This is an automated email from the ASF dual-hosted git repository.

davsclaus pushed a commit to branch fix/CAMEL-24739
in repository https://gitbox.apache.org/repos/asf/camel-examples.git

commit 0b593accdabbd9a213e40261a90ee2c339320c2c
Author: Claus Ibsen <[email protected]>
AuthorDate: Fri Oct 2 14:51:16 2026 +0200

    CAMEL-24739: Fix the spiffe example for fetchX509Svid keeping the private 
key off the message
    
    Since CAMEL-24739, fetchX509Svid puts only the certificate chain on the 
body by default and the
    SPIFFE ID in the CamelSpiffeSpiffeId header. X509SvidSummary still expected 
an X509Svid, the bean
    call failed, the route's onException handled it, and IdentityRoutesTest saw 
the raw certificate
    instead of the summary.
    
    Describe the chain and the header instead, which follows the new default 
rather than opting back
    in to the private key with x509Response=svid. Update the route comment and 
the README.
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
    Claude-Session: https://claude.ai/code/session_01STT6whBgK1AqsSsUKrnE8m
---
 spiffe/README.adoc                                     |  8 ++++----
 .../apache/camel/example/spiffe/IdentityRoutes.java    |  6 +++---
 .../apache/camel/example/spiffe/X509SvidSummary.java   | 18 +++++++++++-------
 3 files changed, 18 insertions(+), 14 deletions(-)

diff --git a/spiffe/README.adoc b/spiffe/README.adoc
index 929c8f61..b4ef3098 100644
--- a/spiffe/README.adoc
+++ b/spiffe/README.adoc
@@ -260,10 +260,10 @@ from("direct:callBackend").routeId("call-backend")
     .log("GET ${header.CamelHttpPath} answered HTTP 
${header.CamelHttpResponseCode}: ${body}");
 ----
 
-* All applications run `IdentityRoutes`, where `fetchX509Svid` makes the 
message body an
-  `io.spiffe.svid.x509svid.X509Svid` with the certificate chain, the private 
key and the SPIFFE ID of the
-  workload. `X509SvidSummary` describes the leaf certificate, and only the 
certificate: the private key is never
-  logged.
+* All applications run `IdentityRoutes`, where `fetchX509Svid` makes the 
message body the certificate chain of the
+  workload and sets its SPIFFE ID as the `CamelSpiffeSpiffeId` header. The 
private key stays off the message: the
+  component only puts the whole `X509Svid` on the body when 
`x509Response=svid` is set. `X509SvidSummary`
+  describes the leaf certificate.
 
 The component finds the Workload API through the standard 
`SPIFFE_ENDPOINT_SOCKET` environment variable, which
 `compose.yaml` sets for each application. The 
`camel.component.spiffe.spiffe-socket-path` option in
diff --git 
a/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java 
b/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java
index c419d764..a91e8c2c 100644
--- a/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java
+++ b/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java
@@ -39,10 +39,10 @@ public class IdentityRoutes extends RouteBuilder {
                 .log(LoggingLevel.WARN, "Could not fetch the X.509-SVID: 
${exception.message}");
 
         from("timer:identity?period={{identity.period}}").routeId("identity")
-                // fetchX509Svid is also the default operation of the 
component. The message body becomes an
-                // io.spiffe.svid.x509svid.X509Svid and the SPIFFE ID is set 
as the CamelSpiffeSpiffeId header
+                // fetchX509Svid is also the default operation of the 
component. The message body becomes the
+                // certificate chain, without the private key, and the SPIFFE 
ID is set as the CamelSpiffeSpiffeId header
                 .to("spiffe:identity?operation=fetchX509Svid")
-                // the X509Svid also carries the private key of the workload, 
so never log the body as-is
+                // describe the leaf certificate instead of logging the whole 
chain
                 .bean(X509SvidSummary.class, "describe")
                 .log("${body}");
     }
diff --git 
a/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java 
b/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java
index 12544622..40475a6f 100644
--- a/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java
+++ b/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java
@@ -22,11 +22,14 @@ import java.util.ArrayList;
 import java.util.Collection;
 import java.util.List;
 
-import io.spiffe.svid.x509svid.X509Svid;
+import org.apache.camel.Body;
+import org.apache.camel.Header;
+import org.apache.camel.component.spiffe.SpiffeConstants;
 
 /**
- * Turns an {@link X509Svid} into a human-readable summary of its leaf 
certificate. Only the certificate is described:
- * the private key that comes with the SVID is never printed.
+ * Turns the X.509-SVID fetched by the spiffe component into a human-readable 
summary of its leaf certificate. By
+ * default the component puts only the certificate chain on the message body, 
and the SPIFFE ID in a header, so the
+ * private key of the workload never reaches the route.
  */
 public class X509SvidSummary {
 
@@ -36,8 +39,9 @@ public class X509SvidSummary {
      */
     private static final int URI_NAME = 6;
 
-    public String describe(X509Svid svid) throws CertificateParsingException {
-        X509Certificate leaf = svid.getLeaf();
+    public String describe(@Body List<X509Certificate> chain, 
@Header(SpiffeConstants.SPIFFE_ID) String spiffeId)
+            throws CertificateParsingException {
+        X509Certificate leaf = chain.get(0);
         return String.format("""
                 X.509-SVID of %s
                     serial number : %s
@@ -47,14 +51,14 @@ public class X509SvidSummary {
                     valid until   : %s
                     URI SANs      : %s
                     chain length  : %d certificate(s)""",
-                svid.getSpiffeId(),
+                spiffeId,
                 leaf.getSerialNumber().toString(16),
                 leaf.getSubjectX500Principal(),
                 leaf.getIssuerX500Principal(),
                 leaf.getNotBefore().toInstant(),
                 leaf.getNotAfter().toInstant(),
                 uriSubjectAlternativeNames(leaf),
-                svid.getChain().size());
+                chain.size());
     }
 
     private static List<String> uriSubjectAlternativeNames(X509Certificate 
certificate)

Reply via email to