + NONSTOP* ) + nonstop=true + ;; +esac + CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar # Determine the Java command to use to start the JVM. @@ -85,7 +89,7 @@ location of your Java installation." fi # Increase the maximum file descriptors if we can. -if [ "$cygwin" = "false" -a "$darwin" = "false" ] ; then +if [ "$cygwin" = "false" -a "$darwin" = "false" -a "$nonstop" = "false" ] ; then MAX_FD_LIMIT=`ulimit -H -n` if [ $? -eq 0 ] ; then if [ "$MAX_FD" = "maximum" -o "$MAX_FD" = "max" ] ; then @@ -150,11 +154,19 @@ if $cygwin ; then esac fi -# Split up the JVM_OPTS And GRADLE_OPTS values into an array, following the shell quoting and substitution rules -function splitJvmOpts() { - JVM_OPTS=("$@") +# Escape application args +save () { + for i do printf %s\\n "$i" | sed "s/'/'\\\\''/g;1s/^/'/;\$s/\$/' \\\\/" ; done + echo " " } -eval splitJvmOpts $DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS -JVM_OPTS[${#JVM_OPTS[*]}]="-Dorg.gradle.appname=$APP_BASE_NAME" +APP_ARGS=$(save "$@") -exec "$JAVACMD" "${JVM_OPTS[@]}" -classpath "$CLASSPATH" org.gradle.wrapper.GradleWrapperMain "$@" +# Collect all arguments for the java command, following the shell quoting and substitution rules +eval set -- $DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS "\"-Dorg.gradle.appname=$APP_BASE_NAME\"" -classpath "\"$CLASSPATH\"" org.gradle.wrapper.GradleWrapperMain "$APP_ARGS" + +# by default we should be in the correct project dir, but when run from Finder on Mac, the cwd is wrong +if [ "$(uname)" = "Darwin" ] && [ "$HOME" = "$PWD" ]; then + cd "$(dirname "$0")" +fi + +exec "$JAVACMD" "$@" diff --git a/gradlew.bat b/gradlew.bat index aec99730..e95643d6 100644 --- a/gradlew.bat +++ b/gradlew.bat @@ -8,14 +8,14 @@ @rem Set local scope for the variables with windows NT shell if "%OS%"=="Windows_NT" setlocal -@rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. -set DEFAULT_JVM_OPTS= - set DIRNAME=%~dp0 if "%DIRNAME%" == "" set DIRNAME=. set APP_BASE_NAME=%~n0 set APP_HOME=%DIRNAME% +@rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +set DEFAULT_JVM_OPTS= + @rem Find java.exe if defined JAVA_HOME goto findJavaFromJavaHome @@ -46,10 +46,9 @@ echo location of your Java installation. goto fail :init -@rem Get command-line arguments, handling Windowz variants +@rem Get command-line arguments, handling Windows variants if not "%OS%" == "Windows_NT" goto win9xME_args -if "%@eval[2+2]" == "4" goto 4NT_args :win9xME_args @rem Slurp the command line arguments. @@ -60,11 +59,6 @@ set _SKIP=2 if "x%~1" == "x" goto execute set CMD_LINE_ARGS=%* -goto execute - -:4NT_args -@rem Get arguments from the 4NT Shell from JP Software -set CMD_LINE_ARGS=%$ :execute @rem Setup the command line diff --git a/spring-ws-core/src/test/java/org/springframework/ws/client/core/WebServiceTemplateTest.java b/spring-ws-core/src/test/java/org/springframework/ws/client/core/WebServiceTemplateTest.java index bcbbeef5..b353b2fa 100644 --- a/spring-ws-core/src/test/java/org/springframework/ws/client/core/WebServiceTemplateTest.java +++ b/spring-ws-core/src/test/java/org/springframework/ws/client/core/WebServiceTemplateTest.java @@ -34,7 +34,6 @@ import org.springframework.ws.client.support.destination.DestinationProvider; import org.springframework.ws.client.support.interceptor.ClientInterceptor; import org.springframework.ws.context.DefaultMessageContext; import org.springframework.ws.context.MessageContext; -import org.springframework.ws.support.TestUtilities; import org.springframework.ws.transport.FaultAwareWebServiceConnection; import org.springframework.ws.transport.WebServiceConnection; import org.springframework.ws.transport.WebServiceMessageSender; @@ -486,13 +485,10 @@ public class WebServiceTemplateTest { reset(connectionMock); - if (!TestUtilities.SPRING5) { - expect(connectionMock.getUri()).andReturn(providerUri); - } - connectionMock.send(isA(WebServiceMessage.class)); expect(connectionMock.hasError()).andReturn(false); expect(connectionMock.receive(messageFactory)).andReturn(null); + expect(connectionMock.getUri()).andReturn(new URI("http://example.com")); connectionMock.close(); replay(connectionMock, extractorMock, providerMock); diff --git a/spring-ws-core/src/test/java/org/springframework/ws/soap/soap11/AbstractSoap11MessageTestCase.java b/spring-ws-core/src/test/java/org/springframework/ws/soap/soap11/AbstractSoap11MessageTestCase.java index 4375fcfe..0da1d2e7 100644 --- a/spring-ws-core/src/test/java/org/springframework/ws/soap/soap11/AbstractSoap11MessageTestCase.java +++ b/spring-ws-core/src/test/java/org/springframework/ws/soap/soap11/AbstractSoap11MessageTestCase.java @@ -23,7 +23,7 @@ import javax.xml.parsers.DocumentBuilderFactory; import javax.xml.transform.dom.DOMResult; import javax.xml.transform.stream.StreamSource; -import junit.framework.Assert; +import org.junit.Assert; import org.w3c.dom.Document; import org.w3c.dom.Element; diff --git a/spring-ws-core/src/test/java/org/springframework/ws/soap/soap12/AbstractSoap12MessageTestCase.java b/spring-ws-core/src/test/java/org/springframework/ws/soap/soap12/AbstractSoap12MessageTestCase.java index ed8e9115..91ce754a 100644 --- a/spring-ws-core/src/test/java/org/springframework/ws/soap/soap12/AbstractSoap12MessageTestCase.java +++ b/spring-ws-core/src/test/java/org/springframework/ws/soap/soap12/AbstractSoap12MessageTestCase.java @@ -23,7 +23,7 @@ import javax.xml.parsers.DocumentBuilderFactory; import javax.xml.transform.dom.DOMResult; import javax.xml.transform.stream.StreamSource; -import junit.framework.Assert; +import org.junit.Assert; import org.w3c.dom.Document; import org.w3c.dom.Element; diff --git a/spring-ws-core/src/test/java/org/springframework/ws/support/TestUtilities.java b/spring-ws-core/src/test/java/org/springframework/ws/support/TestUtilities.java deleted file mode 100644 index 42f9a04d..00000000 --- a/spring-ws-core/src/test/java/org/springframework/ws/support/TestUtilities.java +++ /dev/null @@ -1,37 +0,0 @@ -/* - * Copyright 2017 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ -package org.springframework.ws.support; - -import org.springframework.util.ClassUtils; - -/** - * @author Greg Turnquist - */ -public final class TestUtilities { - - public static boolean SPRING5; - - static { - ClassLoader classLoader = TestUtilities.class.getClassLoader(); - try { - ClassUtils.forName("org.springframework.http.server.reactive.ReactorHttpHandlerAdapter", classLoader); - SPRING5 = true; - } catch (ClassNotFoundException e) { - SPRING5 = false; - } - - } -} diff --git a/spring-ws-core/src/test/java/org/springframework/ws/transport/support/WebServiceMessageReceiverObjectSupportTest.java b/spring-ws-core/src/test/java/org/springframework/ws/transport/support/WebServiceMessageReceiverObjectSupportTest.java index 3a0a0dfa..d5904b52 100644 --- a/spring-ws-core/src/test/java/org/springframework/ws/transport/support/WebServiceMessageReceiverObjectSupportTest.java +++ b/spring-ws-core/src/test/java/org/springframework/ws/transport/support/WebServiceMessageReceiverObjectSupportTest.java @@ -28,7 +28,6 @@ import org.springframework.ws.MockWebServiceMessageFactory; import org.springframework.ws.WebServiceMessage; import org.springframework.ws.context.MessageContext; import org.springframework.ws.soap.SoapVersion; -import org.springframework.ws.support.TestUtilities; import org.springframework.ws.transport.FaultAwareWebServiceConnection; import org.springframework.ws.transport.WebServiceMessageReceiver; @@ -55,9 +54,7 @@ public class WebServiceMessageReceiverObjectSupportTest { @Test public void handleConnectionResponse() throws Exception { - if (!TestUtilities.SPRING5) { - expect(connectionMock.getUri()).andReturn(new URI("http://example.com")); - } + expect(connectionMock.getUri()).andReturn(new URI("http://example.com")); expect(connectionMock.receive(messageFactory)).andReturn(request); connectionMock.setFaultCode(null); connectionMock.send(isA(WebServiceMessage.class)); @@ -83,9 +80,7 @@ public class WebServiceMessageReceiverObjectSupportTest { public void handleConnectionFaultResponse() throws Exception { final QName faultCode = SoapVersion.SOAP_11.getClientOrSenderFaultName(); - if (!TestUtilities.SPRING5) { - expect(connectionMock.getUri()).andReturn(new URI("http://example.com")); - } + expect(connectionMock.getUri()).andReturn(new URI("http://example.com")); expect(connectionMock.receive(messageFactory)).andReturn(request); connectionMock.setFaultCode(faultCode); connectionMock.send(isA(WebServiceMessage.class)); @@ -111,9 +106,7 @@ public class WebServiceMessageReceiverObjectSupportTest { @Test public void handleConnectionNoResponse() throws Exception { - if (!TestUtilities.SPRING5) { - expect(connectionMock.getUri()).andReturn(new URI("http://example.com")); - } + expect(connectionMock.getUri()).andReturn(new URI("http://example.com")); expect(connectionMock.receive(messageFactory)).andReturn(request); connectionMock.close(); diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jHandler.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jHandler.java deleted file mode 100644 index a8ca645a..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jHandler.java +++ /dev/null @@ -1,124 +0,0 @@ -/* - * Copyright 2005-2012 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.util.List; -import java.util.Properties; - -import org.apache.ws.security.WSSecurityEngineResult; -import org.apache.ws.security.WSSecurityException; -import org.apache.ws.security.components.crypto.Crypto; -import org.apache.ws.security.handler.RequestData; -import org.apache.ws.security.handler.WSHandler; -import org.apache.ws.security.handler.WSHandlerConstants; -import org.w3c.dom.Document; - -import org.springframework.ws.context.MessageContext; - -/** - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.Wss4jHandler}. - */ -@Deprecated -class Wss4jHandler extends WSHandler { - - /** Keys are constants from {@link WSHandlerConstants}; values are strings. */ - private Properties options = new Properties(); - - private String securementPassword; - - private Crypto securementEncryptionCrypto; - - private Crypto securementSignatureCrypto; - - Wss4jHandler() { - // set up default handler properties - options.setProperty(WSHandlerConstants.MUST_UNDERSTAND, Boolean.toString(true)); - options.setProperty(WSHandlerConstants.ENABLE_SIGNATURE_CONFIRMATION, Boolean.toString(true)); - } - - @Override - protected boolean checkReceiverResultsAnyOrder(List wsResult, List actions) { - return super.checkReceiverResultsAnyOrder(wsResult, actions); - } - - void setOption(String key, String value) { - options.setProperty(key, value); - } - - void setOption(String key, boolean value) { - options.setProperty(key, Boolean.toString(value)); - } - - @Override - public Object getOption(String key) { - return options.getProperty(key); - } - - void setSecurementPassword(String securementPassword) { - this.securementPassword = securementPassword; - } - - void setSecurementEncryptionCrypto(Crypto securementEncryptionCrypto) { - this.securementEncryptionCrypto = securementEncryptionCrypto; - } - - void setSecurementSignatureCrypto(Crypto securementSignatureCrypto) { - this.securementSignatureCrypto = securementSignatureCrypto; - } - - @Override - public String getPassword(Object msgContext) { - return securementPassword; - } - - @Override - public Object getProperty(Object msgContext, String key) { - return ((MessageContext) msgContext).getProperty(key); - } - - @Override - protected Crypto loadEncryptionCrypto(RequestData reqData) throws WSSecurityException { - return securementEncryptionCrypto; - } - - @Override - public Crypto loadSignatureCrypto(RequestData reqData) throws WSSecurityException { - return securementSignatureCrypto; - } - - @Override - public void setPassword(Object msgContext, String password) { - securementPassword = password; - } - - @Override - public void setProperty(Object msgContext, String key, Object value) { - ((MessageContext) msgContext).setProperty(key, value); - } - - @Override - protected void doSenderAction(int doAction, - Document doc, - RequestData reqData, - List actions, - boolean isRequest) throws WSSecurityException { - super.doSenderAction(doAction, doc, reqData, actions, isRequest); - } -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityFaultException.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityFaultException.java deleted file mode 100644 index ab4c6c4b..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityFaultException.java +++ /dev/null @@ -1,38 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import javax.xml.namespace.QName; - -import org.springframework.ws.soap.security.WsSecurityFaultException; - -/** - * WSS4J-specific version of the {@link WsSecurityFaultException}. - * - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.Wss4jSecurityFaultException} - */ -@SuppressWarnings("serial") -@Deprecated -public class Wss4jSecurityFaultException extends WsSecurityFaultException { - - public Wss4jSecurityFaultException(QName faultCode, String faultString, String faultActor) { - super(faultCode, faultString, faultActor); - } -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityInterceptor.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityInterceptor.java deleted file mode 100644 index 9102444c..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityInterceptor.java +++ /dev/null @@ -1,770 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.io.IOException; -import java.security.Principal; -import java.security.cert.X509Certificate; -import java.util.ArrayList; -import java.util.List; -import javax.security.auth.callback.Callback; -import javax.security.auth.callback.CallbackHandler; -import javax.security.auth.callback.UnsupportedCallbackException; - -import org.apache.ws.security.WSConstants; -import org.apache.ws.security.WSSConfig; -import org.apache.ws.security.WSSecurityEngine; -import org.apache.ws.security.WSSecurityEngineResult; -import org.apache.ws.security.WSSecurityException; -import org.apache.ws.security.WSUsernameTokenPrincipal; -import org.apache.ws.security.components.crypto.Crypto; -import org.apache.ws.security.handler.RequestData; -import org.apache.ws.security.handler.WSHandlerConstants; -import org.apache.ws.security.handler.WSHandlerResult; -import org.apache.ws.security.message.token.Timestamp; -import org.apache.ws.security.saml.SAMLIssuer; -import org.apache.ws.security.util.WSSecurityUtil; -import org.apache.ws.security.validate.Credential; -import org.apache.ws.security.validate.SignatureTrustValidator; -import org.apache.ws.security.validate.TimestampValidator; -import org.w3c.dom.Document; - -import org.springframework.beans.factory.InitializingBean; -import org.springframework.util.Assert; -import org.springframework.util.CollectionUtils; -import org.springframework.util.StringUtils; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.AbstractWsSecurityInterceptor; -import org.springframework.ws.soap.security.WsSecuritySecurementException; -import org.springframework.ws.soap.security.WsSecurityValidationException; -import org.springframework.ws.soap.security.callback.CallbackHandlerChain; -import org.springframework.ws.soap.security.callback.CleanupCallback; -import org.springframework.ws.soap.security.wss4j.callback.UsernameTokenPrincipalCallback; - -/** - * A WS-Security endpoint interceptor based on Apache's WSS4J. This interceptor supports messages created by the {@link - * org.springframework.ws.soap.axiom.AxiomSoapMessageFactory} and the {@link org.springframework.ws.soap.saaj.SaajSoapMessageFactory}. - * - *

The validation and securement actions executed by this interceptor are configured via {@code validationActions} - * and {@code securementActions} properties, respectively. Actions should be passed as a space-separated strings. - * - *

Valid validation actions are: - * - *

- * - * - * - * - * - * - * - *
Validation actionDescription
{@code UsernameToken}Validates username token
{@code Timestamp}Validates the timestamp
{@code Encrypt}Decrypts the message
{@code Signature}Validates the signature
{@code NoSecurity}No action performed
- *

