SOAPUtil
Stub
WebReference
DID THIS ARTICLE SOLVE YOUR ISSUE?
Let us know so we can improve!
Let us know so we can improve!
Utility class for working with SOAP web services. This class provides methods for setting SOAP headers and a set of constants representing the supported header names.
If you want to use ws-security features, such as signing and encryption, with your RPC-style SOAP web service, use this class to construct a HashMap with security constants and values.
Note: this method handles sensitive security-related data. Pay special attention to PCI DSS v3. requirements 2, 4, and 12. The following example configures the ws-security actions taken for the request and response to a web service.
1importPackage( dw.system );
2importPackage( dw.util );
3importPackage( dw.rpc );
4
5
6function execute( args : PipelineDictionary ) : Number
7{
8 var WSU_NS : String = "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd";
9
10 try
11 {
12
13 // define a map with all the secrets
14 var secretsMap : Map = new HashMap();
15 secretsMap.put("myclientkey", "ckpass");
16 secretsMap.put("myservicekey", "ckpass");
17 secretsMap.put("username", "password");
18
19 var requestCfg : Map = new HashMap();
20
21 // define the ws actions to be performed
22 requestCfg.put(SOAPUtil.WS_ACTION, SOAPUtil.WS_USERNAME_TOKEN + " " +
23 SOAPUtil.WS_TIMESTAMP + " " +
24 SOAPUtil.WS_SIGNATURE + " " +
25 SOAPUtil.WS_ENCRYPT);
26 requestCfg.put(SOAPUtil.WS_USER, "username");
27 requestCfg.put(SOAPUtil.WS_PASSWORD_TYPE, SOAPUtil.WS_PW_DIGEST );
28 requestCfg.put(SOAPUtil.WS_SIG_DIGEST_ALGO, "http://www.w3.org/2001/04/xmlenc#sha256" );
29
30 // define signature properties
31 // the keystore file has the basename of the WSDL file and the
32 // file extension based on the keystore type (e.g. HelloWorld.jks).
33 // The keystore file has to be placed beside the WSDL file.
34 requestCfg.put(SOAPUtil.WS_SIG_PROP_KEYSTORE_TYPE, "jks");
35 requestCfg.put(SOAPUtil.WS_SIG_PROP_KEYSTORE_PW, "cspass");
36 requestCfg.put(SOAPUtil.WS_SIG_PROP_KEYSTORE_ALIAS, "myclientkey");
37
38 requestCfg.put(SOAPUtil.WS_SIGNATURE_USER, "myclientkey");
39
40 // define enrcryption properties
41 requestCfg.put(SOAPUtil.WS_ENC_PROP_KEYSTORE_TYPE, "jks");
42 requestCfg.put(SOAPUtil.WS_ENC_PROP_KEYSTORE_PW, "cspass");
43 requestCfg.put(SOAPUtil.WS_ENC_PROP_KEYSTORE_ALIAS, "myservicekey");
44
45 requestCfg.put(SOAPUtil.WS_ENCRYPTION_USER, "myservicekey");
46 requestCfg.put(SOAPUtil.WS_SIGNATURE_PARTS, "{Element}{http://schemas.xmlsoap.org/soap/envelope/}Body");
47 requestCfg.put(SOAPUtil.WS_ENCRYPTION_PARTS,"{Element}{" + WSU_NS + "}
48 Timestamp;"+"{Content}{http://schemas.xmlsoap.org/soap/envelope/}Body");
49
50 // set the secrets for the callback
51 requestCfg.put(SOAPUtil.WS_SECRETS_MAP, secretsMap);
52
53 var responseCfg : Map = new HashMap();
54
55 // define the ws actions to be performed for the response
56 responseCfg.put(SOAPUtil.WS_ACTION, SOAPUtil.WS_TIMESTAMP + " " +
57 SOAPUtil.WS_SIGNATURE + " " +
58 SOAPUtil.WS_ENCRYPT);
59
60 // define signature properties
61 responseCfg.put(SOAPUtil.WS_SIG_PROP_KEYSTORE_TYPE, "jks");
62 responseCfg.put(SOAPUtil.WS_SIG_PROP_KEYSTORE_PW, "cspass");
63 responseCfg.put(SOAPUtil.WS_SIG_PROP_KEYSTORE_ALIAS, "myservicekey");
64
65 responseCfg.put(SOAPUtil.WS_SIGNATURE_USER, "myservicekey");
66
67 // define decryption properties
68 responseCfg.put(SOAPUtil.WS_ENC_PROP_KEYSTORE_TYPE, "jks");
69 responseCfg.put(SOAPUtil.WS_ENC_PROP_KEYSTORE_PW, "cspass");
70 responseCfg.put(SOAPUtil.WS_ENC_PROP_KEYSTORE_ALIAS, "myclientkey");
71
72 responseCfg.put(SOAPUtil.WS_ENCRYPTION_USER, "myclientkey");
73
74 // set the secrets for the callback
75 responseCfg.put(SOAPUtil.WS_SECRETS_MAP, secretsMap);
76
77 // get the service and stub
78 var helloWorldService : WebReference = webreferences.HelloWorld;
79 var stub : Stub = helloWorldService.defaultService;
