This is an automated email from the ASF dual-hosted git repository.
oscerd pushed a commit to branch camel-4.18.x
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/camel-4.18.x by this push:
new ab456fb72a45 [backport camel-4.18.x] CAMEL-25376: camel-netty-http -
match security constraint roles by exact role name (#27481)
ab456fb72a45 is described below
commit ab456fb72a455c94b581699c02173c9198b6f3b8
Author: Andrea Cosentino <[email protected]>
AuthorDate: Wed Oct 7 10:46:58 2026 +0200
[backport camel-4.18.x] CAMEL-25376: camel-netty-http - match security
constraint roles by exact role name (#27481)
Backport of #27432 to camel-4.18.x (adapted: junit5 test imports, no
catalog doc mirror on this branch). Security constraint roles are matched as
whole role names: configured and user roles are split on comma, trimmed and
blank entries dropped, matched case-sensitively as before, with `*` unchanged.
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
Signed-off-by: Andrea Cosentino <[email protected]>
---
.../src/main/docs/netty-http-component.adoc | 5 +
.../http/handlers/HttpServerChannelHandler.java | 21 +++-
.../NettyHttpBasicAuthConstraintRolesTest.java | 109 +++++++++++++++++++++
.../HttpServerChannelHandlerRolesTest.java | 65 ++++++++++++
4 files changed, 198 insertions(+), 2 deletions(-)
diff --git
a/components/camel-netty-http/src/main/docs/netty-http-component.adoc
b/components/camel-netty-http/src/main/docs/netty-http-component.adoc
index 125747683685..26b1c551e454 100644
--- a/components/camel-netty-http/src/main/docs/netty-http-component.adoc
+++ b/components/camel-netty-http/src/main/docs/netty-http-component.adoc
@@ -169,6 +169,11 @@ no roles)
* access to /public/* is an exclusion that means no authentication is
necessary, and is therefore public for everyone without logging in
+The roles of an inclusion are a comma-separated list of role names. A user
+is in role when one of the user roles is equal to one of the listed names.
+The comparison is case-sensitive, whitespace around each name and blank
+entries are ignored, and a value of `*` accepts any role.
+
To use this constraint, we just need to refer to the bean id as shown
below:
diff --git
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
index 7bc5556f8af8..af39b14fcdcc 100644
---
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
+++
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
@@ -19,7 +19,9 @@ package org.apache.camel.component.netty.http.handlers;
import java.net.URI;
import java.nio.channels.ClosedChannelException;
import java.nio.charset.Charset;
+import java.util.HashSet;
import java.util.Locale;
+import java.util.Set;
import javax.security.auth.Subject;
import javax.security.auth.login.LoginException;
@@ -232,9 +234,10 @@ public class HttpServerChannelHandler extends
ServerChannelHandler {
return true;
}
- // see if any of the user roles is contained in the roles list
+ // the user must have one of the roles, compared by the exact role name
+ Set<String> names = roleNames(roles);
for (String userRole : ObjectHelper.createIterable(userRoles)) {
- if (roles.contains(userRole)) {
+ if (names.contains(userRole.trim())) {
return true;
}
}
@@ -242,6 +245,20 @@ public class HttpServerChannelHandler extends
ServerChannelHandler {
return false;
}
+ /**
+ * The role names in the comma separated list of roles, trimmed and
without blank entries.
+ */
+ private static Set<String> roleNames(String roles) {
+ Set<String> names = new HashSet<>();
+ for (String role : ObjectHelper.createIterable(roles)) {
+ String name = role.trim();
+ if (!name.isEmpty()) {
+ names.add(name);
+ }
+ }
+ return names;
+ }
+
/**
* Extracts the username and password details from the HTTP basic header
Authorization.
* <p/>
diff --git
a/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/NettyHttpBasicAuthConstraintRolesTest.java
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/NettyHttpBasicAuthConstraintRolesTest.java
new file mode 100644
index 000000000000..55a2041e4e95
--- /dev/null
+++
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/NettyHttpBasicAuthConstraintRolesTest.java
@@ -0,0 +1,109 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.netty.http;
+
+import org.apache.camel.BindToRegistry;
+import org.apache.camel.CamelExecutionException;
+import org.apache.camel.builder.RouteBuilder;
+import org.junit.jupiter.api.Test;
+
+import static org.apache.camel.test.junit5.TestSupport.assertIsInstanceOf;
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertThrows;
+
+/**
+ * The roles of a security constraint inclusion are matched by role name. The
JAAS test login gives scott the roles
+ * admin and guest, and gives guest the role guest.