- * Securement actions are: - * - *

- * - * - * - * - * - * - * - * - *
Securement actionDescription
{@code UsernameToken}Adds a username token
{@code UsernameTokenSignature}Adds a username token and a signature username token secret key
{@code Timestamp}Adds a timestamp
{@code Encrypt}Encrypts the response
{@code Signature}Signs the response
{@code NoSecurity}No action performed
- * - *

The order of the actions that the client performed to secure the messages is significant and is enforced by the - * interceptor. - * - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @author Greg Turnquist - * @see Apache WSS4J - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.Wss4jSecurityInterceptor} - */ -@Deprecated -public class Wss4jSecurityInterceptor extends AbstractWsSecurityInterceptor implements InitializingBean { - - public static final String SECUREMENT_USER_PROPERTY_NAME = "Wss4jSecurityInterceptor.securementUser"; - - private static final String SAML_ISSUER_PROPERTY_NAME = "Wss4jSecurityInterceptor.samlIssuer"; - - private int securementAction; - - private String securementActions; - - private List securementActionsVector; - - private String securementUsername; - - private CallbackHandler validationCallbackHandler; - - private int validationAction; - - private String validationActions; - - private List validationActionsVector; - - private String validationActor; - - private Crypto validationDecryptionCrypto; - - private Crypto validationSignatureCrypto; - - private boolean timestampStrict = true; - - private boolean enableSignatureConfirmation; - - private int validationTimeToLive = 300; - - private int securementTimeToLive = 300; - - private int futureTimeToLive = 60; - - private SAMLIssuer samlIssuer; - - private WSSConfig wssConfig; - - private final Wss4jHandler handler = new Wss4jHandler(); - - private final WSSecurityEngine securityEngine = new WSSecurityEngine(); - - private boolean enableRevocation; - - private boolean bspCompliant; - - private boolean securementUseDerivedKey; - - // To maintain same behavior as default, this flag is set to true - private boolean removeSecurityHeader = true; - - public void setSecurementActions(String securementActions) { - this.securementActions = securementActions; - securementActionsVector = new ArrayList(); - try { - securementAction = WSSecurityUtil.decodeAction(securementActions, securementActionsVector); - } - catch (WSSecurityException ex) { - throw new IllegalArgumentException(ex); - } - } - - /** - * The actor name of the {@code wsse:Security} header. - * - *

If this parameter is omitted, the actor name is not set. - * - *

The value of the actor or role has to match the receiver's setting or may contain standard values. - */ - public void setSecurementActor(String securementActor) { - handler.setOption(WSHandlerConstants.ACTOR, securementActor); - } - - public void setSecurementEncryptionCrypto(Crypto securementEncryptionCrypto) { - handler.setSecurementEncryptionCrypto(securementEncryptionCrypto); - } - - /** Sets the key name that needs to be sent for encryption. */ - public void setSecurementEncryptionEmbeddedKeyName(String securementEncryptionEmbeddedKeyName) { - handler.setOption(WSHandlerConstants.ENC_KEY_NAME, securementEncryptionEmbeddedKeyName); - } - - /** - * Defines which key identifier type to use. The WS-Security specifications recommends to use the identifier type - * {@code IssuerSerial}. For possible encryption key identifier types refer to {@link - * org.apache.ws.security.handler.WSHandlerConstants#keyIdentifier}. For encryption {@code IssuerSerial}, - * {@code X509KeyIdentifier}, {@code DirectReference}, {@code Thumbprint}, - * {@code SKIKeyIdentifier}, and {@code EmbeddedKeyName} are valid only. - */ - public void setSecurementEncryptionKeyIdentifier(String securementEncryptionKeyIdentifier) { - handler.setOption(WSHandlerConstants.ENC_KEY_ID, securementEncryptionKeyIdentifier); - } - - /** - * Defines which algorithm to use to encrypt the generated symmetric key. Currently WSS4J supports {@link - * WSConstants#KEYTRANSPORT_RSA15} and {@link WSConstants#KEYTRANSPORT_RSAOEP}. - */ - public void setSecurementEncryptionKeyTransportAlgorithm(String securementEncryptionKeyTransportAlgorithm) { - handler.setOption(WSHandlerConstants.ENC_KEY_TRANSPORT, securementEncryptionKeyTransportAlgorithm); - } - - /** - * Property to define which parts of the request shall be encrypted. - * - *

The value of this property is a list of semicolon separated element names that identify the elements to encrypt. - * An encryption mode specifier and a namespace identification, each inside a pair of curly brackets, may precede - * each element name. - * - *

The encryption mode specifier is either {@code {Content}} or {@code {Element}}. Please refer to the W3C - * XML Encryption specification about the differences between Element and Content encryption. The encryption mode - * defaults to {@code Content} if it is omitted. Example of a list: - *

-	 * <property name="securementEncryptionParts"
-	 *	 value="{Content}{http://example.org/paymentv2}CreditCard;
-	 *			   {Element}{}UserName" />
-	 * 
- * The first entry of the list identifies the element {@code CreditCard} in the namespace - * {@code http://example.org/paymentv2}, and will encrypt its content. Be aware that the element name, the - * namespace identifier, and the encryption modifier are case sensitive. - * - *

The encryption modifier and the namespace identifier can be omitted. In this case the encryption mode defaults to - * {@code Content} and the namespace is set to the SOAP namespace. - * - *

An empty encryption mode defaults to {@code Content}, an empty namespace identifier defaults to the SOAP - * namespace. The second line of the example defines {@code Element} as encryption mode for an - * {@code UserName} element in the SOAP namespace. - * - *

To specify an element without a namespace use the string {@code Null} as the namespace name (this is a case - * sensitive string) - * - *

If no list is specified, the handler encrypts the SOAP Body in {@code Content} mode by default. - */ - public void setSecurementEncryptionParts(String securementEncryptionParts) { - handler.setOption(WSHandlerConstants.ENCRYPTION_PARTS, securementEncryptionParts); - } - - /** - * Defines which symmetric encryption algorithm to use. WSS4J supports the following alorithms: {@link - * WSConstants#TRIPLE_DES}, {@link WSConstants#AES_128}, {@link WSConstants#AES_256}, and {@link - * WSConstants#AES_192}. Except for AES 192 all of these algorithms are required by the XML Encryption - * specification. - */ - public void setSecurementEncryptionSymAlgorithm(String securementEncryptionSymAlgorithm) { - this.handler.setOption(WSHandlerConstants.ENC_SYM_ALGO, securementEncryptionSymAlgorithm); - } - - /** - * The user's name for encryption. - * - *

The encryption functions uses the public key of this user's certificate to encrypt the generated symmetric key. - * - *

If this parameter is not set, then the encryption function falls back to the {@link - * org.apache.ws.security.handler.WSHandlerConstants#USER} parameter to get the certificate. - * - *

If only encryption of the SOAP body data is requested, it is recommended to use this parameter to define - * the username. The application can then use the standard user and password functions (see example at {@link - * org.apache.ws.security.handler.WSHandlerConstants#USER} to enable HTTP authentication functions. - * - *

Encryption only does not authenticate a user / sender, therefore it does not need a password. - * - *

Placing the username of the encryption certificate in the configuration file is not a security risk, because the - * public key of that certificate is used only. - */ - public void setSecurementEncryptionUser(String securementEncryptionUser) { - handler.setOption(WSHandlerConstants.ENCRYPTION_USER, securementEncryptionUser); - } - - public void setSecurementPassword(String securementPassword) { - this.handler.setSecurementPassword(securementPassword); - } - - /** - * Specific parameter for UsernameToken action to define the encoding of the passowrd. - * - *

The parameter can be set to either {@link WSConstants#PW_DIGEST} or to {@link WSConstants#PW_TEXT}. - * - *

The default setting is PW_DIGEST. - */ - public void setSecurementPasswordType(String securementUsernameTokenPasswordType) { - handler.setOption(WSHandlerConstants.PASSWORD_TYPE, securementUsernameTokenPasswordType); - } - - /** - * Defines which signature algorithm to use. - * @see WSConstants#RSA - * @see WSConstants#DSA - */ - public void setSecurementSignatureAlgorithm(String securementSignatureAlgorithm) { - handler.setOption(WSHandlerConstants.SIG_ALGO, securementSignatureAlgorithm); - } - - /** - * Defines which signature digest algorithm to use. - */ - public void setSecurementSignatureDigestAlgorithm(String digestAlgorithm) { - handler.setOption(WSHandlerConstants.SIG_DIGEST_ALGO, digestAlgorithm); - } - - public void setSecurementSignatureCrypto(Crypto securementSignatureCrypto) { - handler.setSecurementSignatureCrypto(securementSignatureCrypto); - } - - /** - * Defines which key identifier type to use. The WS-Security specifications recommends to use the identifier type - * {@code IssuerSerial}. For possible signature key identifier types refer to {@link - * org.apache.ws.security.handler.WSHandlerConstants#keyIdentifier}. For signature {@code IssuerSerial} and - * {@code DirectReference} are valid only. - */ - public void setSecurementSignatureKeyIdentifier(String securementSignatureKeyIdentifier) { - handler.setOption(WSHandlerConstants.SIG_KEY_ID, securementSignatureKeyIdentifier); - } - - /** - * Property to define which parts of the request shall be signed. - * - *

Refer to {@link #setSecurementEncryptionParts(String)} for a detailed description of the format of the value - * string. - * - *

If this property is not specified the handler signs the SOAP Body by default. - * - *

The WS Security specifications define several formats to transfer the signature tokens (certificates) or - * references to these tokens. Thus, the plain element name {@code Token} signs the token and takes care of the - * different formats. - * - *

To sign the SOAP body and the signature token the value of this parameter must contain: - *

-	 * <property name="securementSignatureParts"
-	 *	 value="{}{http://schemas.xmlsoap.org/soap/envelope/}Body; Token" />
-	 * 
- * To specify an element without a namespace use the string {@code Null} as the namespace name (this is a case - * sensitive string) - * - *

If there is no other element in the request with a local name of {@code Body} then the SOAP namespace - * identifier can be empty ({@code {}}). - */ - public void setSecurementSignatureParts(String securementSignatureParts) { - handler.setOption(WSHandlerConstants.SIGNATURE_PARTS, securementSignatureParts); - } - - /** - * The user's name for signature. - * - *

This name is used as the alias name in the keystore to get user's - * certificate and private key to perform signing. - * - *

If this parameter is not set, then the signature - * function falls back to the alias specified by {@link #setSecurementUsername(String)}. - * - */ - public void setSecurementSignatureUser(String securementSignatureUser) { - handler.setOption(WSHandlerConstants.SIGNATURE_USER, securementSignatureUser); - } - - /** Sets the username for securement username token or/and the alias of the private key for securement signature */ - public void setSecurementUsername(String securementUsername) { - this.securementUsername = securementUsername; - } - - /** Sets the time to live on the outgoing message */ - public void setSecurementTimeToLive(int securementTimeToLive) { - if (securementTimeToLive <= 0) { - throw new IllegalArgumentException("timeToLive must be positive"); - } - this.securementTimeToLive = securementTimeToLive; - } - - /** - * Enables the derivation of keys as per the UsernameTokenProfile 1.1 spec. Default is {@code true}. - */ - public void setSecurementUseDerivedKey(boolean securementUseDerivedKey) { - this.securementUseDerivedKey = securementUseDerivedKey; - } - - /** Sets the server-side time to live */ - public void setValidationTimeToLive(int validationTimeToLive) { - if (validationTimeToLive <= 0) { - throw new IllegalArgumentException("timeToLive must be positive"); - } - this.validationTimeToLive = validationTimeToLive; - } - - /** Sets the validation actions to be executed by the interceptor. */ - public void setValidationActions(String actions) { - this.validationActions = actions; - try { - validationActionsVector = new ArrayList(); - validationAction = WSSecurityUtil.decodeAction(actions, validationActionsVector); - } - catch (WSSecurityException ex) { - throw new IllegalArgumentException(ex); - } - } - - public void setValidationActor(String validationActor) { - this.validationActor = validationActor; - } - - /** - * Sets the {@link org.apache.ws.security.WSPasswordCallback} handler to use when validating messages. - * - * @see #setValidationCallbackHandlers(CallbackHandler[]) - */ - public void setValidationCallbackHandler(CallbackHandler callbackHandler) { - this.validationCallbackHandler = callbackHandler; - } - - /** - * Sets the {@link org.apache.ws.security.WSPasswordCallback} handlers to use when validating messages. - * - * @see #setValidationCallbackHandler(CallbackHandler) - */ - public void setValidationCallbackHandlers(CallbackHandler[] callbackHandler) { - this.validationCallbackHandler = new CallbackHandlerChain(callbackHandler); - } - - /** Sets the Crypto to use to decrypt incoming messages */ - public void setValidationDecryptionCrypto(Crypto decryptionCrypto) { - this.validationDecryptionCrypto = decryptionCrypto; - } - - /** Sets the Crypto to use to verify the signature of incoming messages */ - public void setValidationSignatureCrypto(Crypto signatureCrypto) { - this.validationSignatureCrypto = signatureCrypto; - } - - /** Whether to enable signatureConfirmation or not. By default signatureConfirmation is enabled */ - public void setEnableSignatureConfirmation(boolean enableSignatureConfirmation) { - handler.setOption(WSHandlerConstants.ENABLE_SIGNATURE_CONFIRMATION, enableSignatureConfirmation); - this.enableSignatureConfirmation = enableSignatureConfirmation; - } - - /** Sets if the generated timestamp header's precision is in milliseconds. */ - public void setTimestampPrecisionInMilliseconds(boolean timestampPrecisionInMilliseconds) { - handler.setOption(WSHandlerConstants.TIMESTAMP_PRECISION, timestampPrecisionInMilliseconds); - } - - /** Sets whether or not timestamp verification is done with the server-side time to live */ - public void setTimestampStrict(boolean timestampStrict) { - this.timestampStrict = timestampStrict; - } - - /** - * Enables the {@code mustUnderstand} attribute on WS-Security headers on outgoing messages. Default is - * {@code true}. - */ - public void setSecurementMustUnderstand(boolean securementMustUnderstand) { - handler.setOption(WSHandlerConstants.MUST_UNDERSTAND, securementMustUnderstand); - } - - /** - * Sets the additional elements in {@code UsernameToken}s. - * - *

The value of this parameter is a list of element names that are added to the UsernameToken. The names of the list - * a separated by spaces. - * - *

The list may contain the names {@code Nonce} and {@code Created} only (case sensitive). Use this option - * if the password type is {@code passwordText} and the handler shall add the {@code Nonce} and/or - * {@code Created} elements. - */ - public void setSecurementUsernameTokenElements(String securementUsernameTokenElements) { - handler.setOption(WSHandlerConstants.ADD_UT_ELEMENTS, securementUsernameTokenElements); - } - - /** - * Sets the web service specification settings. - *

