Skip to main content

Hi,

I have a flow that offers some entry point protected by Basic Authentication implemented with th Spring module.

This is how the Security Manager is defined:

<spring:config name="Spring_Config" doc:name="Spring Config" doc:id="f4918a5e-67ef-4d54-b957-c44d74b063dd" files="beans.xml" />

 

<spring:security-manager doc:name="Spring Security manager" doc:id="4f6dbe4f-7b8f-462d-bc3b-845ff42d7192" >

 

<spring:delegate-security-provider name="auth-manager" delegate-ref="authenticationManager" />

 

</spring:security-manager>

It works but, if I upgrade the spring module from version 1.3.6 to version 1.4.0, this error occurs:

Element: delegate-security-provider is not allowed to be child of element Spring Security manager	apiugovqueries.xml	/apiugovqueries/src/main/mule	Spring Security manager	Message Flow Error

 

How can I solve this problem?

Thank you very much.

 

Claudio

16 件の回答
  1. 2025年3月3日 22:32

    I have opened case for this few months ago. After more detailed investigation I have found out that Studio ignores schema definitions declared in Spring file and instead of using them from proper locations on Internet to validate configuration it ignores original locations specified in XML and goes to outdated schema definition files that are inside Studio installation. On top of that, locations for schema namespaces might be incorrect in Spring XML. I requested that Mulesoft team corrects that behavior in Studio and it is not just to synch files, but Studio should never validate against local copies when XML contains full URL's to schema definition files on Internet when they are accessible. Doing it incorrectly through some substitute behavior is not what W3C meant when they created relevant RFC so, there is no valid excuse to have dangerous or confusing substitute behavior on XML files. Let's not reinvent wheel. Also accessibility of schema definition files is not excuse either. We in finance have to specifically whitelist URL's for Maven (typical technique is firewall override of certificates by local CA not recognized by Java) so, it can be done the same way everywhere in commercial enterprise including schema validation files on Internet.

0/9000