80 // set the security
81 SOAPUtil.setWSSecurityConfig(stub, requestCfg, responseCfg);
82 //var h : Hello = new helloWorldService.Hello();
83 var h = new helloWorldService.com.support.ws.security.test.Hello2();
84
85 h.setName('Send Text from client Axis ...');
86
87 // call the web service
88 var response = stub.hello2(h);
89 //var response = stub.hello(h);
90 var result = response.getHello2Return();
91
92
93 args.OutStr = result;
94 Logger.error("Hello World We Are SIGNED old version Send Text from client ...", result);
95
96 return PIPELET_NEXT;
97
98 }
99 catch (e)
100 {
101 Logger.error("Error in helloWorldRpc.ds is: " + e);
102 return PIPELET_ERROR;
103 }
104
105}See Also:
Deprecated:
This class is deprecated, please use webreferences2 instead (see also WSUtil).
Warning
| Constant | Description |
|---|---|
| WS-Security action property name. | |
| WS-Security action: encrypt the message. | |
| WS-Security encryption: defines which parts of the request are encrypted. | |
| WS-Security encryption: the user’s name for encryption. | |
| WS-Security encryption: the encryption/decryption keystore alias name | |
| WS-Security encryption: the encryption/decryption keystore password | |
| WS-Security encryption: the encryption/decryption keystore type ( jks or pkcs12 ), default is jks. | |
| WS-Security action: no security | |
| WS-Security password type: parameter for UsernameToken action to define the encoding of the password. | |
| WS-Security password of type digest: use a password digest to send the password information. | |
| WS-Security password of type text: send the password information in clear text. | |
| A secrets map with the username/password entries is needed to create the password callback object. | |
| WS-Security action: sign the message. | |
| WS-Security signature: defines which parts of the request are signed. | |
| WS-Security signature: the user’s name for signature. | |
| WS-Security signature: sets the signature digest algorithm to use. | |
| WS-Security signature: the signature keystore alias name | |
| WS-Security signature: the signature keystore password. | |
| WS-Security: the signature keystore type ( jks or pkcs12 ). | |
| WS-Security action: add a timestamp to the security header. | |
| WS-Security user name. | |
| WS-Security action: add a UsernameToken identification. |
| Constructor | Description |
|---|---|
| SOAPUtil() |
| Method | Description |
|---|---|
| Returns an HTTP request header property value using the specified key. | |
| Returns an HTTP response header property value using the specified key. | |
| Sets an HTTP request header property using the specified key and value. | |
| Sets a new SOAPHeaderElement in the SOAP request with the namespace of the XML content. | |
| Sets a new SOAPHeaderElement in the SOAP request with the namespace of the XML content. | |
| Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it. | |
| Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it. | |
| Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it. | |
| Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it. | |
| Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it. | |
| Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it. | |
| Sets the WS-Security configuration for the request and response based on the constants defined. |
assign, create, create, defineProperties, defineProperty, entries, freeze, fromEntries, getOwnPropertyDescriptor, getOwnPropertyNames, getOwnPropertySymbols, getPrototypeOf, hasOwnProperty, is, isExtensible, isFrozen, isPrototypeOf, isSealed, keys, preventExtensions, propertyIsEnumerable, seal, setPrototypeOf, toLocaleString, toString, valueOf, values
WS-Security action property name. Allowed property values are WS_NO_SECURITY, WS_TIMESTAMP, WS_ENCRYPT, WS_SIGNATURE, WS_USERNAME_TOKEN or a space separated String with multiple values.