- * The default settings follow the latest OASIS and changing anything might violate the OASIS specs. - * - * @param config web service security configuration or {@code null} to use default settings - */ - public void setWssConfig(WSSConfig config) { - securityEngine.setWssConfig(config); - wssConfig = config; - } - - /** - * Set whether to enable CRL checking or not when verifying trust in a certificate. - */ - public void setEnableRevocation(boolean enableRevocation) { - this.enableRevocation = enableRevocation; - } - - /** - * Set the WS-I Basic Security Profile compliance mode. Default is {@code true}. - */ - public void setBspCompliant(boolean bspCompliant) { - this.handler.setOption(WSHandlerConstants.IS_BSP_COMPLIANT, bspCompliant); - this.bspCompliant = bspCompliant; - } - - /** - * Sets the location of the SAML properties file. The file should be available on the classpath. - */ - public void setSamlProperties(String location) { - handler.setOption(WSHandlerConstants.SAML_PROP_FILE, location); - } - - /** - * Sets the time in seconds in the future within which the Created time of an - * incoming Timestamp is valid. The default is 60 seconds. - */ - public void setFutureTimeToLive(int futureTimeToLive) { - if (futureTimeToLive <= 0) { - throw new IllegalArgumentException("futureTimeToLive must be positive"); - } - this.futureTimeToLive = futureTimeToLive; - } - - /** - * Sets the SAML issuer. - */ - public void setSamlIssuer(SAMLIssuer samlIssuer) { - handler.setOption(WSHandlerConstants.SAML_PROP_REF_ID, SAML_ISSUER_PROPERTY_NAME); - this.samlIssuer = samlIssuer; - } - - public boolean getRemoveSecurityHeader() { - return removeSecurityHeader; - } - - public void setRemoveSecurityHeader(boolean removeSecurityHeader) { - this.removeSecurityHeader = removeSecurityHeader; - } - - @Override - public void afterPropertiesSet() throws Exception { - Assert.isTrue(validationActions != null || securementActions != null, - "validationActions or securementActions are required"); - if (validationActions != null) { - if ((validationAction & WSConstants.UT) != 0) { - Assert.notNull(validationCallbackHandler, "validationCallbackHandler is required"); - } - - if ((validationAction & WSConstants.SIGN) != 0) { - Assert.notNull(validationSignatureCrypto, "validationSignatureCrypto is required"); - } - } - // securement actions are not to be validated at start up as they could - // be configured dynamically via the message context - - // allow for qualified password types for .Net interoperability - securityEngine.getWssConfig().setAllowNamespaceQualifiedPasswordTypes(true); - securityEngine.getWssConfig().setWsiBSPCompliant(bspCompliant); - } - - @Override - protected void secureMessage(SoapMessage soapMessage, MessageContext messageContext) - throws WsSecuritySecurementException { - if (securementAction == WSConstants.NO_SECURITY && !enableSignatureConfirmation) { - return; - } - if (logger.isDebugEnabled()) { - logger.debug("Securing message [" + soapMessage + "] with actions [" + securementActions + "]"); - } - RequestData requestData = initializeRequestData(messageContext); - - Document envelopeAsDocument = soapMessage.getDocument(); - try { - // In case on signature confirmation with no other securement - // action, we need to pass an empty securementActionsVector to avoid - // NPE - if (securementAction == WSConstants.NO_SECURITY) { - securementActionsVector = new ArrayList(0); - } - - handler.doSenderAction(securementAction, envelopeAsDocument, requestData, securementActionsVector, false); - } - catch (WSSecurityException ex) { - throw new Wss4jSecuritySecurementException(ex.getMessage(), ex); - } - - soapMessage.setDocument(envelopeAsDocument); - } - - /** - * Creates and initializes a request data for the given message context. - * - * @param messageContext the message context - * @return the request data - */ - protected RequestData initializeRequestData(MessageContext messageContext) { - RequestData requestData = new RequestData(); - requestData.setMsgContext(messageContext); - - // reads securementUsername first from the context then from the property - String contextUsername = (String) messageContext.getProperty(SECUREMENT_USER_PROPERTY_NAME); - if (StringUtils.hasLength(contextUsername)) { - requestData.setUsername(contextUsername); - } - else { - requestData.setUsername(securementUsername); - } - - requestData.setTimeToLive(securementTimeToLive); - - requestData.setUseDerivedKey(securementUseDerivedKey); - - requestData.setWssConfig(wssConfig); - - messageContext.setProperty(WSHandlerConstants.TTL_TIMESTAMP, Integer.toString(securementTimeToLive)); - - messageContext.setProperty(SAML_ISSUER_PROPERTY_NAME, samlIssuer); - - return requestData; - } - - @Override - protected void validateMessage(SoapMessage soapMessage, MessageContext messageContext) - throws WsSecurityValidationException { - if (logger.isDebugEnabled()) { - logger.debug("Validating message [" + soapMessage + "] with actions [" + validationActions + "]"); - } - - if (validationAction == WSConstants.NO_SECURITY) { - return; - } - - Document envelopeAsDocument = soapMessage.getDocument(); - - // Header processing - - try { - List results = securityEngine - .processSecurityHeader(envelopeAsDocument, validationActor, validationCallbackHandler, - validationSignatureCrypto, validationDecryptionCrypto); - - // Results verification - if (CollectionUtils.isEmpty(results)) { - throw new Wss4jSecurityValidationException("No WS-Security header found"); - } - - checkResults(results, validationActionsVector); - - // puts the results in the context - // useful for Signature Confirmation - updateContextWithResults(messageContext, results); - - verifyCertificateTrust(results); - - verifyTimestamp(results); - - processPrincipal(results); - } - catch (WSSecurityException ex) { - throw new Wss4jSecurityValidationException(ex.getMessage(), ex); - } - - soapMessage.setDocument(envelopeAsDocument); - - if (this.getRemoveSecurityHeader()) { - soapMessage.getEnvelope().getHeader().removeHeaderElement(WS_SECURITY_NAME); - } - } - - /** - * Checks whether the received headers match the configured validation actions. Subclasses could override this method - * for custom verification behavior. - * - * - * @param results the results of the validation function - * @param validationActions the decoded validation actions - * @throws Wss4jSecurityValidationException if the results are deemed invalid - */ - protected void checkResults(List results, List validationActions) - throws Wss4jSecurityValidationException { - if (!handler.checkReceiverResultsAnyOrder(results, validationActions)) { - throw new Wss4jSecurityValidationException("Security processing failed (actions mismatch)"); - } - } - - /** - * Puts the results of WS-Security headers processing in the message context. Some actions like Signature - * Confirmation require this. - */ - @SuppressWarnings("unchecked") - private void updateContextWithResults(MessageContext messageContext, List results) { - List handlerResults; - if ((handlerResults = (List) messageContext.getProperty(WSHandlerConstants.RECV_RESULTS)) == null) { - handlerResults = new ArrayList(); - messageContext.setProperty(WSHandlerConstants.RECV_RESULTS, handlerResults); - } - WSHandlerResult rResult = new WSHandlerResult(validationActor, results); - handlerResults.add(0, rResult); - messageContext.setProperty(WSHandlerConstants.RECV_RESULTS, handlerResults); - } - - /** Verifies the trust of a certificate. */ - protected void verifyCertificateTrust(List results) throws WSSecurityException { - WSSecurityEngineResult actionResult = WSSecurityUtil.fetchActionResult(results, WSConstants.SIGN); - - if (actionResult != null) { - X509Certificate returnCert = - (X509Certificate) actionResult.get(WSSecurityEngineResult.TAG_X509_CERTIFICATE); - Credential credential = new Credential(); - credential.setCertificates(new X509Certificate[] { returnCert}); - - RequestData requestData = new RequestData(); - requestData.setSigCrypto(validationSignatureCrypto); - requestData.setEnableRevocation(enableRevocation); - - SignatureTrustValidator validator = new SignatureTrustValidator(); - validator.validate(credential, requestData); - } - } - - /** Verifies the timestamp. */ - protected void verifyTimestamp(List results) throws WSSecurityException { - WSSecurityEngineResult actionResult = WSSecurityUtil.fetchActionResult(results, WSConstants.TS); - - if (actionResult != null) { - Timestamp timestamp = (Timestamp) actionResult.get(WSSecurityEngineResult.TAG_TIMESTAMP); - if (timestamp != null && timestampStrict) { - Credential credential = new Credential(); - credential.setTimestamp(timestamp); - - RequestData requestData = new RequestData(); - WSSConfig config = new WSSConfig(); - config.setTimeStampTTL(validationTimeToLive); - config.setTimeStampStrict(timestampStrict); - config.setTimeStampFutureTTL(futureTimeToLive); - requestData.setWssConfig(config); - - TimestampValidator validator = new TimestampValidator(); - validator.validate(credential, requestData); - } - } - } - - private void processPrincipal(List results) { - WSSecurityEngineResult actionResult = WSSecurityUtil.fetchActionResult(results, WSConstants.UT); - - if (actionResult != null) { - Principal principal = (Principal) actionResult.get(WSSecurityEngineResult.TAG_PRINCIPAL); - if (principal != null && principal instanceof WSUsernameTokenPrincipal) { - WSUsernameTokenPrincipal usernameTokenPrincipal = (WSUsernameTokenPrincipal) principal; - UsernameTokenPrincipalCallback callback = new UsernameTokenPrincipalCallback(usernameTokenPrincipal); - try { - validationCallbackHandler.handle(new Callback[]{callback}); - } - catch (IOException ex) { - logger.warn("Principal callback resulted in IOException", ex); - } - catch (UnsupportedCallbackException ex) { - // ignore - } - } - } - } - - @Override - protected void cleanUp() { - if (validationCallbackHandler != null) { - try { - CleanupCallback cleanupCallback = new CleanupCallback(); - validationCallbackHandler.handle(new Callback[]{cleanupCallback}); - } - catch (IOException ex) { - logger.warn("Cleanup callback resulted in IOException", ex); - } - catch (UnsupportedCallbackException ex) { - // ignore - } - } - } -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecuritySecurementException.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecuritySecurementException.java deleted file mode 100644 index 291c9cf0..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecuritySecurementException.java +++ /dev/null @@ -1,41 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import org.springframework.ws.soap.security.WsSecuritySecurementException; - -/** - * WSS4J-specific version of the {@link WsSecuritySecurementException}. - * - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.Wss4jSecuritySecurementException} - */ -@SuppressWarnings("serial") -@Deprecated -public class Wss4jSecuritySecurementException extends WsSecuritySecurementException { - - public Wss4jSecuritySecurementException(String msg) { - super(msg); - } - - public Wss4jSecuritySecurementException(String msg, Throwable ex) { - super(msg, ex); - } - -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityValidationException.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityValidationException.java deleted file mode 100644 index ae10f2d0..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/Wss4jSecurityValidationException.java +++ /dev/null @@ -1,41 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import org.springframework.ws.soap.security.WsSecurityValidationException; - -/** - * WSS4J-specific version of the {@link WsSecurityValidationException}. - * - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.Wss4jSecurityValidationException} - */ -@SuppressWarnings("serial") -@Deprecated -public class Wss4jSecurityValidationException extends WsSecurityValidationException { - - public Wss4jSecurityValidationException(String msg) { - super(msg); - } - - public Wss4jSecurityValidationException(String msg, Throwable ex) { - super(msg, ex); - } - -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/AbstractWsPasswordCallbackHandler.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/AbstractWsPasswordCallbackHandler.java deleted file mode 100644 index f3de66bd..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/AbstractWsPasswordCallbackHandler.java +++ /dev/null @@ -1,172 +0,0 @@ -/* - * Copyright 2005-2012 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.callback; - -import java.io.IOException; -import javax.security.auth.callback.Callback; -import javax.security.auth.callback.UnsupportedCallbackException; - -import org.apache.ws.security.WSPasswordCallback; - -import org.springframework.ws.soap.security.callback.AbstractCallbackHandler; -import org.springframework.ws.soap.security.callback.CleanupCallback; - -/** - * Abstract base class for {@link javax.security.auth.callback.CallbackHandler} implementations that handle {@link - * WSPasswordCallback} callbacks. - * - * @author Arjen Poutsma - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.callback.AbstractWsPasswordCallbackHandler} - */ -@Deprecated -public abstract class AbstractWsPasswordCallbackHandler extends AbstractCallbackHandler { - - /** - * Handles {@link WSPasswordCallback} callbacks. Inspects the callback {@link WSPasswordCallback#getUsage() usage} - * code, and calls the various {@code handle*} template methods. - * - * @param callback the callback - * @throws IOException in case of I/O errors - * @throws UnsupportedCallbackException when the callback is not supported - */ - @Override - protected final void handleInternal(Callback callback) throws IOException, UnsupportedCallbackException { - if (callback instanceof WSPasswordCallback) { - WSPasswordCallback passwordCallback = (WSPasswordCallback) callback; - switch (passwordCallback.getUsage()) { - case WSPasswordCallback.DECRYPT: - handleDecrypt(passwordCallback); - break; - case WSPasswordCallback.USERNAME_TOKEN: - handleUsernameToken(passwordCallback); - break; - case WSPasswordCallback.SIGNATURE: - handleSignature(passwordCallback); - break; - case WSPasswordCallback.SECURITY_CONTEXT_TOKEN: - handleSecurityContextToken(passwordCallback); - break; - case WSPasswordCallback.CUSTOM_TOKEN: - handleCustomToken(passwordCallback); - break; - case WSPasswordCallback.SECRET_KEY: - handleSecretKey(passwordCallback); - break; - default: - throw new UnsupportedCallbackException(callback, - "Unknown usage [" + passwordCallback.getUsage() + "]"); - } - } - else if (callback instanceof CleanupCallback) { - handleCleanup((CleanupCallback) callback); - } - else if (callback instanceof UsernameTokenPrincipalCallback) { - handleUsernameTokenPrincipal((UsernameTokenPrincipalCallback) callback); - } - else { - throw new UnsupportedCallbackException(callback); - } - } - - /** - * Invoked when the callback has a {@link WSPasswordCallback#DECRYPT} usage. - * - *

This method is invoked when WSS4J needs a password to get the private key of the {@link - * WSPasswordCallback#getIdentifier() identifier} (username) from the keystore. WSS4J uses this private key to - * decrypt the session (symmetric) key. Because the encryption method uses the public key to encrypt the session key - * it needs no password (a public key is usually not protected by a password). - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleDecrypt(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } - - /** - * Invoked when the callback has a {@link WSPasswordCallback#USERNAME_TOKEN} usage. - * - *

This method is invoked when WSS4J needs the password to fill in or to verify a UsernameToken. - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleUsernameToken(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } - - /** - * Invoked when the callback has a {@link WSPasswordCallback#SIGNATURE} usage. - * - *

This method is invoked when WSS4J needs the password to get the private key of the {@link - * WSPasswordCallback#getIdentifier() identifier} (username) from the keystore. WSS4J uses this private key to - * produce a signature. The signature verfication uses the public key to verfiy the signature. - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleSignature(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } - - /** - * Invoked when the callback has a {@link WSPasswordCallback#SECURITY_CONTEXT_TOKEN} usage. - * - *

This method is invoked when WSS4J needs the key to to be associated with a SecurityContextToken. - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleSecurityContextToken(WSPasswordCallback callback) - throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } - - /** - * Invoked when the callback has a {@link WSPasswordCallback#CUSTOM_TOKEN} usage. - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleCustomToken(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } - - /** - * Invoked when the callback has a {@link WSPasswordCallback#SECRET_KEY} usage. - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleSecretKey(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } - - /** - * Invoked when a {@link CleanupCallback} is passed to {@link #handle(Callback[])}. - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleCleanup(CleanupCallback callback) throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } - - /** - * Invoked when a {@link UsernameTokenPrincipalCallback} is passed to {@link #handle(Callback[])}. - * - *

