oscerd opened a new pull request, #27118: URL: https://github.com/apache/camel/pull/27118
## What `OAuthCodeFlowProcessor.getPostLoginUrl()` rebuilt the absolute post-login URL from the `X-Forwarded-Proto` / `X-Forwarded-Host` / `X-Forwarded-Port` request headers, stored it in the OAuth session, and `OAuthCodeFlowCallback` later emitted it as the `Location` header of the post-login redirect. Those headers are set by the caller, as is the `Host` header behind `Exchange.HTTP_URL` used by the other branch, so the redirect could be pointed at an arbitrary origin. The URL is now always built from the origin (`scheme://host[:port]`, default port omitted) of the operator-controlled `camel.oauth.redirect-uri`, plus the path of the current request. The request path is reduced to path + query, so an absolute or protocol-relative `CamelHttpUri` cannot move the redirect either. ## CAMEL-21899 is preserved The `X-Forwarded-*` reconstruction was added deliberately in edb78e8fafd6 (CAMEL-21899) so that a deployment behind an OpenShift Route or an Ingress redirects to its externally reachable address rather than the internally observed one. That still holds, by construction: `camel.oauth.redirect-uri` **is** the external address — it is the URL the identity provider sends the browser back to. The `X-Forwarded-*` parsing is kept, but **only to log a warning** when the origin the caller announces differs from the configured one; it cannot influence the URL. The warning is worth keeping because that mismatch is the usual symptom of `camel.oauth.redirect-uri` not naming the address the browser actually reaches. Only the first entry of a comma-separated `X-Forwarded-Host` / `X-Forwarded-Proto` is considered there, since chained proxies append to those headers. ## Notes for reviewers - `getPostLoginUrl` changed from `private (Message)` to package-private `(Exchange)` so it can be unit-tested without an identity provider. - An unparsable `camel.oauth.redirect-uri` now throws `IllegalStateException` rather than degrading silently. The property is operator-controlled and such a value would be rejected by the IdP anyway, but it is a new failure mode. - On the matching path the returned URL is the *normalised* origin rather than `HTTP_URL` verbatim (e.g. an explicitly written `:443` is dropped). Byte-identical for a normal single-origin deployment. - The container-based Keycloak tests (`OAuthCodeFlowServletTest`, `OAuthCodeFlowVertxTest`) were skipped locally, so the end-to-end proxied scenario is covered by CI rather than by the local run. They configure `CAMEL_OAUTH_REDIRECT_URI` to the same origin the test server listens on, so they should be unaffected. ## Testing New `OAuthCodeFlowPostLoginUrlTest`, 14 tests: matching origin, non-default port, default port omitted, non-matching host / scheme / port each confined, comma-separated `X-Forwarded-Host` (both good-first and evil-first), no forwarded headers with matching and with foreign `HTTP_URL`, no headers at all, protocol-relative `CamelHttpUri`, query preserved, unparsable redirect-uri rejected. `mvn test` in `components/camel-oauth`: **155 run, 0 failures, 0 errors, 7 skipped** (the skips are the pre-existing Testcontainers tests). Module follows JUnit assertions (11 files vs 1 AssertJ), so the new test does too, per `CLAUDE.md`. Upgrade-guide entry added to `camel-4x-upgrade-guide-4_23.adoc`. https://issues.apache.org/jira/browse/CAMEL-25162 --- _Claude Code on behalf of @oscerd_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
