allthingssecurity opened a new pull request, #27342: URL: https://github.com/apache/camel/pull/27342
# Description [CAMEL-25301](https://issues.apache.org/jira/browse/CAMEL-25301) `CloudEventJsonDataTypeTransformer` (data type `application-cloudevents+json`) builds the structured-mode CloudEvent by string concatenation and escapes nothing: - a text body with a quote, a backslash or a line break gives an event that is not valid JSON (`"data":"He said "hi""`), or other text (`C:\temp` is read as `C:` TAB `emp`); - the same for every attribute value (a subject that is a file name, a source); - since CAMEL-22339 every text that starts with `[` or `{` is copied in as a JSON value, so a `text/plain` log line `[INFO] order 42 received` gives `"data":[INFO] order 42 received`. This change writes every string with an RFC 8259 escaper (`"`, `\`, `\n`, `\r`, `\t`, `\b`, `\f`, other control characters as `\u00XX`) and nests the body as a JSON value only when it is a JSON object or array that parses (`Jsoner`, camel-util-json, already on the classpath through camel-support). Text that needs no escaping is written exactly as before, so the output of the existing tests does not change. JSON data is still nested as CAMEL-22339 intended (the CloudEvents JSON format stores JSON data "directly as a JSON value"); only text that is not a JSON object or array is now written as a string. Unchanged and out of scope: `Jsoner` is lenient (missing commas or colons, raw control characters in strings), so such malformed JSON bodies are still nested as they are, and the data content type is still not consulted (as since CAMEL-22339). Tests (`CloudEventJsonDataTypeTransformerTest`, the produced event is parsed with `Jsoner`): - new: text body with quote, backslash, line break and tab; a `text/plain` body `[INFO] order 42 received`; a subject with a quote and a backslash. Without the change all three fail with `DeserializationException` (2 runs); with it they pass. - new control: a JSON body is still nested as an object (passes before and after). - the text test also checks that the event has no raw control character (`Jsoner` accepts them inside strings); a mutant without the `\u00XX` escape fails it. - camel-cloudevents: 11 tests, 0 failures. Found with a Lean 4 model of the writer and of a JSON string reader: "the string written for a value is read back as exactly that value" fails for every value whose first quote follows plain characters (the string ends there), and is proved for the escaped writer for every value, which also writes plain text unchanged. # Target - [x] I checked that the commit is targeting the correct branch (Camel 4 uses the `main` branch) # Tracking - [x] If this is a large change, bug fix, or code improvement, I checked there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for the change (usually before you start working on it). # Apache Camel coding standards and style - [x] I checked that each commit in the pull request has a meaningful subject line and body. - [ ] I have run `mvn clean install -DskipTests` locally from root folder and I have committed all auto-generated changes. (I built and tested the affected module, including the formatter and import-sort plugins. I did not run the full root build.) # AI-assisted contributions - [x] If this PR includes AI-generated code, commits have proper co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR description identifies the AI tool used. This PR was prepared with Claude Code (Claude Opus 5.5). The commit carries a `Co-Authored-By` trailer. _Claude Code on behalf of allthingssecurity_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