Default implementation throws an {@link UnsupportedCallbackException}. - */ - protected void handleUsernameTokenPrincipal(UsernameTokenPrincipalCallback callback) - throws IOException, UnsupportedCallbackException { - throw new UnsupportedCallbackException(callback); - } -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/KeyStoreCallbackHandler.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/KeyStoreCallbackHandler.java deleted file mode 100644 index 9ba9771a..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/KeyStoreCallbackHandler.java +++ /dev/null @@ -1,123 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.callback; - -import java.io.IOException; -import java.security.GeneralSecurityException; -import java.security.Key; -import java.security.KeyStore; -import javax.crypto.SecretKey; -import javax.security.auth.callback.UnsupportedCallbackException; - -import org.apache.ws.security.WSPasswordCallback; - -import org.springframework.beans.factory.InitializingBean; -import org.springframework.ws.soap.security.support.KeyStoreUtils; - -/** - * Callback handler that uses Java Security {@code KeyStore}s to handle cryptographic callbacks. Allows for - * specific key stores to be set for various cryptographic operations. - * - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @see org.springframework.ws.soap.security.support.KeyStoreFactoryBean - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.callback.KeyStoreCallbackHandler} - */ -@Deprecated -public class KeyStoreCallbackHandler extends AbstractWsPasswordCallbackHandler implements InitializingBean { - - private String privateKeyPassword; - - private char[] symmetricKeyPassword; - - private KeyStore keyStore; - - /** Sets the key store to use if a symmetric key name is embedded. */ - public void setKeyStore(KeyStore keyStore) { - this.keyStore = keyStore; - } - - /** - * Sets the password used to retrieve private keys from the keystore. This property is required for decryption based - * on private keys, and signing. - */ - public void setPrivateKeyPassword(String privateKeyPassword) { - if (privateKeyPassword != null) { - this.privateKeyPassword = privateKeyPassword; - } - } - - /** - * Sets the password used to retrieve keys from the symmetric keystore. If this property is not set, it defaults to - * the private key password. - * - * @see #setPrivateKeyPassword(String) - */ - public void setSymmetricKeyPassword(String symmetricKeyPassword) { - if (symmetricKeyPassword != null) { - this.symmetricKeyPassword = symmetricKeyPassword.toCharArray(); - } - } - - @Override - public void afterPropertiesSet() throws Exception { - if (keyStore == null) { - loadDefaultKeyStore(); - } - if (symmetricKeyPassword == null) { - symmetricKeyPassword = privateKeyPassword.toCharArray(); - } - } - - @Override - protected void handleDecrypt(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - callback.setPassword(privateKeyPassword); - } - - - @Override - protected void handleSecretKey(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - try { - String identifier = callback.getIdentifier(); - Key key = keyStore.getKey(identifier, symmetricKeyPassword); - if (key instanceof SecretKey) { - callback.setKey(key.getEncoded()); - } - else { - logger.error("Key [" + key + "] is not a javax.crypto.SecretKey"); - } - } - catch (GeneralSecurityException ex) { - logger.error("Could not obtain symmetric key", ex); - } - } - - /** Loads the key store indicated by system properties. Delegates to {@link KeyStoreUtils#loadDefaultKeyStore()}. */ - protected void loadDefaultKeyStore() { - try { - keyStore = KeyStoreUtils.loadDefaultKeyStore(); - if (logger.isDebugEnabled()) { - logger.debug("Loaded default key store"); - } - } - catch (Exception ex) { - logger.warn("Could not open default key store", ex); - } - } - -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/SimplePasswordValidationCallbackHandler.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/SimplePasswordValidationCallbackHandler.java deleted file mode 100644 index 6a6e3b5e..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/SimplePasswordValidationCallbackHandler.java +++ /dev/null @@ -1,70 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.callback; - -import java.io.IOException; -import java.util.HashMap; -import java.util.Map; -import java.util.Properties; -import javax.security.auth.callback.UnsupportedCallbackException; - -import org.apache.ws.security.WSPasswordCallback; - -import org.springframework.beans.factory.InitializingBean; -import org.springframework.util.Assert; - -/** - * Simple callback handler that validates passwords against a in-memory {@code Properties} object. Password - * validation is done on a case-sensitive basis. - * - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @see #setUsers(java.util.Properties) - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.callback.SimplePasswordValidationCallbackHandler} - */ -@Deprecated -public class SimplePasswordValidationCallbackHandler extends AbstractWsPasswordCallbackHandler - implements InitializingBean { - - private Map users = new HashMap(); - - /** Sets the users to validate against. Property names are usernames, property values are passwords. */ - public void setUsers(Properties users) { - for (Map.Entry entry : users.entrySet()) { - if (entry.getKey() instanceof String && entry.getValue() instanceof String) { - this.users.put((String) entry.getKey(), (String) entry.getValue()); - } - } - } - - public void setUsersMap(Map users) { - this.users = users; - } - - @Override - public void afterPropertiesSet() throws Exception { - Assert.notNull(users, "users is required"); - } - - @Override - protected void handleUsernameToken(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - String identifier = callback.getIdentifier(); - callback.setPassword(users.get(identifier)); - } - -} \ No newline at end of file diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/SpringSecurityPasswordValidationCallbackHandler.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/SpringSecurityPasswordValidationCallbackHandler.java deleted file mode 100644 index 9ad660fb..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/SpringSecurityPasswordValidationCallbackHandler.java +++ /dev/null @@ -1,116 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.callback; - -import java.io.IOException; -import javax.security.auth.callback.UnsupportedCallbackException; - -import org.apache.ws.security.WSPasswordCallback; -import org.apache.ws.security.WSUsernameTokenPrincipal; - -import org.springframework.beans.factory.InitializingBean; -import org.springframework.dao.DataAccessException; -import org.springframework.security.authentication.UsernamePasswordAuthenticationToken; -import org.springframework.security.core.context.SecurityContextHolder; -import org.springframework.security.core.userdetails.UserCache; -import org.springframework.security.core.userdetails.UserDetails; -import org.springframework.security.core.userdetails.UserDetailsService; -import org.springframework.security.core.userdetails.UsernameNotFoundException; -import org.springframework.security.core.userdetails.cache.NullUserCache; -import org.springframework.util.Assert; -import org.springframework.ws.soap.security.callback.CleanupCallback; -import org.springframework.ws.soap.security.support.SpringSecurityUtils; - -/** - * Callback handler that validates a plain text or digest password using an Spring Security {@code UserDetailsService}. - * - *

An Spring Security {@link UserDetailsService} is used to load {@link UserDetails} from. The digest of the - * password contained in this details object is then compared with the digest in the message. - * - * @author Arjen Poutsma - * @since 2.1 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.callback.SpringSecurityPasswordValidationCallbackHandler} - */ -@Deprecated -public class SpringSecurityPasswordValidationCallbackHandler extends AbstractWsPasswordCallbackHandler - implements InitializingBean { - - private UserCache userCache = new NullUserCache(); - - private UserDetailsService userDetailsService; - - /** Sets the users cache. Not required, but can benefit performance. */ - public void setUserCache(UserCache userCache) { - this.userCache = userCache; - } - - /** Sets the Spring Security user details service. Required. */ - public void setUserDetailsService(UserDetailsService userDetailsService) { - this.userDetailsService = userDetailsService; - } - - @Override - public void afterPropertiesSet() throws Exception { - Assert.notNull(userDetailsService, "userDetailsService is required"); - } - - @Override - protected void handleUsernameToken(WSPasswordCallback callback) throws IOException, UnsupportedCallbackException { - String identifier = callback.getIdentifier(); - UserDetails user = loadUserDetails(identifier); - if (user != null) { - SpringSecurityUtils.checkUserValidity(user); - callback.setPassword(user.getPassword()); - } - } - - @Override - protected void handleUsernameTokenPrincipal(UsernameTokenPrincipalCallback callback) - throws IOException, UnsupportedCallbackException { - UserDetails user = loadUserDetails(callback.getPrincipal().getName()); - WSUsernameTokenPrincipal principal = callback.getPrincipal(); - UsernamePasswordAuthenticationToken authRequest = - new UsernamePasswordAuthenticationToken(principal, principal.getPassword(), user.getAuthorities()); - if (logger.isDebugEnabled()) { - logger.debug("Authentication success: " + authRequest.toString()); - } - SecurityContextHolder.getContext().setAuthentication(authRequest); - } - - @Override - protected void handleCleanup(CleanupCallback callback) throws IOException, UnsupportedCallbackException { - SecurityContextHolder.clearContext(); - } - - private UserDetails loadUserDetails(String username) throws DataAccessException { - UserDetails user = userCache.getUserFromCache(username); - - if (user == null) { - try { - user = userDetailsService.loadUserByUsername(username); - } - catch (UsernameNotFoundException notFound) { - if (logger.isDebugEnabled()) { - logger.debug("Username '" + username + "' not found"); - } - return null; - } - userCache.putUserInCache(user); - } - return user; - } -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/UsernameTokenPrincipalCallback.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/UsernameTokenPrincipalCallback.java deleted file mode 100644 index ecc753e4..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/UsernameTokenPrincipalCallback.java +++ /dev/null @@ -1,50 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.callback; - -import java.io.Serializable; -import javax.security.auth.callback.Callback; - -import org.apache.ws.security.WSUsernameTokenPrincipal; - -/** - * Underlying security services instantiate and pass a {@code UsernameTokenPrincipalCallback} to the - * {@code handle} method of a {@code CallbackHandler} to pass a security - * {@code WSUsernameTokenPrincipal}. - * - * @author Arjen Poutsma - * @see WSUsernameTokenPrincipal - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.callback.UsernameTokenPrincipalCallback} - */ -@Deprecated -public class UsernameTokenPrincipalCallback implements Callback, Serializable { - - private static final long serialVersionUID = -3022202225157082715L; - - private final WSUsernameTokenPrincipal principal; - - /** Construct a {@code UsernameTokenPrincipalCallback}. */ - public UsernameTokenPrincipalCallback(WSUsernameTokenPrincipal principal) { - this.principal = principal; - } - - /** Get the retrieved {@code Principal}. */ - public WSUsernameTokenPrincipal getPrincipal() { - return principal; - } -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/package.html b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/package.html deleted file mode 100644 index 1d1c4a69..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/callback/package.html +++ /dev/null @@ -1,5 +0,0 @@ - - -Contains CallbackHandler implementations for WSS4J (deprecated as of Spring WS 2.3). - - \ No newline at end of file diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/package.html b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/package.html deleted file mode 100644 index add5a944..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/package.html +++ /dev/null @@ -1,6 +0,0 @@ - - -Contains classes for using the Apache WSS4J WS-Security implementation within -Spring-WS (deprecated as of Spring WS 2.3). - - \ No newline at end of file diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/support/CryptoFactoryBean.java b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/support/CryptoFactoryBean.java deleted file mode 100644 index c21220f3..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/support/CryptoFactoryBean.java +++ /dev/null @@ -1,196 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.support; - -import java.io.IOException; -import java.util.Properties; - -import org.apache.ws.security.components.crypto.Crypto; -import org.apache.ws.security.components.crypto.CryptoFactory; -import org.apache.ws.security.components.crypto.Merlin; - -import org.springframework.beans.factory.BeanClassLoaderAware; -import org.springframework.beans.factory.FactoryBean; -import org.springframework.beans.factory.InitializingBean; -import org.springframework.core.io.ClassPathResource; -import org.springframework.core.io.Resource; -import org.springframework.util.Assert; - -/** - * Spring factory bean for a WSS4J {@link Crypto}. Allows for strong-typed property configuration, or configuration - * through {@link Properties}. - * - *

Requires either individual properties, or the {@link #setConfiguration(java.util.Properties) configuration} property - * to be set. - * - * @author Tareq Abed Rabbo - * @author Arjen Poutsma - * @see org.apache.ws.security.components.crypto.Crypto - * @since 1.5.0 - * @deprecated Transition to {@link org.springframework.ws.soap.security.wss4j2.support.CryptoFactoryBean} - */ -@Deprecated -public class CryptoFactoryBean implements FactoryBean, BeanClassLoaderAware, InitializingBean { - - private Properties configuration = new Properties(); - - private ClassLoader classLoader; - - private Crypto crypto; - - private static final String CRYPTO_PROVIDER_PROPERTY = "org.apache.ws.security.crypto.provider"; - - /** - * Sets the configuration of the Crypto. Setting this property overrides all previously set configuration, through - * the type-safe properties - * - * @see org.apache.ws.security.components.crypto.CryptoFactory#getInstance(java.util.Properties) - */ - public void setConfiguration(Properties properties) { - Assert.notNull(properties, "'properties' must not be null"); - this.configuration.putAll(properties); - } - - /** - * Sets the {@link org.apache.ws.security.components.crypto.Crypto} provider name. Defaults to {@link - * org.apache.ws.security.components.crypto.Merlin}. - * - *

This property maps to the WSS4J {@code org.apache.ws.security.crypto.provider} property. - * - * @param cryptoProviderClass the crypto provider class - */ - public void setCryptoProvider(Class cryptoProviderClass) { - this.configuration.setProperty(CRYPTO_PROVIDER_PROPERTY, cryptoProviderClass.getName()); - } - - /** - * Sets the location of the key store to be loaded in the {@link org.apache.ws.security.components.crypto.Crypto} - * instance. - * - *

This property maps to the WSS4J {@code org.apache.ws.security.crypto.merlin.file} property. - * - * @param location the key store location - * @throws java.io.IOException when the resource cannot be opened - */ - public void setKeyStoreLocation(Resource location) throws IOException { - String resourcePath = getResourcePath(location); - this.configuration.setProperty("org.apache.ws.security.crypto.merlin.file", resourcePath); - } - - private String getResourcePath(Resource resource) throws IOException { - try { - return resource.getFile().getAbsolutePath(); - } - catch (IOException ex) { - if (resource instanceof ClassPathResource) { - ClassPathResource classPathResource = (ClassPathResource) resource; - return classPathResource.getPath(); - } - else { - throw ex; - } - } - } - - /** - * Sets the key store provider. - * - *

This property maps to the WSS4J {@code org.apache.ws.security.crypto.merlin.keystore.provider} property. - * - * @param provider the key store provider - */ - public void setKeyStoreProvider(String provider) { - this.configuration.setProperty("org.apache.ws.security.crypto.merlin.keystore.provider", provider); - } - - /** - * Sets the key store password. Defaults to {@code security}. - * - *

This property maps to the WSS4J {@code org.apache.ws.security.crypto.merlin.keystore.password} property. - * - * @param password the key store password - */ - public void setKeyStorePassword(String password) { - this.configuration.setProperty("org.apache.ws.security.crypto.merlin.keystore.password", password); - } - - /** - * Sets the key store type. Defaults to {@link java.security.KeyStore#getDefaultType()}. - * - *

This property maps to the WSS4J {@code org.apache.ws.security.crypto.merlin.keystore.type} property. - * - * @param type the key store type - */ - public void setKeyStoreType(String type) { - this.configuration.setProperty("org.apache.ws.security.crypto.merlin.keystore.type", type); - } - - /** - * Sets the trust store password. Defaults to {@code changeit}. - * - *

WSS4J crypto uses the standard J2SE trust store, i.e. {@code $JAVA_HOME/lib/security/cacerts}. - * - *

This property maps to the WSS4J {@code org.apache.ws.security.crypto.merlin.cacerts.password} property. - * - * @param password the trust store password - */ - public void setTrustStorePassword(String password) { - this.configuration.setProperty("org.apache.ws.security.crypto.merlin.cacerts.password", password); - } - - /** - * Sets the alias name of the default certificate which has been specified as a property. This should be the - * certificate that is used for signature and encryption. This alias corresponds to the certificate that should be - * used whenever KeyInfo is not present in a signed or an encrypted message. - * - *

