This is an automated email from the ASF dual-hosted git repository.
davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-examples.git
The following commit(s) were added to refs/heads/main by this push:
new 1fbc4e2b CAMEL-24739: Fix the spiffe example for fetchX509Svid keeping
the private key off the message (#282)
1fbc4e2b is described below
commit 1fbc4e2bfa0a2048f0515bc94519c126fdfb4f1a
Author: Claus Ibsen <[email protected]>
AuthorDate: Fri Oct 2 15:26:13 2026 +0200
CAMEL-24739: Fix the spiffe example for fetchX509Svid keeping the private
key off the message (#282)
Since CAMEL-24739, fetchX509Svid puts only the certificate chain on the
body by default and the
SPIFFE ID in the CamelSpiffeSpiffeId header. X509SvidSummary still expected
an X509Svid, the bean
call failed, the route's onException handled it, and IdentityRoutesTest saw
the raw certificate
instead of the summary.
Describe the chain and the header instead, which follows the new default
rather than opting back
in to the private key with x509Response=svid. Update the route comment and
the README.
Claude-Session: https://claude.ai/code/session_01STT6whBgK1AqsSsUKrnE8m
Co-authored-by: Claude Opus 5.5 (1M context) <[email protected]>
---
spiffe/README.adoc | 8 ++++----
.../apache/camel/example/spiffe/IdentityRoutes.java | 6 +++---
.../apache/camel/example/spiffe/X509SvidSummary.java | 18 +++++++++++-------
3 files changed, 18 insertions(+), 14 deletions(-)
diff --git a/spiffe/README.adoc b/spiffe/README.adoc
index 929c8f61..b4ef3098 100644
--- a/spiffe/README.adoc
+++ b/spiffe/README.adoc
@@ -260,10 +260,10 @@ from("direct:callBackend").routeId("call-backend")
.log("GET ${header.CamelHttpPath} answered HTTP
${header.CamelHttpResponseCode}: ${body}");
----
-* All applications run `IdentityRoutes`, where `fetchX509Svid` makes the
message body an
- `io.spiffe.svid.x509svid.X509Svid` with the certificate chain, the private
key and the SPIFFE ID of the
- workload. `X509SvidSummary` describes the leaf certificate, and only the
certificate: the private key is never
- logged.
+* All applications run `IdentityRoutes`, where `fetchX509Svid` makes the
message body the certificate chain of the
+ workload and sets its SPIFFE ID as the `CamelSpiffeSpiffeId` header. The
private key stays off the message: the
+ component only puts the whole `X509Svid` on the body when
`x509Response=svid` is set. `X509SvidSummary`
+ describes the leaf certificate.
The component finds the Workload API through the standard
`SPIFFE_ENDPOINT_SOCKET` environment variable, which
`compose.yaml` sets for each application. The
`camel.component.spiffe.spiffe-socket-path` option in
diff --git
a/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java
b/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java
index c419d764..a91e8c2c 100644
--- a/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java
+++ b/spiffe/src/main/java/org/apache/camel/example/spiffe/IdentityRoutes.java
@@ -39,10 +39,10 @@ public class IdentityRoutes extends RouteBuilder {
.log(LoggingLevel.WARN, "Could not fetch the X.509-SVID:
${exception.message}");
from("timer:identity?period={{identity.period}}").routeId("identity")
- // fetchX509Svid is also the default operation of the
component. The message body becomes an
- // io.spiffe.svid.x509svid.X509Svid and the SPIFFE ID is set
as the CamelSpiffeSpiffeId header
+ // fetchX509Svid is also the default operation of the
component. The message body becomes the
+ // certificate chain, without the private key, and the SPIFFE
ID is set as the CamelSpiffeSpiffeId header
.to("spiffe:identity?operation=fetchX509Svid")
- // the X509Svid also carries the private key of the workload,
so never log the body as-is
+ // describe the leaf certificate instead of logging the whole
chain
.bean(X509SvidSummary.class, "describe")
.log("${body}");
}
diff --git
a/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java
b/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java
index 12544622..40475a6f 100644
--- a/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java
+++ b/spiffe/src/main/java/org/apache/camel/example/spiffe/X509SvidSummary.java
@@ -22,11 +22,14 @@ import java.util.ArrayList;
import java.util.Collection;
import java.util.List;
-import io.spiffe.svid.x509svid.X509Svid;
+import org.apache.camel.Body;
+import org.apache.camel.Header;
+import org.apache.camel.component.spiffe.SpiffeConstants;
/**
- * Turns an {@link X509Svid} into a human-readable summary of its leaf
certificate. Only the certificate is described:
- * the private key that comes with the SVID is never printed.
+ * Turns the X.509-SVID fetched by the spiffe component into a human-readable
summary of its leaf certificate. By
+ * default the component puts only the certificate chain on the message body,
and the SPIFFE ID in a header, so the
+ * private key of the workload never reaches the route.
*/
public class X509SvidSummary {
@@ -36,8 +39,9 @@ public class X509SvidSummary {
*/
private static final int URI_NAME = 6;
- public String describe(X509Svid svid) throws CertificateParsingException {
- X509Certificate leaf = svid.getLeaf();
+ public String describe(@Body List<X509Certificate> chain,
@Header(SpiffeConstants.SPIFFE_ID) String spiffeId)
+ throws CertificateParsingException {
+ X509Certificate leaf = chain.get(0);
return String.format("""
X.509-SVID of %s
serial number : %s
@@ -47,14 +51,14 @@ public class X509SvidSummary {
valid until : %s
URI SANs : %s
chain length : %d certificate(s)""",
- svid.getSpiffeId(),
+ spiffeId,
leaf.getSerialNumber().toString(16),
leaf.getSubjectX500Principal(),
leaf.getIssuerX500Principal(),
leaf.getNotBefore().toInstant(),
leaf.getNotAfter().toInstant(),
uriSubjectAlternativeNames(leaf),
- svid.getChain().size());
+ chain.size());
}
private static List<String> uriSubjectAlternativeNames(X509Certificate
certificate)