[
https://issues.apache.org/jira/browse/CAMEL-24444?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen resolved CAMEL-24444.
---------------------------------
Resolution: Fixed
Merged to main for 4.23.0 via https://github.com/apache/camel/pull/26726
(commit 0a72858971ec2d581b41a5d58b129906d34a6c14). A follow-up corrects the
code comment on a Reference without a URI.
_Claude Code on behalf of davsclaus_
> camel-xmlsecurity - verifier output is not correlated with the validated
> signature References
> ---------------------------------------------------------------------------------------------
>
> Key: CAMEL-24444
> URL: https://issues.apache.org/jira/browse/CAMEL-24444
> Project: Camel
> Issue Type: Bug
> Components: camel-xmlsecurity
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> {{DefaultXmlSignature2Message.mapToMessage()}}, in the default
> (non-enveloping) branch:
> {code:java}
> // enveloped or detached XML signature --> remove signature element
> node = input.getMessageBodyDocument().getDocumentElement();
> removeSignatureElements = true;
> {code}
> {{XmlVerifierProcessor.verify()}} validates every {{ds:Signature}} and then
> calls {{map2Message}}, which emits the entire document root minus the
> Signature elements. The validated References are available on {{Input}}
> precisely so the output can be restricted to what they covered, but the
> default mapper does not use them. The {{XmlSignatureChecker}} hook that
> exists to close this gap is {{null}} by default.
> So content that was never covered by any validated Reference is passed
> downstream indistinguishably from content that was. {{URI=""}} enveloped
> signatures are unaffected, because the Reference covers the whole document.
> Proposal: in the default branch, emit only the nodes covered by the validated
> References, or fail when the document contains content outside them. If that
> is too strict a default, at minimum ship a default {{XmlSignatureChecker}}
> that enforces the correlation and document the trade-off. Needs an
> upgrade-guide entry.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)