This is an automated email from the ASF dual-hosted git repository.
davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new 029b2d80e4dd CAMEL-24444: camel-xmlsecurity - correct the comment on a
Reference without a URI (#27006)
029b2d80e4dd is described below
commit 029b2d80e4dd4c8a6e077271fa0cf825ec7d612b
Author: Claus Ibsen <[email protected]>
AuthorDate: Mon Sep 28 22:43:16 2026 +0200
CAMEL-24444: camel-xmlsecurity - correct the comment on a Reference without
a URI (#27006)
XMLDSig does not give an omitted URI a referent - only URI="" is the whole
document - and a signature whose references are all absent or external is
left alone rather than rejected. The comment said the opposite on both
counts.
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
Signed-off-by: Claus Ibsen <[email protected]>
---
.../component/xmlsecurity/api/DefaultXmlSignature2Message.java | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git
a/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
b/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
index 9bff7be67307..3b1f7276c9c5 100644
---
a/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
+++
b/components/camel-xmlsecurity/src/main/java/org/apache/camel/component/xmlsecurity/api/DefaultXmlSignature2Message.java
@@ -386,10 +386,10 @@ public class DefaultXmlSignature2Message implements
XmlSignature2Message {
for (Reference reference : references) {
String uri = reference.getURI();
if (uri == null) {
- // Absent URI (getURI() == null per JSR-105) identifies the
whole document per the XML Signature
- // spec, the same as URI="". However, treating it as
whole-document coverage here would let an
- // attacker bypass the check by attaching a null-URI
reference, so we skip it conservatively:
- // a lone absent-URI reference leaves
sameDocumentReferenceSeen false and the document is rejected.
+ // An absent URI tells us nothing about this document: XMLDSig
leaves its referent to the application,
+ // unlike URI="", which is the whole document. Like an
external reference below, it must not
+ // short-circuit the check for the references that follow it.
A signature whose references are all
+ // absent or external leaves sameDocumentReferenceSeen false
and is left alone, as described above.
continue;
}
if (uri.isEmpty()) {