如何完善WSDL以生成符合WSSE规范的SOAP请求?
完善WSDL以生成带WS-Security的XML请求
要让WSDL生成包含wsu、wsse命名空间及PasswordText类型的请求,无需第三方注入,需在WSDL中显式定义WS-Security相关的结构和绑定策略,具体修改步骤如下:
1. 声明必要的命名空间
在WSDL的根definitions标签中添加WS-Security相关的命名空间:
<definitions xmlns:soap="http://schemas.xmlsoap.org/wsdl/soap/" xmlns:wsdl="http://schemas.xmlsoap.org/wsdl/" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsaw="http://www.w3.org/2006/05/addressing/wsdl" targetNamespace="你的服务目标命名空间">
2. 引入WS-Security的标准XSD
在WSDL的types部分引入官方的WS-Security Schema,避免重复定义类型:
<types> <xsd:schema> <xsd:import namespace="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" schemaLocation="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"/> <xsd:import namespace="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" schemaLocation="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"/> <!-- 你的服务原有类型定义 --> </xsd:schema> </types>
3. 在绑定中添加WS-Security策略
在binding部分的SOAP绑定里,添加WS-Security的策略断言,指定使用UsernameToken且密码类型为PasswordText:
<binding name="你的绑定名称" type="你的端口类型"> <soap:binding style="document" transport="http://schemas.xmlsoap.org/soap/http"/> <!-- 添加WS-Security策略 --> <wsp:Policy> <wsp:ExactlyOne> <wsp:All> <wsse:SecurityTokenPolicy> <wsse:TokenType>http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#UsernameToken</wsse:TokenType> <wsse:Usage>http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd#UsernameToken</wsse:Usage> <wsse:PasswordType>http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText</wsse:PasswordType> </wsse:SecurityTokenPolicy> </wsp:All> </wsp:ExactlyOne> </wsp:Policy> <!-- 你的操作绑定 --> <operation name="你的操作名称"> <soap:operation soapAction="你的SOAP动作"/> <input> <soap:body use="literal"/> <!-- 显式指定Security头 --> <soap:header message="wsse:Security" part="Security" use="literal"/> </input> <output> <soap:body use="literal"/> </output> </operation> </binding>
4. 定义包含Security头的消息
在WSDL的messages部分添加WS-Security的Security头消息:
<message name="Security"> <part name="Security" element="wsse:Security"/> </message>
验证修改后的效果
修改完成后,使用WSDL生成工具(如wsimport、soapUI)重新生成客户端代码,生成的请求应自动包含如下结构:
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"> <soapenv:Header> <wsse:Security soapenv:mustUnderstand="1"> <wsse:UsernameToken wsu:Id="UsernameToken-123"> <wsse:Username>你的用户名</wsse:Username> <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText">你的密码</wsse:Password> </wsse:UsernameToken> </wsse:Security> </soapenv:Header> <soapenv:Body> <!-- 你的请求体内容 --> </soapenv:Body> </soapenv:Envelope>
注意事项
- 确保生成工具支持WS-Policy和WS-Security的解析,部分轻量工具可能需要额外配置
- 如果无法引入外部XSD,可以将WS-Security的类型定义直接嵌入到WSDL的
types部分 - 若服务端要求特定的
wsu:Id或其他属性,可在策略中进一步指定约束
内容的提问来源于stack exchange,提问作者Avraam
相关产品推荐
相关产品推荐

