oscerd commented on code in PR #27077:
URL: https://github.com/apache/camel/pull/27077#discussion_r4142069775
##########
components/camel-spiffe/src/main/docs/spiffe-component.adoc:
##########
@@ -88,6 +90,23 @@ from("direct:start")
.to("http://backend.example.org/api");
------------------------------------------------------------
+Validate an incoming bearer token on a `platform-http` route, without a bean
to strip the scheme:
+
+[source,yaml]
+------------------------------------------------------------
+- from:
+ uri: "platform-http:/api"
+ steps:
+ # the Authorization: Bearer <token> header is picked up automatically
+ - to:
"spiffe:auth?operation=validateJwtSvid&audience=spiffe://example.org/api"
+ # the token is a credential; drop it before the exchange goes further
+ - removeHeaders: "Authorization"
+ - to: "direct:handleRequest"
+------------------------------------------------------------
+
+A rejected token throws an `IllegalArgumentException`, so an
`onException(IllegalArgumentException.class)` can answer
Review Comment:
You're right — a rejected token throws
`io.spiffe.exception.JwtSvidException` (which extends `java.lang.Exception`),
not `IllegalArgumentException` (that is only the missing-token case). Fixed in
2b52471: the note now says a missing token fails with
`IllegalArgumentException` and a rejected one (invalid, expired, or wrong
audience) with `JwtSvidException`, and the 401 handler catches both.
_Claude Code on behalf of oscerd_
##########
components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java:
##########
@@ -72,9 +72,15 @@ private void validateJwtSvid(WorkloadApiClient client,
Exchange exchange) throws
if (ObjectHelper.isEmpty(token)) {
token = exchange.getIn().getBody(String.class);
}
+ if (ObjectHelper.isEmpty(token)) {
+ // last fallback: a JWT-SVID is presented over HTTP as
"Authorization: Bearer <token>", so an HTTP route
+ // can validate it without a bean to strip the scheme
+ token = bearerToken(exchange.getIn().getHeader("Authorization",
String.class));
Review Comment:
Fixed the behaviour in 2b52471: `Authorization` is now checked before the
body, so a POST/PUT request payload is no longer mistaken for the token (added
`validateJwtSvidAuthorizationWinsOverBody`, which stubs only the bearer token
and sets a body payload). I also documented that validation replaces the body
with the `JwtSvid`, so the fallback fits requests whose payload is not needed
afterwards (or the route keeps a copy before validating). Good call to fix it
while the component is unreleased.
_Claude Code on behalf of oscerd_
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]