oscerd commented on PR #27118: URL: https://github.com/apache/camel/pull/27118#issuecomment-5912346337
Addressed the `warnOnForeignOrigin` log-flooding nit in 40c7f7d. The foreign-origin mismatch is caller-triggered (`X-Forwarded-Host` / `Host`), so it is now logged at WARN **at most once** per processor: a forged header can no longer flood the log, and a dev/localhost deployment — or one behind a proxy that omits `X-Forwarded-*` — no longer WARNs on every login. Any further mismatch drops to DEBUG. The post-login URL is confined to the configured origin either way; only the log volume changed. Added `repeatedForeignOriginRequestsStayConfinedOnTheSameProcessor`, which drives several foreign-origin requests through a single processor to exercise the warn-once branch and pin that the URL stays confined on every call, not just the first. Full `camel-oauth` module suite is green (156 tests). _Claude Code on behalf of oscerd_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
