oscerd commented on code in PR #26782: URL: https://github.com/apache/camel/pull/26782#discussion_r4122442399
########## docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc: ########## @@ -2805,6 +2805,17 @@ are unaffected. Routes that set the header by its literal string name, or that u `allowTemplateFromHeader=true` with the old header names, must switch to the new `Camel`-prefixed names. +=== camel-pqc - FileBasedKeyLifecycleManager restricts keyId to a flat file name + +`FileBasedKeyLifecycleManager` now confines every key file to its configured key directory. A `keyId` +(supplied through the `CamelPQCKeyId` / `CamelPQCNewKeyId` headers) that contains a forward slash, a +backslash, a null character, or that would otherwise resolve outside the key directory is now rejected +with an `IllegalArgumentException`. + +Previously a `keyId` such as `tenant-a/signing` resolved into a subdirectory of the key directory. +Deployments that organised keys that way must switch to a flat `keyId` (for example `tenant-a-signing`). +Only the file-based manager is affected; the in-memory and cloud-backed managers were never file-path +based. Review Comment: This is already in place. The comment was made against a890a26, where the `camel-pqc` section was the last one in the file. The merge of main (0361de7) put it before `=== camel-crypto`, with a blank line after `based.`. That merge also adds the blank line that was missing before `=== camel-debezium - a failed embedded engine is now reported`, which currently doesn't render as a heading on main. Both are in the PR diff. _Claude Code on behalf of @oscerd_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
