This is an automated email from the ASF dual-hosted git repository. davsclaus pushed a commit to branch fix/CAMEL-24739 in repository https://gitbox.apache.org/repos/asf/camel-examples.git
commit 0b593accdabbd9a213e40261a90ee2c339320c2c Author: Claus Ibsen <[email protected]> AuthorDate: Fri Oct 2 14:51:16 2026 +0200 CAMEL-24739: Fix the spiffe example for fetchX509Svid keeping the private key off the message Since CAMEL-24739, fetchX509Svid puts only the certificate chain on the body by default and the SPIFFE ID in the CamelSpiffeSpiffeId header. X509SvidSummary still expected an X509Svid, the bean call failed, the route's onException handled it, and IdentityRoutesTest saw the raw certificate instead of the summary. Describe the chain and the header instead, which follows the new default rather than opting back in to the private key with x509Response=svid. Update the route comment and the README. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01STT6whBgK1AqsSsUKrnE8m --- spiffe/README.adoc | 8 ++++---- .../apache/camel/example/spiffe/IdentityRoutes.java | 6 +++--- .../apache/camel/example/spiffe/X509SvidSummary.java | 18 +++++++++++------- 3 files changed, 18 insertions(+), 14 deletions(-) diff --git a/spiffe/README.adoc b/spiffe/README.adoc index 929c8f61..b4ef3098 100644 --- a/spiffe/README.adoc +++ b/spiffe/README.adoc @@ -260,10 +260,10 @@ from("direct:callBackend").routeId("call-backend") .log("GET ${header.CamelHttpPath} answered HTTP ${header.CamelHttpResponseCode}: ${body}"); ---- -* All applications run `IdentityRoutes`, where `fetchX509Svid` makes the message body an - `io.spiffe.svid.x509svid.X509Svid` with the certificate chain, the private key and the SPIFFE ID of the - workload. `X509SvidSummary` describes the leaf certificate, and only the certificate: the private key is never - logged. +* All applications run `IdentityRoutes`, where `fetchX509Svid` makes the message body the certificate chain of the + workload and sets its SPIFFE ID as the `CamelSpiffeSpiffeId` header. The private key stays off the message: the + component only puts the whole `X509Svid` on the body when `x509Response=svid` is set. `X509SvidSummary` + describes the leaf certificate. The component finds the Workload API through the standard `SPIFFE_ENDPOINT_SOCKET` environment variable, which `compose.yaml` sets for each application. The `camel.component.spiffe.spiffe-socket-path` option in diff --git a/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java b/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java index c419d764..a91e8c2c 100644 --- a/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java +++ b/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java @@ -39,10 +39,10 @@ public class IdentityRoutes extends RouteBuilder { .log(LoggingLevel.WARN, "Could not fetch the X.509-SVID: ${exception.message}"); from("timer:identity?period={{identity.period}}").routeId("identity") - // fetchX509Svid is also the default operation of the component. The message body becomes an - // io.spiffe.svid.x509svid.X509Svid and the SPIFFE ID is set as the CamelSpiffeSpiffeId header + // fetchX509Svid is also the default operation of the component. The message body becomes the + // certificate chain, without the private key, and the SPIFFE ID is set as the CamelSpiffeSpiffeId header .to("spiffe:identity?operation=fetchX509Svid") - // the X509Svid also carries the private key of the workload, so never log the body as-is + // describe the leaf certificate instead of logging the whole chain .bean(X509SvidSummary.class, "describe") .log("${body}"); } diff --git a/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java b/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java index 12544622..40475a6f 100644 --- a/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java +++ b/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java @@ -22,11 +22,14 @@ import java.util.ArrayList; import java.util.Collection; import java.util.List; -import io.spiffe.svid.x509svid.X509Svid; +import org.apache.camel.Body; +import org.apache.camel.Header; +import org.apache.camel.component.spiffe.SpiffeConstants; /** - * Turns an {@link X509Svid} into a human-readable summary of its leaf certificate. Only the certificate is described: - * the private key that comes with the SVID is never printed. + * Turns the X.509-SVID fetched by the spiffe component into a human-readable summary of its leaf certificate. By + * default the component puts only the certificate chain on the message body, and the SPIFFE ID in a header, so the + * private key of the workload never reaches the route. */ public class X509SvidSummary { @@ -36,8 +39,9 @@ public class X509SvidSummary { */ private static final int URI_NAME = 6; - public String describe(X509Svid svid) throws CertificateParsingException { - X509Certificate leaf = svid.getLeaf(); + public String describe(@Body List<X509Certificate> chain, @Header(SpiffeConstants.SPIFFE_ID) String spiffeId) + throws CertificateParsingException { + X509Certificate leaf = chain.get(0); return String.format(""" X.509-SVID of %s serial number : %s @@ -47,14 +51,14 @@ public class X509SvidSummary { valid until : %s URI SANs : %s chain length : %d certificate(s)""", - svid.getSpiffeId(), + spiffeId, leaf.getSerialNumber().toString(16), leaf.getSubjectX500Principal(), leaf.getIssuerX500Principal(), leaf.getNotBefore().toInstant(), leaf.getNotAfter().toInstant(), uriSubjectAlternativeNames(leaf), - svid.getChain().size()); + chain.size()); } private static List<String> uriSubjectAlternativeNames(X509Certificate certificate)
