oscerd opened a new pull request, #26782: URL: https://github.com/apache/camel/pull/26782
## What `FileBasedKeyLifecycleManager` resolved key file paths as `keyDirectory.resolve(keyId + suffix)` (`.private.json` / `.public.json` / `.metadata` / `.key`) with no check that the result stays within the configured directory. `keyId` arrives from the `CamelPQCKeyId` / `CamelPQCNewKeyId` headers (generateKeyPair / rotateKey / getKeyMetadata / expireKey / revokeKey / deleteKeyState), so a value containing path separators, parent references or an absolute path could resolve outside the directory. This adds a `resolveKeyFile(keyId, suffix)` helper that rejects null/blank/separator/NUL `keyId`s and verifies the normalized resolved path stays under the key directory, so all key-file operations are confined regardless of the supplied `keyId`. The cloud-backed managers (`AwsSecretsManagerKeyLifecycleManager` / `AzureKeyVaultKeyLifecycleManager`) build provider-side names validated server-side, so only the file-based manager needs filesystem confinement. ## Test Added `FileBasedKeyLifecycleManagerPathTest` covering parent-traversal, absolute, separator and blank `keyId`s (rejected; a file outside the directory stays untouched) and a plain `keyId` (accepted). `mvn clean install` on `camel-pqc` is green. JIRA: https://issues.apache.org/jira/browse/CAMEL-24937 _Claude Code on behalf of oscerd_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
