This is an automated email from the ASF dual-hosted git repository.

davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new 029b2d80e4dd CAMEL-24444: camel-xmlsecurity - correct the comment on a 
Reference without a URI (#27006)
029b2d80e4dd is described below

commit 029b2d80e4dd4c8a6e077271fa0cf825ec7d612b
Author: Claus Ibsen <[email protected]>
AuthorDate: Mon Sep 28 22:43:16 2026 +0200

    CAMEL-24444: camel-xmlsecurity - correct the comment on a Reference without 
a URI (#27006)
    
    XMLDSig does not give an omitted URI a referent - only URI="" is the whole
    document - and a signature whose references are all absent or external is
    left alone rather than rejected. The comment said the opposite on both 
counts.
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
    Signed-off-by: Claus Ibsen <[email protected]>
---
 .../component/xmlsecurity/api/DefaultXmlSignature2Message.java    | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git 
a/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
 
b/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
index 9bff7be67307..3b1f7276c9c5 100644
--- 
a/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
+++ 
b/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
@@ -386,10 +386,10 @@ public class DefaultXmlSignature2Message implements 
XmlSignature2Message {
         for (Reference reference : references) {
             String uri = reference.getURI();
             if (uri == null) {
-                // Absent URI (getURI() == null per JSR-105) identifies the 
whole document per the XML Signature
-                // spec, the same as URI="". However, treating it as 
whole-document coverage here would let an
-                // attacker bypass the check by attaching a null-URI 
reference, so we skip it conservatively:
-                // a lone absent-URI reference leaves 
sameDocumentReferenceSeen false and the document is rejected.
+                // An absent URI tells us nothing about this document: XMLDSig 
leaves its referent to the application,
+                // unlike URI="", which is the whole document. Like an 
external reference below, it must not
+                // short-circuit the check for the references that follow it. 
A signature whose references are all
+                // absent or external leaves sameDocumentReferenceSeen false 
and is left alone, as described above.
                 continue;
             }
             if (uri.isEmpty()) {

Reply via email to