This property maps to the WSS4J {@code org.apache.ws.security.crypto.merlin.keystore.alias} property. - * - * @param defaultX509Alias alias name of the default X509 certificate - */ - public void setDefaultX509Alias(String defaultX509Alias) { - this.configuration.setProperty("org.apache.ws.security.crypto.merlin.keystore.alias", defaultX509Alias); - } - - @Override - public void setBeanClassLoader(ClassLoader classLoader) { - this.classLoader = classLoader; - } - - @Override - public void afterPropertiesSet() throws Exception { - if (!configuration.containsKey(CRYPTO_PROVIDER_PROPERTY)) { - configuration.setProperty(CRYPTO_PROVIDER_PROPERTY, Merlin.class.getName()); - } - this.crypto = CryptoFactory.getInstance(configuration, classLoader); - } - - @Override - public Class getObjectType() { - return Crypto.class; - } - - @Override - public boolean isSingleton() { - return true; - } - - @Override - public Crypto getObject() throws Exception { - return crypto; - } - -} diff --git a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/support/package.html b/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/support/package.html deleted file mode 100644 index adc038ee..00000000 --- a/spring-ws-security/src/main/java/org/springframework/ws/soap/security/wss4j/support/package.html +++ /dev/null @@ -1,5 +0,0 @@ - - -Contains support classes for working with WSS4J (deprecated as of Spring WS 2.3). - - \ No newline at end of file diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jInterceptorTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jInterceptorTest.java deleted file mode 100644 index d346a541..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jInterceptorTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jInterceptorTest extends Wss4jInterceptorTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorEncryptionTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorEncryptionTest.java deleted file mode 100644 index 1812c97d..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorEncryptionTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorEncryptionTest extends Wss4jMessageInterceptorEncryptionTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorHeaderTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorHeaderTest.java deleted file mode 100644 index 370d801c..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorHeaderTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorHeaderTest extends Wss4jMessageInterceptorHeaderTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSignTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSignTest.java deleted file mode 100644 index 3bac8e5f..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSignTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorSignTest extends Wss4jMessageInterceptorSignTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSoapActionTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSoapActionTest.java deleted file mode 100644 index 20539692..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSoapActionTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorSoapActionTest extends Wss4jMessageInterceptorSoapActionTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSpringSecurityCallbackHandlerTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSpringSecurityCallbackHandlerTest.java deleted file mode 100644 index 5be3bb45..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorSpringSecurityCallbackHandlerTest.java +++ /dev/null @@ -1,22 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorSpringSecurityCallbackHandlerTest - extends Wss4jMessageInterceptorSpringSecurityCallbackHandlerTestCase { - -} \ No newline at end of file diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorTimestampTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorTimestampTest.java deleted file mode 100644 index d5e23aa9..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorTimestampTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorTimestampTest extends Wss4jMessageInterceptorTimestampTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorUsernameTokenSignatureTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorUsernameTokenSignatureTest.java deleted file mode 100644 index f8e09df1..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorUsernameTokenSignatureTest.java +++ /dev/null @@ -1,22 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorUsernameTokenSignatureTest - extends Wss4jMessageInterceptorUsernameTokenSignatureTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorUsernameTokenTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorUsernameTokenTest.java deleted file mode 100644 index 4162248d..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorUsernameTokenTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class AxiomWss4jMessageInterceptorUsernameTokenTest extends Wss4jMessageInterceptorUsernameTokenTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorX509Test.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorX509Test.java deleted file mode 100644 index 0b1bae09..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/AxiomWss4jMessageInterceptorX509Test.java +++ /dev/null @@ -1,22 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -/** @author tareq */ -public class AxiomWss4jMessageInterceptorX509Test extends Wss4jMessageInterceptorX509TestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jInterceptorTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jInterceptorTest.java deleted file mode 100644 index 7233fe9e..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jInterceptorTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jInterceptorTest extends Wss4jInterceptorTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorEncryptionTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorEncryptionTest.java deleted file mode 100644 index 78b8cbf4..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorEncryptionTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jMessageInterceptorEncryptionTest extends Wss4jMessageInterceptorEncryptionTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorHeaderTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorHeaderTest.java deleted file mode 100644 index 539313db..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorHeaderTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jMessageInterceptorHeaderTest extends Wss4jMessageInterceptorHeaderTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSignTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSignTest.java deleted file mode 100644 index 4cbc1651..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSignTest.java +++ /dev/null @@ -1,83 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.io.ByteArrayInputStream; -import java.io.ByteArrayOutputStream; -import java.util.Iterator; -import javax.xml.namespace.QName; -import javax.xml.soap.MimeHeaders; -import javax.xml.soap.SOAPHeader; -import javax.xml.soap.SOAPHeaderElement; -import javax.xml.soap.SOAPMessage; -import javax.xml.transform.Transformer; -import javax.xml.transform.TransformerFactory; -import javax.xml.transform.dom.DOMResult; - -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.saaj.SaajSoapMessage; -import org.springframework.ws.soap.saaj.SaajSoapMessageFactory; -import org.springframework.xml.transform.StringSource; - -import org.junit.Test; - -import static org.junit.Assert.assertTrue; - -public class SaajWss4jMessageInterceptorSignTest extends Wss4jMessageInterceptorSignTestCase { - - private static final String PAYLOAD = - "QQQ"; - - @Test - public void testSignAndValidate() throws Exception { - Transformer transformer = TransformerFactory.newInstance().newTransformer(); - interceptor.setSecurementActions("Signature"); - interceptor.setEnableSignatureConfirmation(false); - interceptor.setSecurementPassword("123456"); - interceptor.setSecurementUsername("rsaKey"); - SOAPMessage saajMessage = saajSoap11MessageFactory.createMessage(); - transformer.transform(new StringSource(PAYLOAD), new DOMResult(saajMessage.getSOAPBody())); - SoapMessage message = new SaajSoapMessage(saajMessage, saajSoap11MessageFactory); - MessageContext messageContext = new DefaultMessageContext(message, new SaajSoapMessageFactory(saajSoap11MessageFactory)); - - interceptor.secureMessage(message, messageContext); - - SOAPHeader header = ((SaajSoapMessage) message).getSaajMessage().getSOAPHeader(); - Iterator iterator = header.getChildElements(new QName( - "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd", "Security")); - assertTrue("No security header", iterator.hasNext()); - SOAPHeaderElement securityHeader = (SOAPHeaderElement) iterator.next(); - iterator = securityHeader.getChildElements(new QName("http://www.w3.org/2000/09/xmldsig#", "Signature")); - assertTrue("No signature header", iterator.hasNext()); - - ByteArrayOutputStream bos = new ByteArrayOutputStream(); - message.writeTo(bos); - - MimeHeaders mimeHeaders = new MimeHeaders(); - mimeHeaders.addHeader("Content-Type", "text/xml"); - ByteArrayInputStream bis = new ByteArrayInputStream(bos.toByteArray()); - - SOAPMessage signed = saajSoap11MessageFactory.createMessage(mimeHeaders, bis); - message = new SaajSoapMessage(signed, saajSoap11MessageFactory); - messageContext = new DefaultMessageContext(message, new SaajSoapMessageFactory(saajSoap11MessageFactory)); - - interceptor.validateMessage(message, messageContext); - } - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSoapActionTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSoapActionTest.java deleted file mode 100644 index 21de82d5..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSoapActionTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jMessageInterceptorSoapActionTest extends Wss4jMessageInterceptorSoapActionTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSpringSecurityCallbackHandlerTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSpringSecurityCallbackHandlerTest.java deleted file mode 100644 index ed7faa1c..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorSpringSecurityCallbackHandlerTest.java +++ /dev/null @@ -1,22 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jMessageInterceptorSpringSecurityCallbackHandlerTest - extends Wss4jMessageInterceptorSpringSecurityCallbackHandlerTestCase { - -} \ No newline at end of file diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorTimestampTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorTimestampTest.java deleted file mode 100644 index 8e66b3ac..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorTimestampTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jMessageInterceptorTimestampTest extends Wss4jMessageInterceptorTimestampTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorUsernameTokenSignatureTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorUsernameTokenSignatureTest.java deleted file mode 100644 index 6c31316c..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorUsernameTokenSignatureTest.java +++ /dev/null @@ -1,22 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jMessageInterceptorUsernameTokenSignatureTest - extends Wss4jMessageInterceptorUsernameTokenSignatureTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorUsernameTokenTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorUsernameTokenTest.java deleted file mode 100644 index 066d5b4a..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorUsernameTokenTest.java +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -public class SaajWss4jMessageInterceptorUsernameTokenTest extends Wss4jMessageInterceptorUsernameTokenTestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorX509Test.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorX509Test.java deleted file mode 100644 index 3d4227c1..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/SaajWss4jMessageInterceptorX509Test.java +++ /dev/null @@ -1,22 +0,0 @@ -/* - * Copyright 2008 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -/** @author tareq */ -public class SaajWss4jMessageInterceptorX509Test extends Wss4jMessageInterceptorX509TestCase { - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jInterceptorTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jInterceptorTestCase.java deleted file mode 100644 index f602bc35..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jInterceptorTestCase.java +++ /dev/null @@ -1,84 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.WsSecuritySecurementException; -import org.springframework.ws.soap.security.WsSecurityValidationException; - -import org.junit.Test; - -import static org.junit.Assert.assertEquals; -import static org.junit.Assert.fail; - -public abstract class Wss4jInterceptorTestCase extends Wss4jTestCase { - - @Test - public void testHandleRequest() throws Exception { - SoapMessage request = loadSoap11Message("empty-soap.xml"); - final Object requestMessage = getMessage(request); - SoapMessage validatedRequest = loadSoap11Message("empty-soap.xml"); - final Object validatedRequestMessage = getMessage(validatedRequest); - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor() { - @Override - protected void secureMessage(SoapMessage soapMessage, MessageContext messageContext) - throws WsSecuritySecurementException { - fail("secure not expected"); - } - - @Override - protected void validateMessage(SoapMessage soapMessage, MessageContext messageContext) - throws WsSecurityValidationException { - assertEquals("Invalid message", requestMessage, getMessage(soapMessage)); - setMessage(soapMessage, validatedRequestMessage); - } - }; - MessageContext context = new DefaultMessageContext(request, getSoap11MessageFactory()); - interceptor.handleRequest(context, null); - assertEquals("Invalid request", validatedRequestMessage, getMessage((SoapMessage) context.getRequest())); - } - - @Test - public void testHandleResponse() throws Exception { - SoapMessage securedResponse = loadSoap11Message("empty-soap.xml"); - final Object securedResponseMessage = getMessage(securedResponse); - - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor() { - - @Override - protected void secureMessage(SoapMessage soapMessage, MessageContext messageContext) - throws WsSecuritySecurementException { - setMessage(soapMessage, securedResponseMessage); - } - - @Override - protected void validateMessage(SoapMessage soapMessage, MessageContext messageContext) - throws WsSecurityValidationException { - fail("validate not expected"); - } - - }; - SoapMessage request = loadSoap11Message("empty-soap.xml"); - MessageContext context = new DefaultMessageContext(request, getSoap11MessageFactory()); - context.getResponse(); - interceptor.handleResponse(context, null); - assertEquals("Invalid response", securedResponseMessage, getMessage((SoapMessage) context.getResponse())); - } - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorEncryptionTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorEncryptionTestCase.java deleted file mode 100644 index 60a9a969..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorEncryptionTestCase.java +++ /dev/null @@ -1,86 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.util.Properties; - -import org.junit.Test; -import org.w3c.dom.Document; - -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.wss4j.callback.KeyStoreCallbackHandler; -import org.springframework.ws.soap.security.wss4j.support.CryptoFactoryBean; - -public abstract class Wss4jMessageInterceptorEncryptionTestCase extends Wss4jTestCase { - - protected Wss4jSecurityInterceptor interceptor; - - @Override - protected void onSetup() throws Exception { - interceptor = new Wss4jSecurityInterceptor(); - interceptor.setValidationActions("Encrypt"); - interceptor.setSecurementActions("Encrypt"); - - KeyStoreCallbackHandler callbackHandler = new KeyStoreCallbackHandler(); - callbackHandler.setPrivateKeyPassword("123456"); - interceptor.setValidationCallbackHandler(callbackHandler); - - CryptoFactoryBean cryptoFactoryBean = new CryptoFactoryBean(); - - Properties cryptoFactoryBeanConfig = new Properties(); - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.provider", - "org.apache.ws.security.components.crypto.Merlin"); - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.merlin.keystore.type", "jceks"); - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.merlin.keystore.password", "123456"); - - // from the class path - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.merlin.file", "private.jks"); - cryptoFactoryBean.setConfiguration(cryptoFactoryBeanConfig); - cryptoFactoryBean.afterPropertiesSet(); - interceptor.setValidationDecryptionCrypto(cryptoFactoryBean - .getObject()); - interceptor.setSecurementEncryptionCrypto(cryptoFactoryBean - .getObject()); - - interceptor.afterPropertiesSet(); - } - - @Test - public void testDecryptRequest() throws Exception { - SoapMessage message = loadSoap11Message("encrypted-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, messageContext); - Document document = getDocument((SoapMessage) messageContext.getRequest()); - assertXpathEvaluatesTo("Decryption error", "Hello", "/SOAP-ENV:Envelope/SOAP-ENV:Body/echo:echoRequest/text()", - document); - assertXpathNotExists("Security Header not removed", "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security", - getDocument(message)); - } - - @Test - public void testEncryptResponse() throws Exception { - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext messageContext = getSoap11MessageContext(message); - interceptor.setSecurementEncryptionUser("rsakey"); - interceptor.secureMessage(message, messageContext); - Document document = getDocument(message); - assertXpathExists("Encryption error", "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/xenc:EncryptedKey", - document); - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorHeaderTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorHeaderTestCase.java deleted file mode 100644 index 528dc3f0..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorHeaderTestCase.java +++ /dev/null @@ -1,160 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import static org.junit.Assert.