You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在JavaEE服务端禁用WSS4J的TIMESTAMP_CACHE

解决方案:在JavaEE SOAP服务端禁用WSS4J的TIMESTAMP_CACHE

针对WSS4J v2.0.2的服务端场景,要禁用TIMESTAMP_CACHE,核心是给WSS4JInHandler(服务端入站安全处理器)设置enableTimestampCache参数为false,以下是两种常用实现方式:

1. 通过Handler Chain配置文件实现(推荐,解耦配置与代码)

创建handler-chain.xml配置文件,放在类路径下(比如src/main/resources),配置WSS4J入站处理器的参数:

<?xml version="1.0" encoding="UTF-8"?>
<handler-chains xmlns="http://java.sun.com/xml/ns/javaee">
  <handler-chain>
    <handler>
      <handler-name>WSS4JInHandler</handler-name>
      <handler-class>org.apache.ws.security.handler.WSS4JInHandler</handler-class>
      <!-- 禁用Timestamp缓存 -->
      <init-param>
        <param-name>enableTimestampCache</param-name>
        <param-value>false</param-value>
      </init-param>
      <!-- 其他WSS4J必要配置,比如消息安全动作、用户信息等 -->
      <init-param>
        <param-name>action</param-name>
        <param-value>Timestamp Signature</param-value>
      </init-param>
      <init-param>
        <param-name>user</param-name>
        <param-value>your-service-identity</param-value>
      </init-param>
    </handler>
  </handler-chain>
</handler-chains>

然后在你的Web服务实现类上添加@HandlerChain注解关联该配置:

import javax.jws.WebService;
import javax.jws.HandlerChain;

@WebService(endpointInterface = "com.your.package.YourServiceInterface")
@HandlerChain(file = "/handler-chain.xml")
public class YourServiceImpl implements YourServiceInterface {
    // 你的服务方法实现
}

2. 通过代码动态配置Endpoint

如果是通过代码发布服务,可以直接给WSS4JInHandler设置属性:

import javax.xml.ws.Endpoint;
import org.apache.ws.security.handler.WSS4JInHandler;
import java.util.HashMap;
import java.util.Map;

public class ServiceStarter {
    public static void main(String[] args) {
        String serviceUrl = "http://localhost:8080/your-soap-service";
        YourServiceImpl serviceInstance = new YourServiceImpl();

        // 初始化WSS4J入站处理器
        WSS4JInHandler wssInHandler = new WSS4JInHandler();
        Map<String, Object> securityProps = new HashMap<>();
        
        // 禁用Timestamp缓存
        securityProps.put("enableTimestampCache", "false");
        // 补充其他安全配置
        securityProps.put("action", "Timestamp Signature");
        securityProps.put("user", "your-service-user");
        
        wssInHandler.setProperties(securityProps);

        // 发布服务并添加处理器
        Endpoint endpoint = Endpoint.create(serviceInstance);
        endpoint.getBinding().getHandlerChain().add(wssInHandler);
        endpoint.publish(serviceUrl);
    }
}

注意事项

  • 禁用TIMESTAMP_CACHE会关闭WSS4J的重放攻击防护,确认业务场景允许后再操作;
  • 如果需要保留重放防护但避免文件缓存问题,可尝试配置WSS4J使用内存缓存实现(需自定义EHCacheTimestampsCache或其他内存缓存实现类),但这超出当前禁用需求的范围。

内容的提问来源于stack exchange,提问作者Pedro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 17:01:21