使用UsernameToken保护WS客户端(SOAP安全标头)

时间:2011-01-04 12:41:02

标签: java web-services jax-ws

我正在尝试保护我的WS客户端能够调用WS 我的代码如下所示:

            SendSmsService smsService = new SendSmsService();
SendSms sendSMS = smsService.getSendSms();  
BindingProvider stub = (BindingProvider)sendSMS;

//Override endpoint with local copy of wsdl.
String URL ="";//here is the wsdl url
Map<String,Object> requestContext = stub.getRequestContext();
requestContext.put(BindingProvider.ENDPOINT_ADDRESS_PROPERTY, URL);

//Set usernametoken
URL fileURL = loader.getResource("client-config.xml");
File file = new File(fileURL.getFile());

FileInputStream clientConfig = null;
try {
 clientConfig = new FileInputStream(file);
} catch (FileNotFoundException e) {
 e.printStackTrace();
}

XWSSecurityConfiguration config = null;
try {
 config = SecurityConfigurationFactory.newXWSSecurityConfiguration(clientConfig);
} catch (Exception e) {
 e.printStackTrace();
 log.warn("Exception: "+e.getMessage());
}
requestContext.put(XWSSecurityConfiguration.MESSAGE_SECURITY_CONFIGURATION, config);

//Invoke the web service

 String requestId = null;
 try {
  requestId = sendSMS.sendSms(addresses, senderName, charging, message,   receiptRequest);
 } catch (PolicyException e) {
  // TODO Auto-generated catch block
  e.printStackTrace();
 } catch (ServiceException e) {
  // TODO Auto-generated catch block
  e.printStackTrace();
 }

,配置文件如下所示:

<xwss:JAXRPCSecurity xmlns:xwss="http://java.sun.com/xml/ns/xwss/config"   optimize="true">
 <xwss:Service>
  <xwss:SecurityConfiguration dumpMessages="true"
   xmlns:xwss="http://java.sun.com/xml/ns/xwss/config">
    <xwss:UsernameToken name="username" password="password>
  </xwss:SecurityConfiguration>
 </xwss:Service>
 <xwss:SecurityEnvironmentHandler>
  util.SecurityEnvironmentHandler
</xwss:SecurityEnvironmentHandler>
</xwss:JAXRPCSecurity>

SecurityEnviromentHandler是一个实现javax.security.auth.callback.CallbackHandler的虚拟类。

身份验证必须符合Oasis Web Services安全性用户名令牌配置文件1.0 但我经常收到“安全标头无效”错误 哪里出错了,谁能告诉我 我使用了wsimport(JAX_WS 2.1为我的客户端生成类)
注意:我只知道关于这个WS的是WSDL URL和用户&amp; pass for authentication

1 个答案:

答案 0 :(得分:4)


我解决了这个问题。出错的是client-config.xml文件导致我不知道如何正确设置它。我遇到了这个例子并使用它:
http://www.javadb.com/using-a-message-handler-to-alter-the-soap-header-in-a-web-service-client
只需将链接上的这两个类复制到我的项目结构中并调用它们,如下所示:

SendSmsService smsService = new SendSmsService();
HeaderHandlerResolver handlerResolver = new HeaderHandlerResolver();
smsService.setHandlerResolver(handlerResolver);
SendSms sendSMS = smsService.getSendSms();

现在它完美无缺!