Skip to content

Fail fast when a SignedXml instance is reused #631

Description

@cjbarth

Split out of #409. In 6.3.3, #624 documents that each signature needs its own SignedXml. This issue is the change #409's reporter asked for: an error, instead of signatures that silently carry one more Reference each time. They only found out when responses grew large enough for their API gateway to reject them.

From #624's measurements on master:

Usage Result
one instance, addReference() before each of three documents 1, 2 and 3 Reference elements
one verifier, three documents checked every check passes; getSignedReferences() returns 1, 2, then 3 entries, including the earlier documents' content

To decide

  • Throw from addReference() when the instance already holds an equal reference, or
  • make an instance single-use, and throw when computeSignature() or checkSignature() is called a second time. That would also refuse signing several documents with the same references, which works correctly today.

The verifier row belongs in the same decision. getSignedReferences() is how the README tells callers to get the content a signature covers, and on a reused verifier it also returns content from documents checked earlier.

Why 7.0

Either option rejects calls that work today.

Activity

  1. added this to the v7.0 milestone on Sep 28, 2026
  2. added
    enhancementAdds a feature, option or export without breaking existing callers
    breaking-changeCan break existing callers; needs a major release. Stands alone or flags another kind
    on Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    breaking-changeCan break existing callers; needs a major release. Stands alone or flags another kindenhancementAdds a feature, option or export without breaking existing callerssemver-major

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions