Repository navigation
fix: resolve #735 SOAP: send WS-Security UsernameToken headers - #743
chenzeyan54-commits wants to merge 1 commit into
Conversation
The `WS_SECURITY` auth type exists in the schema and in the UI, but the SOAP engine never uses it: `buildEnvelope()` in `packages/backend/src/connecto... Signed-off-by: chenzeyan54-commits <chenzeyan54-commits@users.noreply.github.com>
|
I have read the CLA Document and I hereby sign the CLA You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot. |
|
Good catch that WS_SECURITY was never applied. Before it can go in it needs tests for both password types (the header for PasswordText, and a PasswordDigest built from a fixed nonce and timestamp), plus one showing the password never ends up in a log line. Mark it ready when that's in. |
|
Thanks for picking this up. To keep the queue moving: if the CLA is signed and the tests requested above are pushed by 7 October, I'll review it again right away. Otherwise I'll close this PR then. The issue stays open, and you're welcome to reopen or submit a new PR at any time. |
|
@chenzeyan54-commits checking in on this one too. It still needs the PasswordText and PasswordDigest tests, the check that the password never reaches a log line, and the CLA comment. Do you want to finish it, or should I take #735 over? |
|
Closing this as mentioned on 30 Sep, since the CLA and the tests never came. Thanks for spotting it anyway. I'll take #735 over myself now. |
What changed
Fixes #735
Overview
The
WS_SECURITYauth type exists in the schema and in the UI, but the SOAP engine never uses it:buildEnvelope()in `packages/backend/src/connecto...Key Changes
Verification