Deprecated:
use webreferences2 instead
Warning
WS-Security action: encrypt the message. The encryption-specific parameters define how to encrypt, which keys to use, and other parameters.
Deprecated:
use webreferences2 instead
Warning
WS-Security encryption: defines which parts of the request are encrypted.
Deprecated:
use webreferences2 instead
Warning
WS-Security encryption: the user's name for encryption.
Deprecated:
use webreferences2 instead
Warning
WS-Security encryption: the encryption/decryption keystore alias name
Deprecated:
use webreferences2 instead
Warning
WS-Security encryption: the encryption/decryption keystore password
Deprecated:
use webreferences2 instead
Warning
WS-Security encryption: the encryption/decryption keystore type ( jks or pkcs12 ), default is jks.
Note: the keystore file must have the basename of the WSDL file and the file extension based on the keystore type. For example: MyService.jks. The keystore file must be placed in the same cartridge directory as the WSDL file.
Deprecated:
use webreferences2 instead
Warning
WS-Security action: no security
Deprecated:
use webreferences2 instead
Warning
WS-Security password type: parameter for UsernameToken action to define the encoding of the password. Allowed values are PW_DIGEST or PW_TEXT.
Deprecated:
use webreferences2 instead
Warning
WS-Security password of type digest: use a password digest to send the password information.
Deprecated:
use webreferences2 instead
Warning
WS-Security password of type text: send the password information in clear text.
Deprecated:
use webreferences2 instead
Warning
A secrets map with the username/password entries is needed to create the password callback object.
Deprecated:
use webreferences2 instead
Warning
WS-Security action: sign the message. The signature-specific parameters define how to sign, which keys to use, and other parameters.
Deprecated:
use webreferences2 instead
Warning
WS-Security signature: defines which parts of the request are signed.
Deprecated:
use webreferences2 instead
Warning
WS-Security signature: the user's name for signature.
Deprecated:
use webreferences2 instead
Warning
WS-Security signature: sets the signature digest algorithm to use.
Deprecated:
use webreferences2 instead
Warning
WS-Security signature: the signature keystore alias name
Deprecated:
use webreferences2 instead
Warning
WS-Security signature: the signature keystore password.
Deprecated:
use webreferences2 instead
Warning
WS-Security: the signature keystore type ( jks or pkcs12 ). The default is jks.
Note: The keystore file must have the basename of the WSDL file and the file extension of the keystore type. For example: MyService.jks. The keystore file must be placed in the same cartridge directory as the WSDL file.
Deprecated:
use webreferences2 instead
Warning
WS-Security action: add a timestamp to the security header.
Deprecated:
use webreferences2 instead
Warning
WS-Security user name.
Deprecated:
use webreferences2 instead
Warning
WS-Security action: add a UsernameToken identification.
Deprecated:
use webreferences2 instead
Warning
Returns an HTTP request header property value using the specified key. Null is returned if the key does not represent an HTTP header property.
Parameters:
Returns:
Deprecated:
use webreferences2 instead
Warning
Returns an HTTP response header property value using the specified key. Null is returned if the key does not represent an HTTP response header property.
Parameters:
Returns:
Deprecated:
use webreferences2 instead
Warning
Sets an HTTP request header property using the specified key and value.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Sets a new SOAPHeaderElement in the SOAP request with the namespace of the XML content.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Sets a new SOAPHeaderElement in the SOAP request with the namespace of the XML content.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it.
1var usernameToken : XML =
2 <wsse:UsernameToken xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
3 <wsse:Username>{merchantID}</wsse:Username>
4 <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText">
5 {merchantPassword}
6 </wsse:Password>
7 </wsse:UsernameToken>
8SOAPUtil.setHeader( service, "http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd",
9 "Security", usernameToken, true, nullParameters:
Deprecated:
use webreferences2 instead
Warning
Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Creates a new SOAPHeaderElement with the name and namespace and places the given XML into it.
Parameters:
Deprecated:
use webreferences2 instead
Warning
Sets the WS-Security configuration for the request and response based on the constants defined.
Parameters:
Deprecated:
use webreferences2 instead
Warning