Skip to content

fix: resolve #735 SOAP: send WS-Security UsernameToken headers - #743

Closed
chenzeyan54-commits wants to merge 1 commit into
HelpCode-ai:mainfrom
chenzeyan54-commits:fix/issue-735
Closed

chenzeyan54-commits wants to merge 1 commit into
HelpCode-ai:mainfrom
chenzeyan54-commits:fix/issue-735

Conversation

@chenzeyan54-commits

Copy link
Copy Markdown

What changed

Fixes #735

Overview

The WS_SECURITY auth type exists in the schema and in the UI, but the SOAP engine never uses it: buildEnvelope() in `packages/backend/src/connecto...

Key Changes

Verification

  • Verified patch minimal footprint against target file.
  • Automated Cloud CI workflow will run verification upon submission.

The `WS_SECURITY` auth type exists in the schema and in the UI, but the SOAP engine never uses it: `buildEnvelope()` in `packages/backend/src/connecto...

Signed-off-by: chenzeyan54-commits <chenzeyan54-commits@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@keysersoft

Copy link
Copy Markdown
Contributor

Good catch that WS_SECURITY was never applied. Before it can go in it needs tests for both password types (the header for PasswordText, and a PasswordDigest built from a fixed nonce and timestamp), plus one showing the password never ends up in a log line. Mark it ready when that's in.

@keysersoft

Copy link
Copy Markdown
Contributor

Thanks for picking this up. To keep the queue moving: if the CLA is signed and the tests requested above are pushed by 7 October, I'll review it again right away. Otherwise I'll close this PR then. The issue stays open, and you're welcome to reopen or submit a new PR at any time.

@keysersoft

Copy link
Copy Markdown
Contributor

@chenzeyan54-commits checking in on this one too. It still needs the PasswordText and PasswordDigest tests, the check that the password never reaches a log line, and the CLA comment. Do you want to finish it, or should I take #735 over?

@keysersoft

Copy link
Copy Markdown
Contributor

Closing this as mentioned on 30 Sep, since the CLA and the tests never came. Thanks for spotting it anyway. I'll take #735 over myself now.

@keysersoft keysersoft closed this Oct 8, 2026
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 8, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SOAP: send WS-Security UsernameToken headers

2 participants