*; - -import java.io.ByteArrayOutputStream; -import java.util.Iterator; -import java.util.Properties; -import javax.xml.namespace.QName; - -import org.junit.Test; - -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapHeaderElement; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.WsSecurityValidationException; -import org.springframework.ws.soap.security.wss4j.callback.SimplePasswordValidationCallbackHandler; - -/** - * @author Arjen Poutsma - * @author Tareq Abedrabbo - * @author Greg Turnquist - */ -public abstract class Wss4jMessageInterceptorHeaderTestCase extends Wss4jTestCase { - - private Wss4jSecurityInterceptor interceptor; - private Wss4jSecurityInterceptor interceptorThatKeepsSecurityHeader; - - @Override - protected void onSetup() throws Exception { - Properties users = new Properties(); - users.setProperty("Bert", "Ernie"); - interceptor = new Wss4jSecurityInterceptor(); - interceptor.setValidateRequest(true); - interceptor.setSecureResponse(true); - interceptor.setValidationActions("UsernameToken"); - SimplePasswordValidationCallbackHandler callbackHandler = new SimplePasswordValidationCallbackHandler(); - callbackHandler.setUsers(users); - interceptor.setValidationCallbackHandler(callbackHandler); - interceptor.afterPropertiesSet(); - - interceptorThatKeepsSecurityHeader = new Wss4jSecurityInterceptor(); - interceptorThatKeepsSecurityHeader.setValidateRequest(true); - interceptorThatKeepsSecurityHeader.setSecureResponse(true); - interceptorThatKeepsSecurityHeader.setValidationActions("UsernameToken"); - interceptorThatKeepsSecurityHeader.setValidationCallbackHandler(callbackHandler); - interceptorThatKeepsSecurityHeader.setRemoveSecurityHeader(false); - interceptorThatKeepsSecurityHeader.afterPropertiesSet(); - } - - @Test - public void testValidateUsernameTokenPlainText() throws Exception { - SoapMessage message = loadSoap11Message("usernameTokenPlainTextWithHeaders-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, messageContext); - Object result = getMessage(message); - assertNotNull("No result returned", result); - - for (Iterator i = message.getEnvelope().getHeader().examineAllHeaderElements(); i.hasNext();) { - SoapHeaderElement element = i.next(); - QName name = element.getName(); - if (name.getNamespaceURI() - .equals("http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd")) { - fail("Security Header not removed"); - } - - } - - assertXpathNotExists("Security Header not removed", "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security", - getDocument(message)); - assertXpathExists("header1 not found", "/SOAP-ENV:Envelope/SOAP-ENV:Header/header1", getDocument(message)); - assertXpathExists("header2 not found", "/SOAP-ENV:Envelope/SOAP-ENV:Header/header2", getDocument(message)); - - } - - @Test - public void testValidateUsernameTokenPlainTextButKeepSecurityHeader() throws Exception { - SoapMessage message = loadSoap11Message("usernameTokenPlainTextWithHeaders-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptorThatKeepsSecurityHeader.validateMessage(message, messageContext); - Object result = getMessage(message); - assertNotNull("No result returned", result); - - boolean foundSecurityHeader = false; - for (Iterator i = message.getEnvelope().getHeader().examineAllHeaderElements(); i.hasNext();) { - SoapHeaderElement element = i.next(); - QName name = element.getName(); - if (name.getNamespaceURI() - .equals("http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd")) { - foundSecurityHeader = true; - } - - } - assertTrue(foundSecurityHeader); - - assertXpathExists("header1 not found", "/SOAP-ENV:Envelope/SOAP-ENV:Header/header1", getDocument(message)); - assertXpathExists("header2 not found", "/SOAP-ENV:Envelope/SOAP-ENV:Header/header2", getDocument(message)); - - } - - @Test(expected=WsSecurityValidationException.class) - public void testEmptySecurityHeader() throws Exception { - SoapMessage message = loadSoap11Message("emptySecurityHeader-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, messageContext); - } - - @Test - public void testPreserveCustomHeaders() throws Exception { - interceptor.setSecurementActions("UsernameToken"); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - - ByteArrayOutputStream os = new ByteArrayOutputStream(); - SoapMessage message = loadSoap11Message("customHeader-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - message.writeTo(os); - String document = os.toString("UTF-8"); - assertXpathEvaluatesTo("Header 1 does not exist", "test1", "/SOAP-ENV:Envelope/SOAP-ENV:Header/test:header1", - document); - assertXpathNotExists("Header 2 exist", "/SOAP-ENV:Envelope/SOAP-ENV:Header/test:header2", document); - - interceptor.secureMessage(message, messageContext); - - SoapHeaderElement element = message.getSoapHeader().addHeaderElement(new QName("http://test", "header2")); - element.setText("test2"); - - os = new ByteArrayOutputStream(); - message.writeTo(os); - document = os.toString("UTF-8"); - assertXpathEvaluatesTo("Header 1 does not exist", "test1", "/SOAP-ENV:Envelope/SOAP-ENV:Header/test:header1", - document); - assertXpathEvaluatesTo("Header 2 does not exist", "test2", "/SOAP-ENV:Envelope/SOAP-ENV:Header/test:header2", - document); - - os = new ByteArrayOutputStream(); - message.writeTo(os); - document = os.toString("UTF-8"); - assertXpathEvaluatesTo("Header 1 does not exist", "test1", "/SOAP-ENV:Envelope/SOAP-ENV:Header/test:header1", - document); - assertXpathEvaluatesTo("Header 2 does not exist", "test2", "/SOAP-ENV:Envelope/SOAP-ENV:Header/test:header2", - document); - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSignTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSignTestCase.java deleted file mode 100644 index 03a3e87d..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSignTestCase.java +++ /dev/null @@ -1,123 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.util.Properties; - -import org.springframework.ws.WebServiceMessage; -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.wss4j.support.CryptoFactoryBean; - -import org.junit.Test; -import org.w3c.dom.Document; - -import static org.junit.Assert.assertNotNull; - -public abstract class Wss4jMessageInterceptorSignTestCase extends Wss4jTestCase { - - protected Wss4jSecurityInterceptor interceptor; - - @Override - protected void onSetup() throws Exception { - interceptor = new Wss4jSecurityInterceptor(); - interceptor.setValidationActions("Signature"); - - CryptoFactoryBean cryptoFactoryBean = new CryptoFactoryBean(); - Properties cryptoFactoryBeanConfig = new Properties(); - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.provider", - "org.apache.ws.security.components.crypto.Merlin"); - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.merlin.keystore.type", "jceks"); - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.merlin.keystore.password", "123456"); - - // from the class path - cryptoFactoryBeanConfig.setProperty("org.apache.ws.security.crypto.merlin.file", "private.jks"); - cryptoFactoryBean.setConfiguration(cryptoFactoryBeanConfig); - cryptoFactoryBean.afterPropertiesSet(); - interceptor.setValidationSignatureCrypto(cryptoFactoryBean - .getObject()); - interceptor.setSecurementSignatureCrypto(cryptoFactoryBean - .getObject()); - interceptor.afterPropertiesSet(); - - } - - @Test - public void testValidateCertificate() throws Exception { - SoapMessage message = loadSoap11Message("signed-soap.xml"); - - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, messageContext); - Object result = getMessage(message); - assertNotNull("No result returned", result); - assertXpathNotExists("Security Header not removed", "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security", - getDocument(message)); - } - - @Test - public void testValidateCertificateWithSignatureConfirmation() throws Exception { - SoapMessage message = loadSoap11Message("signed-soap.xml"); - MessageContext messageContext = getSoap11MessageContext(message); - interceptor.setEnableSignatureConfirmation(true); - interceptor.validateMessage(message, messageContext); - WebServiceMessage response = messageContext.getResponse(); - interceptor.secureMessage(message, messageContext); - assertNotNull("No result returned", response); - Document document = getDocument((SoapMessage) response); - assertXpathExists("Absent SignatureConfirmation element", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse11:SignatureConfirmation", document); - } - - @Test - public void testSignResponse() throws Exception { - interceptor.setSecurementActions("Signature"); - interceptor.setEnableSignatureConfirmation(false); - interceptor.setSecurementPassword("123456"); - interceptor.setSecurementUsername("rsaKey"); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext messageContext = getSoap11MessageContext(message); - - // interceptor.setSecurementSignatureKeyIdentifier("IssuerSerial"); - - interceptor.secureMessage(message, messageContext); - - Document document = getDocument(message); - assertXpathExists("Absent SignatureConfirmation element", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/ds:Signature", document); - - - } - - @Test - public void testSignResponseWithSignatureUser() throws Exception { - interceptor.setSecurementActions("Signature"); - interceptor.setEnableSignatureConfirmation(false); - interceptor.setSecurementPassword("123456"); - interceptor.setSecurementSignatureUser("rsaKey"); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext messageContext = getSoap11MessageContext(message); - - interceptor.secureMessage(message, messageContext); - - Document document = getDocument(message); - assertXpathExists("Absent SignatureConfirmation element", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/ds:Signature", document); - - - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSoapActionTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSoapActionTestCase.java deleted file mode 100644 index 836f2424..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSoapActionTestCase.java +++ /dev/null @@ -1,108 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.util.Properties; - -import org.springframework.ws.WebServiceMessageFactory; -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.wss4j.callback.SimplePasswordValidationCallbackHandler; - -import org.apache.ws.security.WSConstants; -import org.junit.Test; - -import static org.junit.Assert.assertEquals; -import static org.junit.Assert.assertNotNull; - -public abstract class Wss4jMessageInterceptorSoapActionTestCase extends Wss4jTestCase { - - private static final String SOAP_ACTION = "\"http://test\""; - - private Properties users; - - private Wss4jSecurityInterceptor interceptor; - - @Override - protected void onSetup() throws Exception { - users = new Properties(); - users.setProperty("Bert", "Ernie"); - interceptor = new Wss4jSecurityInterceptor(); - interceptor.setValidationActions("UsernameToken"); - interceptor.setSecurementActions("UsernameToken"); - interceptor.setSecurementPasswordType(WSConstants.PW_TEXT); - SimplePasswordValidationCallbackHandler callbackHandler = new SimplePasswordValidationCallbackHandler(); - callbackHandler.setUsers(users); - interceptor.setValidationCallbackHandler(callbackHandler); - - interceptor.afterPropertiesSet(); - } - - @Test - public void testPreserveSoapActionOnValidation() throws Exception { - SoapMessage message = loadSoap11Message("usernameTokenPlainText-soap.xml"); - message.setSoapAction(SOAP_ACTION); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, messageContext); - - assertNotNull("Soap Action must not be null", message.getSoapAction()); - assertEquals("Soap Action is different from expected", SOAP_ACTION, message.getSoapAction()); - } - - @Test - public void testPreserveSoap12ActionOnValidation() throws Exception { - SoapMessage message = loadSoap12Message("usernameTokenPlainText-soap12.xml"); - message.setSoapAction(SOAP_ACTION); - WebServiceMessageFactory messageFactory = getSoap12MessageFactory(); - MessageContext messageContext = new DefaultMessageContext(message, messageFactory); - interceptor.validateMessage(message, messageContext); - - assertNotNull("Soap Action must not be null", message.getSoapAction()); - assertEquals("Soap Action is different from expected", SOAP_ACTION, message.getSoapAction()); - } - - @Test - public void testPreserveSoapActionOnSecurement() throws Exception { - SoapMessage message = loadSoap11Message("empty-soap.xml"); - message.setSoapAction(SOAP_ACTION); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - MessageContext messageContext = getSoap11MessageContext(message); - interceptor.secureMessage(message, messageContext); - - assertNotNull("Soap Action must not be null", message.getSoapAction()); - assertEquals("Soap Action is different from expected", SOAP_ACTION, message.getSoapAction()); - - } - - @Test - public void testPreserveSoap12ActionOnSecurement() throws Exception { - SoapMessage message = loadSoap12Message("empty-soap12.xml"); - message.setSoapAction(SOAP_ACTION); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - MessageContext messageContext = getSoap12MessageContext(message); - interceptor.secureMessage(message, messageContext); - - assertNotNull("Soap Action must not be null", message.getSoapAction()); - assertEquals("Soap Action is different from expected", SOAP_ACTION, message.getSoapAction()); - - } - - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSpringSecurityCallbackHandlerTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSpringSecurityCallbackHandlerTestCase.java deleted file mode 100644 index 29efefa4..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorSpringSecurityCallbackHandlerTestCase.java +++ /dev/null @@ -1,127 +0,0 @@ -/* - * Copyright 2005-2012 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.util.Properties; - -import org.springframework.security.authentication.AuthenticationManager; -import org.springframework.security.core.context.SecurityContextHolder; -import org.springframework.security.provisioning.InMemoryUserDetailsManager; -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.server.EndpointInterceptor; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.wss4j.callback.SpringSecurityPasswordValidationCallbackHandler; - -import org.apache.ws.security.WSConstants; -import org.junit.After; -import org.junit.Test; - -import static org.easymock.EasyMock.*; -import static org.junit.Assert.assertNotNull; -import static org.junit.Assert.assertNull; - -public abstract class Wss4jMessageInterceptorSpringSecurityCallbackHandlerTestCase extends Wss4jTestCase { - - private Properties users = new Properties(); - - private AuthenticationManager authenticationManager; - - @Override - protected void onSetup() throws Exception { - authenticationManager = createMock(AuthenticationManager.class); - users.setProperty("Bert", "Ernie,ROLE_TEST"); - } - - @After - public void tearDown() throws Exception { - verify(authenticationManager); - SecurityContextHolder.clearContext(); - } - - @Test - public void testValidateUsernameTokenPlainText() throws Exception { - EndpointInterceptor interceptor = prepareInterceptor("UsernameToken", true, false); - SoapMessage message = loadSoap11Message("usernameTokenPlainText-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.handleRequest(messageContext, null); - assertValidateUsernameToken(message); - - // test clean up - messageContext.getResponse(); - interceptor.handleResponse(messageContext, null); - interceptor.afterCompletion(messageContext, null, null); - assertNull("Authentication created", SecurityContextHolder.getContext().getAuthentication()); - } - - @Test - public void testValidateUsernameTokenDigest() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setSecurementActions("UsernameToken"); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - interceptor.setSecurementPasswordType(WSConstants.PW_DIGEST); - - - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.handleRequest(messageContext); - - interceptor = prepareInterceptor("UsernameToken", true, true); - interceptor.handleRequest(messageContext, null); - assertValidateUsernameToken(message); - - // test clean up - messageContext.getResponse(); - interceptor.handleResponse(messageContext, null); - interceptor.afterCompletion(messageContext, null, null); - assertNull("Authentication created", SecurityContextHolder.getContext().getAuthentication()); - } - - protected void assertValidateUsernameToken(SoapMessage message) throws Exception { - Object result = getMessage(message); - assertNotNull("No result returned", result); - assertXpathNotExists("Security Header not removed", "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security", - getDocument(message)); - assertNotNull("No Authentication created", SecurityContextHolder.getContext().getAuthentication()); - } - - protected Wss4jSecurityInterceptor prepareInterceptor(String actions, boolean validating, boolean digest) - throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - if (validating) { - interceptor.setValidationActions(actions); - } - else { - interceptor.setSecurementActions(actions); - } - SpringSecurityPasswordValidationCallbackHandler callbackHandler = - new SpringSecurityPasswordValidationCallbackHandler(); - InMemoryUserDetailsManager userDetailsManager = new InMemoryUserDetailsManager(users); - callbackHandler.setUserDetailsService(userDetailsManager); - if (digest) { - interceptor.setSecurementPasswordType(WSConstants.PW_DIGEST); - } - else { - interceptor.setSecurementPasswordType(WSConstants.PW_TEXT); - } - interceptor.setValidationCallbackHandler(callbackHandler); - interceptor.afterPropertiesSet(); - replay(authenticationManager); - return interceptor; - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorTimestampTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorTimestampTestCase.java deleted file mode 100644 index 6f53b499..