oscerd commented on code in PR #27077:
URL: https://github.com/apache/camel/pull/27077#discussion_r4142069775


##########
components/camel-spiffe/src/main/docs/spiffe-component.adoc:
##########
@@ -88,6 +90,23 @@ from("direct:start")
     .to("http://backend.example.org/api";);
 ------------------------------------------------------------
 
+Validate an incoming bearer token on a `platform-http` route, without a bean 
to strip the scheme:
+
+[source,yaml]
+------------------------------------------------------------
+- from:
+    uri: "platform-http:/api"
+    steps:
+      # the Authorization: Bearer <token> header is picked up automatically
+      - to: 
"spiffe:auth?operation=validateJwtSvid&audience=spiffe://example.org/api"
+      # the token is a credential; drop it before the exchange goes further
+      - removeHeaders: "Authorization"
+      - to: "direct:handleRequest"
+------------------------------------------------------------
+
+A rejected token throws an `IllegalArgumentException`, so an 
`onException(IllegalArgumentException.class)` can answer

Review Comment:
   You're right — a rejected token throws 
`io.spiffe.exception.JwtSvidException` (which extends `java.lang.Exception`), 
not `IllegalArgumentException` (that is only the missing-token case). Fixed in 
2b52471: the note now says a missing token fails with 
`IllegalArgumentException` and a rejected one (invalid, expired, or wrong 
audience) with `JwtSvidException`, and the 401 handler catches both.
   
   _Claude Code on behalf of oscerd_



##########
components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java:
##########
@@ -72,9 +72,15 @@ private void validateJwtSvid(WorkloadApiClient client, 
Exchange exchange) throws
         if (ObjectHelper.isEmpty(token)) {
             token = exchange.getIn().getBody(String.class);
         }
+        if (ObjectHelper.isEmpty(token)) {
+            // last fallback: a JWT-SVID is presented over HTTP as 
"Authorization: Bearer <token>", so an HTTP route
+            // can validate it without a bean to strip the scheme
+            token = bearerToken(exchange.getIn().getHeader("Authorization", 
String.class));

Review Comment:
   Fixed the behaviour in 2b52471: `Authorization` is now checked before the 
body, so a POST/PUT request payload is no longer mistaken for the token (added 
`validateJwtSvidAuthorizationWinsOverBody`, which stubs only the bearer token 
and sets a body payload). I also documented that validation replaces the body 
with the `JwtSvid`, so the fallback fits requests whose payload is not needed 
afterwards (or the route keeps a copy before validating). Good call to fix it 
while the component is unreleased.
   
   _Claude Code on behalf of oscerd_



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to