This is an automated email from the ASF dual-hosted git repository.

oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new ccce87998af9 CAMEL-24650, CAMEL-24652: docs - sync the 
fileNameExtWhitelist entry into the 4.22 and 4.18 upgrade guides (#27269)
ccce87998af9 is described below

commit ccce87998af9d4c818c9e0f658f22c16ac8757a0
Author: Andrea Cosentino <[email protected]>
AuthorDate: Fri Oct 2 11:27:26 2026 +0200

    CAMEL-24650, CAMEL-24652: docs - sync the fileNameExtWhitelist entry into 
the 4.22 and 4.18 upgrade guides (#27269)
    
    The CAMEL-24650 and CAMEL-24652 fixes are being backported to camel-4.22.x 
and
    camel-4.18.x. Upgrade guides for all release lines live on main, so add the
    matching entry under "Upgrading from 4.22.1 to 4.22.2" and "Upgrading from 
4.18.4
    to 4.18.5": fileNameExtWhitelist is now matched exactly by one shared 
check, and
    the two places that still matched extensions as a substring (the
    camel-platform-http-vertx consumer, and DefaultHttpBinding for uploads that 
arrive
    as request attributes) now reject an upload whose extension only matched as 
part of
    a longer entry.
    
    Signed-off-by: Andrea Cosentino <[email protected]>
    Co-authored-by: Claude Opus 5.5 (1M context) <[email protected]>
---
 .../modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc       | 11 +++++++++++
 .../modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc       | 11 +++++++++++
 2 files changed, 22 insertions(+)

diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
index 31654c03c4c0..a0e136bbf307 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
@@ -48,6 +48,17 @@ Other SOAP response header attributes and elements are 
mapped as before, and the
 available in the `CamelSpringWebserviceSoapHeader` header. A route that relies 
on the previous behaviour can supply a
 custom `headerFilterStrategy` on the `spring-ws` endpoint.
 
+=== camel-http-common, camel-platform-http-vertx - fileNameExtWhitelist 
entries are matched exactly
+
+`fileNameExtWhitelist` is now checked the same way everywhere, by one shared 
check in `camel-http-base`. Two
+places still matched each extension as a substring of the whitelist, so for 
example a whitelist of `txt`
+accepted an upload named `evil.x`: the `camel-platform-http-vertx` consumer, 
and `DefaultHttpBinding` in
+`camel-http-common` for uploads that arrive as request attributes, which also 
replaced the configured
+`fileNameExtWhitelist` with its lower-cased value. Both now compare each 
comma-separated entry exactly and
+case-insensitively. `*` still accepts every file, a file name without an 
extension is still accepted, and the
+configured value is left unchanged. An upload whose extension only matched as 
part of a longer entry is now
+rejected.
+
 === camel-core - masking of sensitive values in endpoint URIs
 
 `URISupport.sanitizeUri()`, which masks secrets in endpoint URIs shown in 
logs, events, JMX names and error
diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
index bb0b1e4ed9db..c9fd6ce14868 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
@@ -48,6 +48,17 @@ Other SOAP response header attributes and elements are 
mapped as before, and the
 available in the `CamelSpringWebserviceSoapHeader` header. A route that relies 
on the previous behaviour can supply a
 custom `headerFilterStrategy` on the `spring-ws` endpoint.
 
+=== camel-http-common, camel-platform-http-vertx - fileNameExtWhitelist 
entries are matched exactly
+
+`fileNameExtWhitelist` is now checked the same way everywhere, by one shared 
check in `camel-http-base`. Two
+places still matched each extension as a substring of the whitelist, so for 
example a whitelist of `txt`
+accepted an upload named `evil.x`: the `camel-platform-http-vertx` consumer, 
and `DefaultHttpBinding` in
+`camel-http-common` for uploads that arrive as request attributes, which also 
replaced the configured
+`fileNameExtWhitelist` with its lower-cased value. Both now compare each 
comma-separated entry exactly and
+case-insensitively. `*` still accepts every file, a file name without an 
extension is still accepted, and the
+configured value is left unchanged. An upload whose extension only matched as 
part of a longer entry is now
+rejected.
+
 === camel-core - masking of sensitive values in endpoint URIs
 
 `URISupport.sanitizeUri()`, which masks secrets in endpoint URIs shown in 
logs, events, JMX names and error

Reply via email to