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorTimestampTestCase.java +++ /dev/null @@ -1,103 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.text.DateFormat; -import java.text.SimpleDateFormat; - -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.WsSecurityValidationException; - -import org.junit.Test; -import org.w3c.dom.Document; - -import static org.junit.Assert.assertEquals; - -public abstract class Wss4jMessageInterceptorTimestampTestCase extends Wss4jTestCase { - - @Test - public void testAddTimestamp() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setSecurementActions("Timestamp"); - interceptor.afterPropertiesSet(); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext context = getSoap11MessageContext(message); - interceptor.secureMessage(message, context); - Document document = getDocument(message); - assertXpathExists("timestamp header not found", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsu:Timestamp", document); - } - - @Test - public void testValidateTimestamp() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setValidationActions("Timestamp"); - interceptor.afterPropertiesSet(); - SoapMessage message = getMessageWithTimestamp(); - - MessageContext context = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, context); - assertXpathNotExists("Security Header not removed", "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security", - getDocument(message)); - } - - @Test(expected = WsSecurityValidationException.class) - public void testValidateTimestampWithExpiredTtl() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setValidationActions("Timestamp"); - interceptor.afterPropertiesSet(); - SoapMessage message = loadSoap11Message("expiredTimestamp-soap.xml"); - MessageContext context = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, context); - } - - - @Test - public void testSecureTimestampWithCustomTtl() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setSecurementActions("Timestamp"); - interceptor.setTimestampStrict(true); - int ttlInSeconds = 1; - interceptor.setSecurementTimeToLive(ttlInSeconds); - interceptor.afterPropertiesSet(); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext context = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.secureMessage(message, context); - - String created = xpathTemplate.evaluateAsString("/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsu:Timestamp/wsu:Created/text()", - message.getEnvelope().getSource()); - String expires = xpathTemplate.evaluateAsString("/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsu:Timestamp/wsu:Expires/text()", - message.getEnvelope().getSource()); - - DateFormat format = new SimpleDateFormat("yyyy-MM-dd'T'HH:mm:ss.SS'Z'"); - - long actualTtl = format.parse(expires).getTime() - format.parse(created).getTime(); - assertEquals("invalid ttl", 1000 * ttlInSeconds, actualTtl); - } - - private SoapMessage getMessageWithTimestamp() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setSecurementActions("Timestamp"); - interceptor.afterPropertiesSet(); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext context = getSoap11MessageContext(message); - interceptor.secureMessage(message, context); - return message; - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorUsernameTokenSignatureTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorUsernameTokenSignatureTestCase.java deleted file mode 100644 index bb28b21e..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorUsernameTokenSignatureTestCase.java +++ /dev/null @@ -1,45 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; - -import org.junit.Test; -import org.w3c.dom.Document; - -public abstract class Wss4jMessageInterceptorUsernameTokenSignatureTestCase extends Wss4jTestCase { - - @Test - public void testAddUsernameTokenSignature() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setSecurementActions("UsernameTokenSignature"); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - interceptor.afterPropertiesSet(); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext context = getSoap11MessageContext(message); - interceptor.secureMessage(message, context); - - Document doc = getDocument(message); - assertXpathEvaluatesTo("Invalid Username", "Bert", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse:UsernameToken/wsse:Username/text()", doc); - assertXpathExists("Invalid Password", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse:UsernameToken/wsse:Password[@Type='http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest']/text()", - doc); - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorUsernameTokenTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorUsernameTokenTestCase.java deleted file mode 100644 index ee77cb4c..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorUsernameTokenTestCase.java +++ /dev/null @@ -1,155 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.util.Properties; - -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.wss4j.callback.SimplePasswordValidationCallbackHandler; - -import org.apache.ws.security.WSConstants; -import org.junit.Test; -import org.w3c.dom.Document; - -import static org.junit.Assert.assertNotNull; - -public abstract class Wss4jMessageInterceptorUsernameTokenTestCase extends Wss4jTestCase { - - private Properties users = new Properties(); - - @Override - protected void onSetup() throws Exception { - users.setProperty("Bert", "Ernie"); - } - - @Test - public void testValidateUsernameTokenPlainText() throws Exception { - Wss4jSecurityInterceptor interceptor = prepareInterceptor("UsernameToken", true, false); - SoapMessage message = loadSoap11Message("usernameTokenPlainText-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, messageContext); - assertValidateUsernameToken(message); - } - - @Test - public void testValidateUsernameTokenDigest() throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - interceptor.setSecurementActions("UsernameToken"); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - interceptor.setSecurementPasswordType(WSConstants.PW_DIGEST); - - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.handleRequest(messageContext); - - interceptor = prepareInterceptor("UsernameToken", true, true); - interceptor.validateMessage(message, messageContext); - assertValidateUsernameToken(message); - } - - @Test - public void testValidateUsernameTokenWithQualifiedType() throws Exception { - Wss4jSecurityInterceptor interceptor = prepareInterceptor("UsernameToken", true, false); - SoapMessage message = loadSoap11Message("usernameTokenPlainTextQualifiedType-soap.xml"); - MessageContext messageContext = new DefaultMessageContext(message, getSoap11MessageFactory()); - interceptor.validateMessage(message, messageContext); - assertValidateUsernameToken(message); - } - - @Test - public void testAddUsernameTokenPlainText() throws Exception { - Wss4jSecurityInterceptor interceptor = prepareInterceptor("UsernameToken", false, false); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - - MessageContext messageContext = getSoap11MessageContext(message); - - interceptor.secureMessage(message, messageContext); - assertAddUsernameTokenPlainText(message); - } - - @Test - public void testAddUsernameTokenDigest() throws Exception { - Wss4jSecurityInterceptor interceptor = prepareInterceptor("UsernameToken", false, true); - interceptor.setSecurementUsername("Bert"); - interceptor.setSecurementPassword("Ernie"); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - - MessageContext messageContext = getSoap11MessageContext(message); - interceptor.secureMessage(message, messageContext); - assertAddUsernameTokenDigest(message); - } - - protected void assertValidateUsernameToken(SoapMessage message) throws Exception { - Object result = getMessage(message); - assertNotNull("No result returned", result); - assertXpathNotExists("Security Header not removed", "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security", - getDocument(message)); - } - - protected void assertAddUsernameTokenPlainText(SoapMessage message) throws Exception { - Object result = getMessage(message); - assertNotNull("No result returned", result); - Document doc = getDocument(message); - assertXpathEvaluatesTo("Invalid Username", "Bert", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse:UsernameToken/wsse:Username/text()", doc); - assertXpathEvaluatesTo("Invalid Password", "Ernie", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse:UsernameToken/wsse:Password[@Type='http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText']/text()", - doc); - } - - protected void assertAddUsernameTokenDigest(SoapMessage message) throws Exception { - Object result = getMessage(message); - Document doc = getDocument(message); - assertNotNull("No result returned", result); - assertXpathEvaluatesTo("Invalid Username", "Bert", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse:UsernameToken/wsse:Username/text()", doc); - assertXpathExists("Password does not exist", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse:UsernameToken/wsse:Password[@Type='http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest']", - doc); - - } - - protected Wss4jSecurityInterceptor prepareInterceptor(String actions, boolean validating, boolean digest) - throws Exception { - Wss4jSecurityInterceptor interceptor = new Wss4jSecurityInterceptor(); - if (validating) { - interceptor.setValidationActions(actions); - } - else { - interceptor.setSecurementActions(actions); - } - SimplePasswordValidationCallbackHandler callbackHandler = new SimplePasswordValidationCallbackHandler(); - callbackHandler.setUsers(users); - if (digest) { - interceptor.setSecurementPasswordType(WSConstants.PW_DIGEST); - } - else { - interceptor.setSecurementPasswordType(WSConstants.PW_TEXT); - } - interceptor.setValidationCallbackHandler(callbackHandler); - - interceptor.setBspCompliant(false); - - interceptor.afterPropertiesSet(); - return interceptor; - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorX509TestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorX509TestCase.java deleted file mode 100644 index 7d6b0cad..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jMessageInterceptorX509TestCase.java +++ /dev/null @@ -1,72 +0,0 @@ -/* - * Copyright 2005-2014 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import org.apache.ws.security.components.crypto.Merlin; -import org.junit.Test; -import org.w3c.dom.Document; - -import org.springframework.core.io.ClassPathResource; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.security.wss4j.support.CryptoFactoryBean; - -public abstract class Wss4jMessageInterceptorX509TestCase extends Wss4jTestCase { - - protected Wss4jSecurityInterceptor interceptor; - - @Override - protected void onSetup() throws Exception { - interceptor = new Wss4jSecurityInterceptor(); - interceptor.setSecurementActions("Signature"); - interceptor.setValidationActions("Signature"); - CryptoFactoryBean cryptoFactoryBean = new CryptoFactoryBean(); - cryptoFactoryBean.setCryptoProvider(Merlin.class); - cryptoFactoryBean.setKeyStoreType("jceks"); - cryptoFactoryBean.setKeyStorePassword("123456"); - cryptoFactoryBean.setKeyStoreLocation(new ClassPathResource("private.jks")); - - cryptoFactoryBean.afterPropertiesSet(); - interceptor.setSecurementSignatureCrypto(cryptoFactoryBean - .getObject()); - interceptor.setValidationSignatureCrypto(cryptoFactoryBean - .getObject()); - interceptor.afterPropertiesSet(); - - } - - @Test - public void testAddCertificate() throws Exception { - - interceptor.setSecurementPassword("123456"); - interceptor.setSecurementUsername("rsaKey"); - SoapMessage message = loadSoap11Message("empty-soap.xml"); - MessageContext messageContext = getSoap11MessageContext(message); - - interceptor.setSecurementSignatureKeyIdentifier("DirectReference"); - - interceptor.secureMessage(message, messageContext); - Document document = getDocument(message); - - assertXpathExists("Absent BinarySecurityToken element", - "/SOAP-ENV:Envelope/SOAP-ENV:Header/wsse:Security/wsse:BinarySecurityToken", document); - - // lets verify the signature that we've just generated - interceptor.validateMessage(message, messageContext); - } - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jTestCase.java deleted file mode 100644 index 5c9d826e..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/Wss4jTestCase.java +++ /dev/null @@ -1,281 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j; - -import java.io.InputStream; -import java.util.HashMap; -import java.util.Map; -import javax.xml.soap.MessageFactory; -import javax.xml.soap.MimeHeaders; -import javax.xml.soap.SOAPConstants; -import javax.xml.soap.SOAPMessage; -import javax.xml.stream.XMLInputFactory; -import javax.xml.stream.XMLStreamReader; -import javax.xml.transform.dom.DOMSource; - -import org.springframework.core.io.ClassPathResource; -import org.springframework.core.io.Resource; -import org.springframework.ws.WebServiceMessage; -import org.springframework.ws.context.DefaultMessageContext; -import org.springframework.ws.context.MessageContext; -import org.springframework.ws.soap.SoapMessage; -import org.springframework.ws.soap.SoapMessageFactory; -import org.springframework.ws.soap.SoapVersion; -import org.springframework.ws.soap.axiom.AxiomSoapMessage; -import org.springframework.ws.soap.axiom.AxiomSoapMessageFactory; -import org.springframework.ws.soap.axiom.support.AxiomUtils; -import org.springframework.ws.soap.saaj.SaajSoapMessage; -import org.springframework.ws.soap.saaj.SaajSoapMessageFactory; -import org.springframework.xml.transform.StringSource; -import org.springframework.xml.xpath.Jaxp13XPathTemplate; - -import org.apache.axiom.soap.SOAP12Constants; -import org.apache.axiom.soap.impl.builder.StAXSOAPModelBuilder; -import org.junit.Assert; -import org.junit.Before; -import org.w3c.dom.Document; -import org.w3c.dom.Node; - -import static org.junit.Assert.assertTrue; - -public abstract class Wss4jTestCase { - - protected MessageFactory saajSoap11MessageFactory; - - protected MessageFactory saajSoap12MessageFactory; - - protected final boolean axiomTest = this.getClass().getSimpleName().startsWith("Axiom"); - - protected final boolean saajTest = this.getClass().getSimpleName().startsWith("Saaj"); - - protected Jaxp13XPathTemplate xpathTemplate = new Jaxp13XPathTemplate(); - - @Before - public final void setUp() throws Exception { - if (!axiomTest && !saajTest) { - throw new IllegalArgumentException("test class name must start with either Axiom or Saaj"); - } - saajSoap11MessageFactory = MessageFactory.newInstance(); - saajSoap12MessageFactory = MessageFactory.newInstance(SOAPConstants.SOAP_1_2_PROTOCOL); - Map namespaces = new HashMap(); - namespaces.put("SOAP-ENV", "http://schemas.xmlsoap.org/soap/envelope/"); - namespaces.put("wsse", - "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"); - namespaces.put("ds", "http://www.w3.org/2000/09/xmldsig#"); - namespaces.put("xenc", "http://www.w3.org/2001/04/xmlenc#"); - namespaces.put("wsse11", "http://docs.oasis-open.org/wss/oasis-wss-wssecurity-secext-1.1.xsd"); - namespaces.put("echo", "http://www.springframework.org/spring-ws/samples/echo"); - namespaces.put("wsu", - "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"); - namespaces.put("test", "http://test"); - xpathTemplate.setNamespaces(namespaces); - onSetup(); - } - - protected void assertXpathEvaluatesTo(String message, - String expectedValue, - String xpathExpression, - Document document) { - String actualValue = xpathTemplate.evaluateAsString(xpathExpression, new DOMSource(document)); - Assert.assertEquals(message, expectedValue, actualValue); - } - - protected void assertXpathEvaluatesTo(String message, - String expectedValue, - String xpathExpression, - String document) { - String actualValue = xpathTemplate.evaluateAsString(xpathExpression, new StringSource(document)); - Assert.assertEquals(message, expectedValue, actualValue); - } - - protected void assertXpathExists(String message, String xpathExpression, Document document) { - Node node = xpathTemplate.evaluateAsNode(xpathExpression, new DOMSource(document)); - Assert.assertNotNull(message, node); - } - - protected void assertXpathNotExists(String message, String xpathExpression, Document document) { - Node node = xpathTemplate.evaluateAsNode(xpathExpression, new DOMSource(document)); - Assert.assertNull(message, node); - } - - protected void assertXpathNotExists(String message, String xpathExpression, String document) { - Node node = xpathTemplate.evaluateAsNode(xpathExpression, new StringSource(document)); - Assert.assertNull(message, node); - } - - protected SaajSoapMessage loadSaaj11Message(String fileName) throws Exception { - MimeHeaders mimeHeaders = new MimeHeaders(); - mimeHeaders.addHeader("Content-Type", "text/xml"); - Resource resource = new ClassPathResource(fileName, getClass()); - InputStream is = resource.getInputStream(); - try { - assertTrue("Could not load SAAJ message [" + resource + "]", resource.exists()); - is = resource.getInputStream(); - return new SaajSoapMessage(saajSoap11MessageFactory.createMessage(mimeHeaders, is), saajSoap11MessageFactory); - } - finally { - is.close(); - } - } - - protected SaajSoapMessage loadSaaj12Message(String fileName) throws Exception { - MimeHeaders mimeHeaders = new MimeHeaders(); - mimeHeaders.addHeader("Content-Type", "application/soap+xml"); - Resource resource = new ClassPathResource(fileName, getClass()); - InputStream is = resource.getInputStream(); - try { - assertTrue("Could not load SAAJ message [" + resource + "]", resource.exists()); - is = resource.getInputStream(); - return new SaajSoapMessage(saajSoap12MessageFactory.createMessage(mimeHeaders, is), saajSoap12MessageFactory); - } - finally { - is.close(); - } - } - - protected AxiomSoapMessage loadAxiom11Message(String fileName) throws Exception { - Resource resource = new ClassPathResource(fileName, getClass()); - InputStream is = resource.getInputStream(); - try { - assertTrue("Could not load Axiom message [" + resource + "]", resource.exists()); - is = resource.getInputStream(); - - XMLStreamReader parser = XMLInputFactory.newInstance().createXMLStreamReader(is); - StAXSOAPModelBuilder builder = new StAXSOAPModelBuilder(parser, null); - org.apache.axiom.soap.SOAPMessage soapMessage = builder.getSoapMessage(); - return new AxiomSoapMessage(soapMessage, "", true, true); - } - finally { - is.close(); - } - } - - @SuppressWarnings("Since15") - protected AxiomSoapMessage loadAxiom12Message(String fileName) throws Exception { - Resource resource = new ClassPathResource(fileName, getClass()); - InputStream is = resource.getInputStream(); - try { - assertTrue("Could not load Axiom message [" + resource + "]", resource.exists()); - is = resource.getInputStream(); - - XMLStreamReader parser = XMLInputFactory.newInstance().createXMLStreamReader(is); - StAXSOAPModelBuilder builder = new StAXSOAPModelBuilder(parser, SOAP12Constants.SOAP_ENVELOPE_NAMESPACE_URI); - org.apache.axiom.soap.SOAPMessage soapMessage = builder.getSoapMessage(); - return new AxiomSoapMessage(soapMessage, "", true, true); - } - finally { - is.close(); - } - } - - protected Object getMessage(SoapMessage soapMessage) { - if (soapMessage instanceof SaajSoapMessage) { - return ((SaajSoapMessage) soapMessage).getSaajMessage(); - } - if (soapMessage instanceof AxiomSoapMessage) { - return ((AxiomSoapMessage) soapMessage).getAxiomMessage(); - - } - throw new IllegalArgumentException("Illegal message: " + soapMessage); - } - - protected void setMessage(SoapMessage soapMessage, Object message) { - if (soapMessage instanceof SaajSoapMessage) { - ((SaajSoapMessage) soapMessage).setSaajMessage((SOAPMessage) message); - return; - } - if (soapMessage instanceof AxiomSoapMessage) { - ((AxiomSoapMessage) soapMessage).setAxiomMessage((org.apache.axiom.soap.SOAPMessage) message); - return; - } - throw new IllegalArgumentException("Illegal message: " + message); - } - - protected void onSetup() throws Exception { - } - - protected SoapMessage loadSoap11Message(String fileName) throws Exception { - if (axiomTest) { - return loadAxiom11Message(fileName); - } - if (saajTest) { - return loadSaaj11Message(fileName); - } - throw new IllegalArgumentException(); - } - - protected SoapMessage loadSoap12Message(String fileName) throws Exception { - if (axiomTest) { - return loadAxiom12Message(fileName); - } - if (saajTest) { - return loadSaaj12Message(fileName); - } - throw new IllegalArgumentException(); - } - - protected SoapMessageFactory getSoap11MessageFactory() throws Exception { - if (axiomTest) { - return new AxiomSoapMessageFactory(); - } - if (saajTest) { - return new SaajSoapMessageFactory(saajSoap11MessageFactory); - } - throw new IllegalArgumentException(); - } - - protected SoapMessageFactory getSoap12MessageFactory() throws Exception { - SoapMessageFactory messageFactory; - if (axiomTest) { - messageFactory = new AxiomSoapMessageFactory(); - } else if (saajTest) { - messageFactory = new SaajSoapMessageFactory(saajSoap12MessageFactory); - } else - throw new IllegalArgumentException(); - messageFactory.setSoapVersion(SoapVersion.SOAP_12); - return messageFactory; - } - - protected Document getDocument(SoapMessage message) throws Exception { - if (axiomTest) { - return AxiomUtils.toDocument(((AxiomSoapMessage) message).getAxiomMessage().getSOAPEnvelope()); - } - if (saajTest) { - return ((SaajSoapMessage) message).getSaajMessage().getSOAPPart(); - } - throw new IllegalArgumentException(); - } - - protected MessageContext getSoap11MessageContext(final SoapMessage response) throws Exception { - return new DefaultMessageContext(response, getSoap11MessageFactory()) { - @Override - public WebServiceMessage getResponse() { - return response; - } - }; - } - - protected MessageContext getSoap12MessageContext(final SoapMessage response) throws Exception { - return new DefaultMessageContext(response, getSoap12MessageFactory()) { - @Override - public WebServiceMessage getResponse() { - return response; - } - }; - } - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/callback/KeyStoreCallbackHandlerTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/callback/KeyStoreCallbackHandlerTest.java deleted file mode 100644 index ca725eff..