oscerd opened a new pull request, #27118:
URL: https://github.com/apache/camel/pull/27118

   ## What
   
   `OAuthCodeFlowProcessor.getPostLoginUrl()` rebuilt the absolute post-login 
URL from the `X-Forwarded-Proto` / `X-Forwarded-Host` / `X-Forwarded-Port` 
request headers, stored it in the OAuth session, and `OAuthCodeFlowCallback` 
later emitted it as the `Location` header of the post-login redirect. Those 
headers are set by the caller, as is the `Host` header behind 
`Exchange.HTTP_URL` used by the other branch, so the redirect could be pointed 
at an arbitrary origin.
   
   The URL is now always built from the origin (`scheme://host[:port]`, default 
port omitted) of the operator-controlled `camel.oauth.redirect-uri`, plus the 
path of the current request. The request path is reduced to path + query, so an 
absolute or protocol-relative `CamelHttpUri` cannot move the redirect either.
   
   ## CAMEL-21899 is preserved
   
   The `X-Forwarded-*` reconstruction was added deliberately in edb78e8fafd6 
(CAMEL-21899) so that a deployment behind an OpenShift Route or an Ingress 
redirects to its externally reachable address rather than the internally 
observed one. That still holds, by construction: `camel.oauth.redirect-uri` 
**is** the external address — it is the URL the identity provider sends the 
browser back to.
   
   The `X-Forwarded-*` parsing is kept, but **only to log a warning** when the 
origin the caller announces differs from the configured one; it cannot 
influence the URL. The warning is worth keeping because that mismatch is the 
usual symptom of `camel.oauth.redirect-uri` not naming the address the browser 
actually reaches. Only the first entry of a comma-separated `X-Forwarded-Host` 
/ `X-Forwarded-Proto` is considered there, since chained proxies append to 
those headers.
   
   ## Notes for reviewers
   
   - `getPostLoginUrl` changed from `private (Message)` to package-private 
`(Exchange)` so it can be unit-tested without an identity provider.
   - An unparsable `camel.oauth.redirect-uri` now throws 
`IllegalStateException` rather than degrading silently. The property is 
operator-controlled and such a value would be rejected by the IdP anyway, but 
it is a new failure mode.
   - On the matching path the returned URL is the *normalised* origin rather 
than `HTTP_URL` verbatim (e.g. an explicitly written `:443` is dropped). 
Byte-identical for a normal single-origin deployment.
   - The container-based Keycloak tests (`OAuthCodeFlowServletTest`, 
`OAuthCodeFlowVertxTest`) were skipped locally, so the end-to-end proxied 
scenario is covered by CI rather than by the local run. They configure 
`CAMEL_OAUTH_REDIRECT_URI` to the same origin the test server listens on, so 
they should be unaffected.
   
   ## Testing
   
   New `OAuthCodeFlowPostLoginUrlTest`, 14 tests: matching origin, non-default 
port, default port omitted, non-matching host / scheme / port each confined, 
comma-separated `X-Forwarded-Host` (both good-first and evil-first), no 
forwarded headers with matching and with foreign `HTTP_URL`, no headers at all, 
protocol-relative `CamelHttpUri`, query preserved, unparsable redirect-uri 
rejected.
   
   `mvn test` in `components/camel-oauth`: **155 run, 0 failures, 0 errors, 7 
skipped** (the skips are the pre-existing Testcontainers tests). Module follows 
JUnit assertions (11 files vs 1 AssertJ), so the new test does too, per 
`CLAUDE.md`.
   
   Upgrade-guide entry added to `camel-4x-upgrade-guide-4_23.adoc`.
   
   https://issues.apache.org/jira/browse/CAMEL-25162
   
   ---
   _Claude Code on behalf of @oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to