You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在WSO2 ESB中使用Enrich Mediator添加Header内容

使用Enrich Mediator为SOAP Header添加WS-Security UsernameToken

Got it, let's walk through how to add that WS-Security UsernameToken section to your existing SOAP Header using the Enrich Mediator. Here's a practical breakdown with working config:

Step 1: Core Setup Logic

We'll use the Enrich Mediator to inject the <o:Security> node as a child of your existing <s:Header> (which already holds the <ActivityId>). The key is targeting the correct Header node and embedding the Security content with all required namespaces intact.

Step 2: Full Enrich Mediator Configuration

Drop this config into your sequence, and adjust the Username/Password and u:Id value to match your requirements:

<enrich>
    <!-- Source: Inline WS-Security UsernameToken content -->
    <source type="inline" clone="true">
        <o:Security s:mustUnderstand="1" 
                    xmlns:o="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" 
                    xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" 
                    xmlns:u="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
            <o:UsernameToken u:Id="uuid-05a278f7-0f...">
                <o:Username>your_service_username</o:Username>
                <o:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText">your_service_password</o:Password>
            </o:UsernameToken>
        </o:Security>
    </source>
    <!-- Target: Inject as child into existing SOAP Header -->
    <target xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" 
            action="child" 
            type="custom" 
            xpath="//s:Header"/>
</enrich>

Critical Details to Keep in Mind

  • Namespace Alignment: Make sure all prefixes (s, o, u) map to their standard namespaces. The s prefix matches the SOAP Envelope namespace used in your original Header.
  • clone="true": This avoids unexpected node reference issues when injecting content into the message.
  • action="child": This preserves your original <ActivityId> by adding the Security node as a child of the existing Header, instead of replacing the entire Header.
  • Dynamic u:Id: For production, generate a unique UUID for the u:Id on each request. Use the UUID Mediator to create this value dynamically and reference it via a property.
  • Password Security: If you need password digest (instead of plain text), change the Password element's Type to http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest and add the required <o:Nonce> and <u:Created> elements alongside the password hash.

Final Resulting SOAP Header

After applying this mediator, your combined Header will look like this:

<s:Header>
    <ActivityId xmlns="http://schemas.microsoft.com/2004/09/ServiceModel/Diagnostics" CorrelationId="10018d27-2573-4d6b-8bcb-b49f6c686f1a">5d827c1d-bd7b-437f-904f-5f82c9844022</ActivityId>
    <o:Security s:mustUnderstand="1" xmlns:o="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:u="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
        <o:UsernameToken u:Id="uuid-05a278f7-0f...">
            <o:Username>your_service_username</o:Username>
            <o:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText">your_service_password</o:Password>
        </o:UsernameToken>
    </o:Security>
</s:Header>

内容的提问来源于stack exchange,提问作者kanchetime

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:20:53