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/callback/KeyStoreCallbackHandlerTest.java +++ /dev/null @@ -1,56 +0,0 @@ -/* - * Copyright 2005-2012 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.callback; - -import java.security.KeyStore; - -import org.springframework.core.io.ClassPathResource; -import org.springframework.ws.soap.security.support.KeyStoreFactoryBean; - -import org.apache.ws.security.WSPasswordCallback; -import org.junit.Assert; -import org.junit.Before; -import org.junit.Test; - -public class KeyStoreCallbackHandlerTest { - - private KeyStoreCallbackHandler callbackHandler; - - private WSPasswordCallback callback; - - @Before - public void setUp() throws Exception { - callbackHandler = new KeyStoreCallbackHandler(); - callback = new WSPasswordCallback("secretkey", WSPasswordCallback.SECRET_KEY); - - KeyStoreFactoryBean factory = new KeyStoreFactoryBean(); - factory.setLocation(new ClassPathResource("private.jks")); - factory.setPassword("123456"); - factory.setType("JCEKS"); - factory.afterPropertiesSet(); - KeyStore keyStore = factory.getObject(); - callbackHandler.setKeyStore(keyStore); - callbackHandler.setSymmetricKeyPassword("123456"); - } - - @Test - public void testHandleKeyName() throws Exception { - callbackHandler.handleInternal(callback); - Assert.assertNotNull("symmetric key must not be null", callback.getKey()); - } - -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/callback/SpringSecurityPasswordValidationCallbackHandlerTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/callback/SpringSecurityPasswordValidationCallbackHandlerTest.java deleted file mode 100644 index 41b1cea2..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/callback/SpringSecurityPasswordValidationCallbackHandlerTest.java +++ /dev/null @@ -1,81 +0,0 @@ -/* - * Copyright 2005-2012 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.callback; - -import java.util.Collection; -import java.util.Collections; - -import org.springframework.security.core.Authentication; -import org.springframework.security.core.GrantedAuthority; -import org.springframework.security.core.authority.SimpleGrantedAuthority; -import org.springframework.security.core.context.SecurityContext; -import org.springframework.security.core.context.SecurityContextHolder; -import org.springframework.security.core.userdetails.User; -import org.springframework.security.core.userdetails.UserDetails; -import org.springframework.security.core.userdetails.UserDetailsService; - -import org.apache.ws.security.WSUsernameTokenPrincipal; -import org.junit.Assert; -import org.junit.Before; -import org.junit.Test; - -import static org.easymock.EasyMock.*; - -/** @author tareq */ -public class SpringSecurityPasswordValidationCallbackHandlerTest { - - private SpringSecurityPasswordValidationCallbackHandler callbackHandler; - - private SimpleGrantedAuthority grantedAuthority; - - private UsernameTokenPrincipalCallback callback; - - private UserDetails user; - - @Before - public void setUp() throws Exception { - callbackHandler = new SpringSecurityPasswordValidationCallbackHandler(); - - grantedAuthority = new SimpleGrantedAuthority("ROLE_1"); - user = new User("Ernie", "Bert", true, true, true, true, Collections.singleton(grantedAuthority)); - - WSUsernameTokenPrincipal principal = new WSUsernameTokenPrincipal("Ernie", true); - callback = new UsernameTokenPrincipalCallback(principal); - } - - @Test - public void testHandleUsernameTokenPrincipal() throws Exception { - UserDetailsService userDetailsService = createMock(UserDetailsService.class); - callbackHandler.setUserDetailsService(userDetailsService); - - expect(userDetailsService.loadUserByUsername("Ernie")).andReturn(user).anyTimes(); - - replay(userDetailsService); - - callbackHandler.handleUsernameTokenPrincipal(callback); - SecurityContext context = SecurityContextHolder.getContext(); - Assert.assertNotNull("SecurityContext must not be null", context); - Authentication authentication = context.getAuthentication(); - Assert.assertNotNull("Authentication must not be null", authentication); - Collection authorities = authentication.getAuthorities(); - Assert.assertTrue("GrantedAuthority[] must not be null or empty", - (authorities != null && authorities.size() > 0)); - Assert.assertEquals("Unexpected authority", grantedAuthority, authorities.iterator().next()); - - verify(userDetailsService); - } -} diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/support/CryptoFactoryBeanTest.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/support/CryptoFactoryBeanTest.java deleted file mode 100644 index ba8ca390..00000000 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j/support/CryptoFactoryBeanTest.java +++ /dev/null @@ -1,67 +0,0 @@ -/* - * Copyright 2005-2010 the original author or authors. - * - * Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -package org.springframework.ws.soap.security.wss4j.support; - -import java.util.Properties; - -import org.springframework.core.io.ClassPathResource; -import org.springframework.util.ClassUtils; - -import org.apache.ws.security.components.crypto.Merlin; -import org.junit.Assert; -import org.junit.Before; -import org.junit.Test; - -public class CryptoFactoryBeanTest { - - private CryptoFactoryBean factoryBean; - - @Before - public void setUp() throws Exception { - factoryBean = new CryptoFactoryBean(); - } - - @Test - public void testSetConfiguration() throws Exception { - Properties configuration = new Properties(); - configuration.setProperty("org.apache.ws.security.crypto.provider", - "org.apache.ws.security.components.crypto.Merlin"); - configuration.setProperty("org.apache.ws.security.crypto.merlin.keystore.type", "jceks"); - configuration.setProperty("org.apache.ws.security.crypto.merlin.keystore.password", "123456"); - configuration.setProperty("org.apache.ws.security.crypto.merlin.file", "private.jks"); - - factoryBean.setConfiguration(configuration); - factoryBean.setBeanClassLoader(ClassUtils.getDefaultClassLoader()); - factoryBean.afterPropertiesSet(); - - Object result = factoryBean.getObject(); - Assert.assertNotNull("No result", result); - Assert.assertTrue("Not a Merlin instance", result instanceof Merlin); - } - - @Test - public void testProperties() throws Exception { - factoryBean.setKeyStoreType("jceks"); - factoryBean.setKeyStorePassword("123456"); - factoryBean.setKeyStoreLocation(new ClassPathResource("private.jks")); - factoryBean.setBeanClassLoader(ClassUtils.getDefaultClassLoader()); - factoryBean.afterPropertiesSet(); - Object result = factoryBean.getObject(); - Assert.assertNotNull("No result", result); - Assert.assertTrue("Not a Merlin instance", result instanceof Merlin); - } -} \ No newline at end of file diff --git a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j2/Wss4jTestCase.java b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j2/Wss4jTestCase.java index 2bdeeee2..9c0d7221 100644 --- a/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j2/Wss4jTestCase.java +++ b/spring-ws-security/src/test/java/org/springframework/ws/soap/security/wss4j2/Wss4jTestCase.java @@ -27,6 +27,13 @@ import javax.xml.stream.XMLInputFactory; import javax.xml.stream.XMLStreamReader; import javax.xml.transform.dom.DOMSource; +import org.apache.axiom.soap.SOAP12Constants; +import org.apache.axiom.soap.impl.builder.StAXSOAPModelBuilder; +import org.junit.Assert; +import org.junit.Before; +import org.w3c.dom.Document; +import org.w3c.dom.Node; + import org.springframework.core.io.ClassPathResource; import org.springframework.core.io.Resource; import org.springframework.ws.WebServiceMessage; @@ -43,14 +50,7 @@ import org.springframework.ws.soap.saaj.SaajSoapMessageFactory; import org.springframework.xml.transform.StringSource; import org.springframework.xml.xpath.Jaxp13XPathTemplate; -import org.apache.axiom.soap.SOAP12Constants; -import org.apache.axiom.soap.impl.builder.StAXSOAPModelBuilder; -import org.junit.Assert; -import org.junit.Before; -import org.w3c.dom.Document; -import org.w3c.dom.Node; - -import static org.junit.Assert.assertTrue; +import static org.junit.Assert.*; public abstract class Wss4jTestCase { diff --git a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppMessageReceiver.java b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppMessageReceiver.java index 5b967dde..a04f4587 100644 --- a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppMessageReceiver.java +++ b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppMessageReceiver.java @@ -64,7 +64,11 @@ public class XmppMessageReceiver extends AbstractStandaloneMessageReceiver { @Override protected void onActivate() throws XMPPException, IOException, SmackException { if (!connection.isConnected()) { - connection.connect(); + try { + connection.connect(); + } catch (InterruptedException e) { + throw new IOException(e); + } } } @@ -100,7 +104,7 @@ public class XmppMessageReceiver extends AbstractStandaloneMessageReceiver { private class WebServicePacketListener implements StanzaListener { @Override - public void processPacket(Stanza packet) { + public void processStanza(Stanza packet) { logger.info("Received " + packet); if (packet instanceof Message) { Message message = (Message) packet; diff --git a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppReceiverConnection.java b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppReceiverConnection.java index 578ef85e..747aaedf 100644 --- a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppReceiverConnection.java +++ b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppReceiverConnection.java @@ -145,6 +145,8 @@ public class XmppReceiverConnection extends AbstractReceiverConnection { connection.sendStanza(responseMessage); } catch (SmackException.NotConnectedException e) { throw new IOException(e); + } catch (InterruptedException e) { + throw new IOException(e); } } } diff --git a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppSenderConnection.java b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppSenderConnection.java index 37d2efdb..ab946889 100644 --- a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppSenderConnection.java +++ b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/XmppSenderConnection.java @@ -23,8 +23,8 @@ import java.net.URI; import java.net.URISyntaxException; import java.util.Iterator; -import org.jivesoftware.smack.PacketCollector; import org.jivesoftware.smack.SmackException; +import org.jivesoftware.smack.StanzaCollector; import org.jivesoftware.smack.XMPPConnection; import org.jivesoftware.smack.filter.AndFilter; import org.jivesoftware.smack.filter.StanzaFilter; @@ -32,6 +32,8 @@ import org.jivesoftware.smack.filter.StanzaTypeFilter; import org.jivesoftware.smack.filter.ThreadFilter; import org.jivesoftware.smack.packet.Message; import org.jivesoftware.smack.packet.Stanza; +import org.jxmpp.jid.impl.JidCreate; +import org.jxmpp.stringprep.XmppStringprepException; import org.springframework.util.Assert; import org.springframework.ws.WebServiceMessage; @@ -64,7 +66,11 @@ public class XmppSenderConnection extends AbstractSenderConnection { Assert.hasLength(to, "'to' must not be empty"); Assert.hasLength(thread, "'thread' must not be empty"); this.connection = connection; - this.requestMessage = new Message(to, Message.Type.chat); + try { + this.requestMessage = new Message(JidCreate.from(to), Message.Type.chat); + } catch (XmppStringprepException e) { + throw new RuntimeException(e); + } this.requestMessage.setThread(thread); } @@ -134,6 +140,8 @@ public class XmppSenderConnection extends AbstractSenderConnection { connection.sendStanza(requestMessage); } catch (SmackException.NotConnectedException e) { throw new IOException(e); + } catch (InterruptedException e) { + throw new IOException(e); } } @@ -145,14 +153,17 @@ public class XmppSenderConnection extends AbstractSenderConnection { protected void onReceiveBeforeRead() throws IOException { StanzaFilter packetFilter = createPacketFilter(); - PacketCollector collector = connection.createPacketCollector(packetFilter); - Stanza packet = receiveTimeout >= 0 ? collector.nextResult(receiveTimeout) : collector.nextResult(); - if (packet instanceof Message) { - responseMessage = (Message) packet; - } - else if (packet != null) { - throw new IllegalArgumentException( - "Wrong packet type: [" + packet.getClass() + "]. Only Messages can be handled."); + StanzaCollector collector = connection.createStanzaCollector(packetFilter); + try { + Stanza packet = receiveTimeout >= 0 ? collector.nextResult(receiveTimeout) : collector.nextResult(); + if (packet instanceof Message) { + responseMessage = (Message) packet; + } else if (packet != null) { + throw new IllegalArgumentException( + "Wrong packet type: [" + packet.getClass() + "]. Only Messages can be handled."); + } + } catch (InterruptedException e) { + throw new IOException(e); } } diff --git a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppConnectionFactoryBean.java b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppConnectionFactoryBean.java index 83da23f0..de59b080 100644 --- a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppConnectionFactoryBean.java +++ b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppConnectionFactoryBean.java @@ -22,6 +22,8 @@ import org.jivesoftware.smack.SmackException; import org.jivesoftware.smack.XMPPException; import org.jivesoftware.smack.tcp.XMPPTCPConnection; import org.jivesoftware.smack.tcp.XMPPTCPConnectionConfiguration; +import org.jxmpp.jid.parts.Resourcepart; +import org.jxmpp.stringprep.XmppStringprepException; import org.springframework.beans.factory.DisposableBean; import org.springframework.beans.factory.FactoryBean; @@ -94,12 +96,15 @@ public class XmppConnectionFactoryBean implements FactoryBean Assert.hasText(password, "'password' must not be empty"); connection = new XMPPTCPConnection(configuration); - connection.connect(); - if (StringUtils.hasText(resource)) { - connection.login(username, password, resource); - } - else { - connection.login(username, password); + try { + connection.connect(); + if (StringUtils.hasText(resource)) { + connection.login(username, password, Resourcepart.from(resource)); + } else { + connection.login(username, password); + } + } catch (InterruptedException e) { + throw new IOException(e); } } @@ -130,13 +135,13 @@ public class XmppConnectionFactoryBean implements FactoryBean * @param port the port to connect to * @param serviceName the name of the service to connect to. May be {@code null} */ - protected XMPPTCPConnectionConfiguration createConnectionConfiguration(String host, int port, String serviceName) { + protected XMPPTCPConnectionConfiguration createConnectionConfiguration(String host, int port, String serviceName) throws XmppStringprepException { Assert.hasText(host, "'host' must not be empty"); if (StringUtils.hasText(serviceName)) { return XMPPTCPConnectionConfiguration.builder() .setHost(host) .setPort(port) - .setServiceName(serviceName) + .setXmppDomain(serviceName) .build(); } else { diff --git a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppTransportUtils.java b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppTransportUtils.java index 8935ea3d..2e113ad3 100644 --- a/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppTransportUtils.java +++ b/spring-ws-support/src/main/java/org/springframework/ws/transport/xmpp/support/XmppTransportUtils.java @@ -42,7 +42,8 @@ public abstract class XmppTransportUtils { * Converts the given XMPP destination into a {@code xmpp} URI. */ public static URI toUri(Message requestMessage) throws URISyntaxException { - return new URI(XmppTransportConstants.XMPP_URI_SCHEME, requestMessage.getTo(), null); + return new URI(XmppTransportConstants.XMPP_URI_SCHEME, + requestMessage.getTo().asDomainFullJidIfPossible().asUnescapedString(), null); } public static String getTo(URI uri) { diff --git a/spring4-next-profile.gradle b/spring4-next-profile.gradle deleted file mode 100644 index 3327151f..00000000 --- a/spring4-next-profile.gradle +++ /dev/null @@ -1,6 +0,0 @@ -/** - * Enable with "-Pprofile=spring4-next" - */ - -ext.springVersion = "4.3.10.RELEASE" -ext.springSecurityVersion = "4.2.3.RELEASE" \ No newline at end of file diff --git a/spring5-profile.gradle b/spring5-profile.gradle deleted file mode 100644 index 316447d2..00000000 --- a/spring5-profile.gradle +++ /dev/null @@ -1,15 +0,0 @@ -/** - * Enable with "-Pprofile=spring5" - */ - -ext.springVersion = "5.0.0.BUILD-SNAPSHOT" -ext.springSecurityVersion = "4.2.4.BUILD-SNAPSHOT" - -compileJava { - sourceCompatibility=1.8 - targetCompatibility=1.8 -} - -repositories { - maven { url 'https://repo.spring.io/libs-snapshot' } -} diff --git a/springnext-profile.gradle b/springnext-profile.gradle new file mode 100644 index 00000000..faa8ad55 --- /dev/null +++ b/springnext-profile.gradle @@ -0,0 +1,10 @@ +/** + * Enable with "-Pprofile=spring5" + */ + +ext.springVersion = "5.0.1.BUILD-SNAPSHOT" +ext.springSecurityVersion = "5.0.0.BUILD-SNAPSHOT" + +repositories { + maven { url 'https://repo.spring.io/libs-snapshot' } +}