oscerd commented on code in PR #26782:
URL: https://github.com/apache/camel/pull/26782#discussion_r4122442399


##########
docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc:
##########
@@ -2805,6 +2805,17 @@ are unaffected. Routes that set the header by its 
literal string name, or that u
 `allowTemplateFromHeader=true` with the old header names, must switch to the 
new `Camel`-prefixed
 names.
 
+=== camel-pqc - FileBasedKeyLifecycleManager restricts keyId to a flat file 
name
+
+`FileBasedKeyLifecycleManager` now confines every key file to its configured 
key directory. A `keyId`
+(supplied through the `CamelPQCKeyId` / `CamelPQCNewKeyId` headers) that 
contains a forward slash, a
+backslash, a null character, or that would otherwise resolve outside the key 
directory is now rejected
+with an `IllegalArgumentException`.
+
+Previously a `keyId` such as `tenant-a/signing` resolved into a subdirectory 
of the key directory.
+Deployments that organised keys that way must switch to a flat `keyId` (for 
example `tenant-a-signing`).
+Only the file-based manager is affected; the in-memory and cloud-backed 
managers were never file-path
+based.

Review Comment:
   This is already in place. The comment was made against a890a26, where the 
`camel-pqc` section was the last one in the file. The merge of main (0361de7) 
put it before `=== camel-crypto`, with a blank line after `based.`. That merge 
also adds the blank line that was missing before `=== camel-debezium - a failed 
embedded engine is now reported`, which currently doesn't render as a heading 
on main. Both are in the PR diff.
   
   _Claude Code on behalf of @oscerd_
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to