oscerd opened a new pull request, #25942: URL: https://github.com/apache/camel/pull/25942
Backport to `camel-4.18.x` of six fixes already reviewed and merged on `main`. Each is a case where data arriving from outside the route reached somewhere it should not have. - CAMEL-24455: camel-platform-http - select proxy mode by the exact path, not by prefix (#25833, `7abf13b2`) - CAMEL-24453: camel-platform-http - compare request header names case-insensitively when suppressing the echo (#25831, `126c79bd`) - CAMEL-24442: camel-thrift - unmarshal into a copy instead of the shared defaultInstance (#25823, `c52d3cfa`) - CAMEL-24423: camel-tika - filter parsed document metadata before mapping it to headers (#25819, `b6f6b470`) - CAMEL-24475: camel-xpath - parse an InputSource document type with the hardened XML parser (#25683, `1ead256f`) - CAMEL-24449: camel-core - only consult Long-Running-Action for a saga service that uses it (#25828, `dfde0031`) The same set is going to `camel-4.22.x` in #25940. Cherry-picked in the order they merged on `main`. Two mechanical adaptations for this branch, each folded into its own commit: - `camel-thrift/pom.xml`: the assertj test dependency is added alongside this branch's `junit-toolbox` entry rather than in its place. - `ThriftUnmarshalIsolationTest` and `TikaMetadataHeaderFilterTest` import `camel-test-junit5`; `main` is on junit6. The upgrade-guide entries are not included: the guides for every line live on `main`. Worth calling out for a patch release: - `documentType=InputSource` in camel-xpath now goes through the same hardened parser as the default document type, so a DOCTYPE in the payload is refused rather than resolved. The same `DocumentBuilderFactory` system properties that relaxed the default type still relax this one. - camel-tika no longer maps every parsed metadata key to a header. A route reading a metadata-derived header that the filter now blocks will see it missing. Built and tested per module on this branch (`core`, `camel-lra`, `camel-kafka`, `camel-platform-http`, `camel-thrift`, `camel-tika`, `camel-xpath`), including the new and touched tests. _Claude Code on behalf of oscerd_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
