Apache CXF: Is it Possible to Set the Passwords without a CallbackHandler?

Viewed 199

I'm trying to call a web service enabled with WS Security using Apache CXF, but I'm running into a wall when trying to implement the Callbackhandler for inserting the password into a SOAP message. I understand the concept of interceptors in CXF, specifically the WSS4JOutInterceptor.

I'm using Spring Boot and I want to inject my properties into the Callbackhandler, but it's not working.

I would like to have something like:

public class UTPasswordCallback implements CallbackHandler {

@Autowired
MyProperties myProperties;

public void handle(Callback[] callbacks) throws IOException,
        UnsupportedCallbackException {        
    for (Callback callback : callbacks) {
        WSPasswordCallback wpc = (WSPasswordCallback) callback;
        if (wpc.getIdentifier().equals(myProperties.getUserName())) {
            wpc.setPassword(myProperties.getPassword());
            return;
        }
    }        
}   

This is what I have tried:

  1. Inject the properties into the Handler class
  2. Using @Autowired. This results in the properties being set to null.
  3. Using constructor injection. This results in an InstantiationException.
  4. Using a factory class to retrieve a static instance of the properties. This works, but it defeats the point of dependency injection in my opinion.

Is there a way to set the password directly using the interceptor? For username, I simply set it like:

props.put(WSHandlerConstants.USER, myProperties.getUserName());

Is there a similar construct for setting password or am I forced to use a Callbackhandler?

0 Answers
Related