+ */
+class NettyHttpBasicAuthConstraintRolesTest extends BaseNettyTestSupport {
+
+ // username:password is scott:secret
+ private static final String SCOTT = "Basic c2NvdHQ6c2VjcmV0";
+ // username:password is guest:secret
+ private static final String GUEST = "Basic Z3Vlc3Q6c2VjcmV0";
+
+ @Override
+ protected void doPreSetup() {
+ System.setProperty("java.security.auth.login.config",
"src/test/resources/myjaas.config");
+ }
+
+ @Override
+ protected void doPostTearDown() {
+ System.clearProperty("java.security.auth.login.config");
+ }
+
+ @BindToRegistry("mySecurityConfig")
+ public NettyHttpSecurityConfiguration loadSecConf() {
+ NettyHttpSecurityConfiguration security = new
NettyHttpSecurityConfiguration();
+ security.setRealm("karaf");
+ SecurityAuthenticator auth = new JAASSecurityAuthenticator();
+ auth.setName("karaf");
+ security.setSecurityAuthenticator(auth);
+
+ SecurityConstraintMapping matcher = new SecurityConstraintMapping();
+ matcher.addInclusion("/admin/*", "admin");
+ matcher.addInclusion("/admins/*", "admins");
+ matcher.addInclusion("/staff/*", "operator, guest");
+ security.setSecurityConstraint(matcher);
+
+ return security;
+ }
+
+ @Test
+ void userWithTheRoleIsAccepted() {
+ String out =
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/admin/x",
"Hello",
+ "Authorization", SCOTT, String.class);
+ assertEquals("Bye World", out);
+ }
+
+ @Test
+ void anyRoleOfTheListIsAccepted() {
+ String out =
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/staff/x",
"Hello",
+ "Authorization", GUEST, String.class);
+ assertEquals("Bye World", out);
+ }
+
+ @Test
+ void roleIsMatchedByTheWholeName() {
+ // scott has the role admin, which is not the role admins
+ CamelExecutionException e = assertThrows(CamelExecutionException.class,
+ () ->
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/admins/x",
"Hello",
+ "Authorization", SCOTT, String.class));
+ NettyHttpOperationFailedException cause =
assertIsInstanceOf(NettyHttpOperationFailedException.class, e.getCause());
+ assertEquals(401, cause.getStatusCode());
+ }
+
+ @Test
+ void userWithoutTheRoleIsRejected() {
+ CamelExecutionException e = assertThrows(CamelExecutionException.class,
+ () ->
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/admin/x",
"Hello",
+ "Authorization", GUEST, String.class));
+ NettyHttpOperationFailedException cause =
assertIsInstanceOf(NettyHttpOperationFailedException.class, e.getCause());
+ assertEquals(401, cause.getStatusCode());
+ }
+
+ @Override
+ protected RouteBuilder createRouteBuilder() {
+ return new RouteBuilder() {
+ @Override
+ public void configure() {
+
from("netty-http:http://0.0.0.0:{{port}}/foo?matchOnUriPrefix=true&securityConfiguration=#mySecurityConfig")
+ .transform().constant("Bye World");
+ }
+ };
+ }
+}
diff --git
a/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandlerRolesTest.java
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandlerRolesTest.java
new file mode 100644
index 000000000000..d1c171b18bb8
--- /dev/null
+++
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandlerRolesTest.java
@@ -0,0 +1,65 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.netty.http.handlers;
+
+import org.apache.camel.component.netty.http.NettyHttpConsumer;
+import org.apache.camel.component.netty.http.NettyHttpEndpoint;
+import org.apache.camel.test.junit5.CamelTestSupport;
+import org.junit.jupiter.api.BeforeEach;
+import org.junit.jupiter.params.ParameterizedTest;
+import org.junit.jupiter.params.provider.CsvSource;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+
+/**
+ * The roles of a security constraint are a comma separated list of role
names, and the user is in role when one of the
+ * user roles is equal to one of those names.
+ */
+class HttpServerChannelHandlerRolesTest extends CamelTestSupport {
+
+ private HttpServerChannelHandler handler;
+
+ @BeforeEach
+ void createHandler() {
+ NettyHttpEndpoint endpoint =
context.getEndpoint("netty-http:http://localhost:8080/roles",
NettyHttpEndpoint.class);
+ handler = new HttpServerChannelHandler(new NettyHttpConsumer(endpoint,
exchange -> {
+ }, endpoint.getConfiguration()));
+ }
+
+ @ParameterizedTest
+ @CsvSource(delimiter = '|', nullValues = "null", textBlock = """
+ # roles | user roles | in role
+ * | guest | true
+ * | null | true
+ admin | admin,guest | true
+ admin,guest | guest | true
+ 'admin, guest' | guest | true
+ ' admin , guest ' | 'guest ' | true
+ admins | admin | false
+ readwrite | read | false
+ admin,guest | dmin | false
+ Admin | admin | false
+ admin;guest | guest | false
+ admin | 'guest,,viewer' | false
+ 'admin, ops' | 'guest, ,viewer' | false
+ 'admin,,ops' | 'guest,,viewer' | false
+ admin | null | false
+ """)
+ void matchesRoles(String roles, String userRoles, boolean inRole) {
+ assertEquals(inRole, handler.matchesRoles(roles, userRoles), () ->
"roles " + roles + ", user roles " + userRoles);
+ }
+}