Skip to content

Conversation

@coheigea
Copy link
Contributor

@coheigea coheigea commented Dec 19, 2025

There are some valid use-cases where the data returned from the transform is null, as is the case for signing attachments in WSS4J where we work directly on the OutputStream. Currently this is logging a WARNING which is overkill, INFO seems more appropriate.

Note this is in the JSR-105 code.

@coheigea coheigea requested a review from seanjmullan December 19, 2025 15:52
@scantor
Copy link

scantor commented Dec 19, 2025

There are also signature exploits that leverage this sort of thing if the caller doesn't realize that nothing came back and was added to the digest. That's more of an issue with c14n, but...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants