oscerd opened a new pull request, #26782:
URL: https://github.com/apache/camel/pull/26782

   ## What
   
   `FileBasedKeyLifecycleManager` resolved key file paths as 
`keyDirectory.resolve(keyId + suffix)` (`.private.json` / `.public.json` / 
`.metadata` / `.key`) with no check that the result stays within the configured 
directory. `keyId` arrives from the `CamelPQCKeyId` / `CamelPQCNewKeyId` 
headers (generateKeyPair / rotateKey / getKeyMetadata / expireKey / revokeKey / 
deleteKeyState), so a value containing path separators, parent references or an 
absolute path could resolve outside the directory.
   
   This adds a `resolveKeyFile(keyId, suffix)` helper that rejects 
null/blank/separator/NUL `keyId`s and verifies the normalized resolved path 
stays under the key directory, so all key-file operations are confined 
regardless of the supplied `keyId`. The cloud-backed managers 
(`AwsSecretsManagerKeyLifecycleManager` / `AzureKeyVaultKeyLifecycleManager`) 
build provider-side names validated server-side, so only the file-based manager 
needs filesystem confinement.
   
   ## Test
   
   Added `FileBasedKeyLifecycleManagerPathTest` covering parent-traversal, 
absolute, separator and blank `keyId`s (rejected; a file outside the directory 
stays untouched) and a plain `keyId` (accepted). `mvn clean install` on 
`camel-pqc` is green.
   
   JIRA: https://issues.apache.org/jira/browse/CAMEL-24937
   
   _Claude Code on behalf of oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to