[Axis2] - Use oauth 2.0 when making a Soap Request

Brian Bertram <[email protected]> Tue, 8 Aug 2023 19:23:02 +0000
Newsgroups gmane.text.xml.axis.user
Message-ID <DM6PR16MB24572E1D6C060D23983F7D728D0DA@DM6PR16MB2457.namprd16.prod.outlook.com>
--_000_DM6PR16MB24572E1D6C060D23983F7D728D0DADM6PR16MB2457namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

We are currently leveraging axis2 release 1.7.9 and rampart 1.7.1 to help w=
ith making soap calls.  We have working code that uses basic authentication=
 (username/password).



We are trying to update our program to use oAuth 2.0 instead of username:pa=
ssword.  We have it setup in the endpoint and we have the Client Id, Client=
 Secret and Refresh Token.  We updated the java code to remove the username=
:password from being set and added a Property for HEADER_AUTHORIZATION with=
 Bearer <access token we got back using the Client Id, Client Secret and Re=
fresh Token>.  No changes were made to the axis2.xml and policy.xml files.



If we run the java program the response back is an invalid username and pas=
sword error.  If we take the access token and the Soap request that was cre=
ated from the running of the program, which hits the invalid username or pa=
ssword error, and run it in SOAPUI and/or Postman the responses come back s=
uccessfully and with data as we would expect.



So I had a few Questions that I am not finding in the documentation.

Are the axis2.xml and/or policy.xml files needed for oauth?

If yes then are there updates needed to the axis2.xml and/or policy.xml to =
get oauth to work?

Are there other updates needed to the java code besides for setting the Hea=
der Authorization to have a value of Bearer <access token we got back using=
 the Client Id, Client Secret and Refresh Token>?

Thank you for the help


--_000_DM6PR16MB24572E1D6C060D23983F7D728D0DADM6PR16MB2457namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p style=3D"margin:0in">We are currently leveraging axis2 release 1.7.9 and=
 rampart 1.7.1 to help with making soap calls.&nbsp; We have working code t=
hat uses basic authentication (username/password).<o:p></o:p></p>
<p style=3D"mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margi=
n-left:27.0pt">
<o:p>&nbsp;</o:p></p>
<p style=3D"margin:0in">We are trying to update our program to use oAuth 2.=
0 instead of username:password.&nbsp; We have it setup in the endpoint and =
we have the Client Id, Client Secret and Refresh Token.&nbsp; We updated th=
e java code to remove the username:password
 from being set and added a Property for HEADER_AUTHORIZATION with Bearer &=
lt;access token we got back using the Client Id, Client Secret and Refresh =
Token&gt;.&nbsp; No changes were made to the axis2.xml and policy.xml files=
.<o:p></o:p></p>
<p style=3D"margin:0in">&nbsp;<o:p></o:p></p>
<p style=3D"margin:0in">If we run the java program the response back is an =
invalid username and password error.&nbsp; If we take the access token and =
the Soap request that was created from the running of the program, which hi=
ts the invalid username or password error,
 and run it in SOAPUI and/or Postman the responses come back successfully a=
nd with data as we would expect.<o:p></o:p></p>
<p style=3D"margin:0in"><o:p>&nbsp;</o:p></p>
<p style=3D"margin:0in">So I had a few Questions that I am not finding in t=
he documentation.<o:p></o:p></p>
<p style=3D"margin:0in">Are the axis2.xml and/or policy.xml files needed fo=
r oauth?
<o:p></o:p></p>
<p style=3D"margin:0in">If yes then are there updates needed to the axis2.x=
ml and/or policy.xml to get oauth to work?&nbsp;
<o:p></o:p></p>
<p style=3D"margin:0in">Are there other updates needed to the java code bes=
ides for setting the Header Authorization to have a value of Bearer &lt;acc=
ess token we got back using the Client Id, Client Secret and Refresh Token&=
gt;?<o:p></o:p></p>
<p class=3D"MsoNormal"><b><span style=3D"font-size:8.0pt;font-family:&quot;=
Arial&quot;,sans-serif;color:black"><o:p>&nbsp;</o:p></span></b></p>
<p class=3D"MsoNormal"><b><span style=3D"font-size:8.0pt;font-family:&quot;=
Arial&quot;,sans-serif;color:black">Thank you for the help</span></b><o:p><=
/o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_DM6PR16MB24572E1D6C060D23983F7D728D0DADM6PR16MB2457namp_--