This is an automated email from the ASF dual-hosted git repository.
oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new ccce87998af9 CAMEL-24650, CAMEL-24652: docs - sync the
fileNameExtWhitelist entry into the 4.22 and 4.18 upgrade guides (#27269)
ccce87998af9 is described below
commit ccce87998af9d4c818c9e0f658f22c16ac8757a0
Author: Andrea Cosentino <[email protected]>
AuthorDate: Fri Oct 2 11:27:26 2026 +0200
CAMEL-24650, CAMEL-24652: docs - sync the fileNameExtWhitelist entry into
the 4.22 and 4.18 upgrade guides (#27269)
The CAMEL-24650 and CAMEL-24652 fixes are being backported to camel-4.22.x
and
camel-4.18.x. Upgrade guides for all release lines live on main, so add the
matching entry under "Upgrading from 4.22.1 to 4.22.2" and "Upgrading from
4.18.4
to 4.18.5": fileNameExtWhitelist is now matched exactly by one shared
check, and
the two places that still matched extensions as a substring (the
camel-platform-http-vertx consumer, and DefaultHttpBinding for uploads that
arrive
as request attributes) now reject an upload whose extension only matched as
part of
a longer entry.
Signed-off-by: Andrea Cosentino <[email protected]>
Co-authored-by: Claude Opus 5.5 (1M context) <[email protected]>
---
.../modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc | 11 +++++++++++
.../modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc | 11 +++++++++++
2 files changed, 22 insertions(+)
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
index 31654c03c4c0..a0e136bbf307 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
@@ -48,6 +48,17 @@ Other SOAP response header attributes and elements are
mapped as before, and the
available in the `CamelSpringWebserviceSoapHeader` header. A route that relies
on the previous behaviour can supply a
custom `headerFilterStrategy` on the `spring-ws` endpoint.
+=== camel-http-common, camel-platform-http-vertx - fileNameExtWhitelist
entries are matched exactly
+
+`fileNameExtWhitelist` is now checked the same way everywhere, by one shared
check in `camel-http-base`. Two
+places still matched each extension as a substring of the whitelist, so for
example a whitelist of `txt`
+accepted an upload named `evil.x`: the `camel-platform-http-vertx` consumer,
and `DefaultHttpBinding` in
+`camel-http-common` for uploads that arrive as request attributes, which also
replaced the configured
+`fileNameExtWhitelist` with its lower-cased value. Both now compare each
comma-separated entry exactly and
+case-insensitively. `*` still accepts every file, a file name without an
extension is still accepted, and the
+configured value is left unchanged. An upload whose extension only matched as
part of a longer entry is now
+rejected.
+
=== camel-core - masking of sensitive values in endpoint URIs
`URISupport.sanitizeUri()`, which masks secrets in endpoint URIs shown in
logs, events, JMX names and error
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
index bb0b1e4ed9db..c9fd6ce14868 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
@@ -48,6 +48,17 @@ Other SOAP response header attributes and elements are
mapped as before, and the
available in the `CamelSpringWebserviceSoapHeader` header. A route that relies
on the previous behaviour can supply a
custom `headerFilterStrategy` on the `spring-ws` endpoint.
+=== camel-http-common, camel-platform-http-vertx - fileNameExtWhitelist
entries are matched exactly
+
+`fileNameExtWhitelist` is now checked the same way everywhere, by one shared
check in `camel-http-base`. Two
+places still matched each extension as a substring of the whitelist, so for
example a whitelist of `txt`
+accepted an upload named `evil.x`: the `camel-platform-http-vertx` consumer,
and `DefaultHttpBinding` in
+`camel-http-common` for uploads that arrive as request attributes, which also
replaced the configured
+`fileNameExtWhitelist` with its lower-cased value. Both now compare each
comma-separated entry exactly and
+case-insensitively. `*` still accepts every file, a file name without an
extension is still accepted, and the
+configured value is left unchanged. An upload whose extension only matched as
part of a longer entry is now
+rejected.
+
=== camel-core - masking of sensitive values in endpoint URIs
`URISupport.sanitizeUri()`, which masks secrets in endpoint URIs shown in
logs, events, JMX names and error