This is an automated email from the ASF dual-hosted git repository.

oscerd pushed a commit to branch camel-4.18.x
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/camel-4.18.x by this push:
     new ab456fb72a45 [backport camel-4.18.x] CAMEL-25376: camel-netty-http - 
match security constraint roles by exact role name (#27481)
ab456fb72a45 is described below

commit ab456fb72a455c94b581699c02173c9198b6f3b8
Author: Andrea Cosentino <[email protected]>
AuthorDate: Wed Oct 7 10:46:58 2026 +0200

    [backport camel-4.18.x] CAMEL-25376: camel-netty-http - match security 
constraint roles by exact role name (#27481)
    
    Backport of #27432 to camel-4.18.x (adapted: junit5 test imports, no 
catalog doc mirror on this branch). Security constraint roles are matched as 
whole role names: configured and user roles are split on comma, trimmed and 
blank entries dropped, matched case-sensitively as before, with `*` unchanged.
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
    Signed-off-by: Andrea Cosentino <[email protected]>
---
 .../src/main/docs/netty-http-component.adoc        |   5 +
 .../http/handlers/HttpServerChannelHandler.java    |  21 +++-
 .../NettyHttpBasicAuthConstraintRolesTest.java     | 109 +++++++++++++++++++++
 .../HttpServerChannelHandlerRolesTest.java         |  65 ++++++++++++
 4 files changed, 198 insertions(+), 2 deletions(-)

diff --git 
a/components/camel-netty-http/src/main/docs/netty-http-component.adoc 
b/components/camel-netty-http/src/main/docs/netty-http-component.adoc
index 125747683685..26b1c551e454 100644
--- a/components/camel-netty-http/src/main/docs/netty-http-component.adoc
+++ b/components/camel-netty-http/src/main/docs/netty-http-component.adoc
@@ -169,6 +169,11 @@ no roles)
 * access to /public/* is an exclusion that means no authentication is
 necessary, and is therefore public for everyone without logging in
 
+The roles of an inclusion are a comma-separated list of role names. A user
+is in role when one of the user roles is equal to one of the listed names.
+The comparison is case-sensitive, whitespace around each name and blank
+entries are ignored, and a value of `*` accepts any role.
+
 To use this constraint, we just need to refer to the bean id as shown
 below:
 
diff --git 
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
 
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
index 7bc5556f8af8..af39b14fcdcc 100644
--- 
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
+++ 
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java
@@ -19,7 +19,9 @@ package org.apache.camel.component.netty.http.handlers;
 import java.net.URI;
 import java.nio.channels.ClosedChannelException;
 import java.nio.charset.Charset;
+import java.util.HashSet;
 import java.util.Locale;
+import java.util.Set;
 
 import javax.security.auth.Subject;
 import javax.security.auth.login.LoginException;
@@ -232,9 +234,10 @@ public class HttpServerChannelHandler extends 
ServerChannelHandler {
             return true;
         }
 
-        // see if any of the user roles is contained in the roles list
+        // the user must have one of the roles, compared by the exact role name
+        Set<String> names = roleNames(roles);
         for (String userRole : ObjectHelper.createIterable(userRoles)) {
-            if (roles.contains(userRole)) {
+            if (names.contains(userRole.trim())) {
                 return true;
             }
         }
@@ -242,6 +245,20 @@ public class HttpServerChannelHandler extends 
ServerChannelHandler {
         return false;
     }
 
+    /**
+     * The role names in the comma separated list of roles, trimmed and 
without blank entries.
+     */
+    private static Set<String> roleNames(String roles) {
+        Set<String> names = new HashSet<>();
+        for (String role : ObjectHelper.createIterable(roles)) {
+            String name = role.trim();
+            if (!name.isEmpty()) {
+                names.add(name);
+            }
+        }
+        return names;
+    }
+
     /**
      * Extracts the username and password details from the HTTP basic header 
Authorization.
      * <p/>
diff --git 
a/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/NettyHttpBasicAuthConstraintRolesTest.java
 
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/NettyHttpBasicAuthConstraintRolesTest.java
new file mode 100644
index 000000000000..55a2041e4e95
--- /dev/null
+++ 
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/NettyHttpBasicAuthConstraintRolesTest.java
@@ -0,0 +1,109 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.netty.http;
+
+import org.apache.camel.BindToRegistry;
+import org.apache.camel.CamelExecutionException;
+import org.apache.camel.builder.RouteBuilder;
+import org.junit.jupiter.api.Test;
+
+import static org.apache.camel.test.junit5.TestSupport.assertIsInstanceOf;
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertThrows;
+
+/**
+ * The roles of a security constraint inclusion are matched by role name. The 
JAAS test login gives scott the roles
+ * admin and guest, and gives guest the role guest.
+ */
+class NettyHttpBasicAuthConstraintRolesTest extends BaseNettyTestSupport {
+
+    // username:password is scott:secret
+    private static final String SCOTT = "Basic c2NvdHQ6c2VjcmV0";
+    // username:password is guest:secret
+    private static final String GUEST = "Basic Z3Vlc3Q6c2VjcmV0";
+
+    @Override
+    protected void doPreSetup() {
+        System.setProperty("java.security.auth.login.config", 
"src/test/resources/myjaas.config");
+    }
+
+    @Override
+    protected void doPostTearDown() {
+        System.clearProperty("java.security.auth.login.config");
+    }
+
+    @BindToRegistry("mySecurityConfig")
+    public NettyHttpSecurityConfiguration loadSecConf() {
+        NettyHttpSecurityConfiguration security = new 
NettyHttpSecurityConfiguration();
+        security.setRealm("karaf");
+        SecurityAuthenticator auth = new JAASSecurityAuthenticator();
+        auth.setName("karaf");
+        security.setSecurityAuthenticator(auth);
+
+        SecurityConstraintMapping matcher = new SecurityConstraintMapping();
+        matcher.addInclusion("/admin/*", "admin");
+        matcher.addInclusion("/admins/*", "admins");
+        matcher.addInclusion("/staff/*", "operator, guest");
+        security.setSecurityConstraint(matcher);
+
+        return security;
+    }
+
+    @Test
+    void userWithTheRoleIsAccepted() {
+        String out = 
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/admin/x";,
 "Hello",
+                "Authorization", SCOTT, String.class);
+        assertEquals("Bye World", out);
+    }
+
+    @Test
+    void anyRoleOfTheListIsAccepted() {
+        String out = 
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/staff/x";,
 "Hello",
+                "Authorization", GUEST, String.class);
+        assertEquals("Bye World", out);
+    }
+
+    @Test
+    void roleIsMatchedByTheWholeName() {
+        // scott has the role admin, which is not the role admins
+        CamelExecutionException e = assertThrows(CamelExecutionException.class,
+                () -> 
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/admins/x";,
 "Hello",
+                        "Authorization", SCOTT, String.class));
+        NettyHttpOperationFailedException cause = 
assertIsInstanceOf(NettyHttpOperationFailedException.class, e.getCause());
+        assertEquals(401, cause.getStatusCode());
+    }
+
+    @Test
+    void userWithoutTheRoleIsRejected() {
+        CamelExecutionException e = assertThrows(CamelExecutionException.class,
+                () -> 
template.requestBodyAndHeader("netty-http:http://localhost:{{port}}/foo/admin/x";,
 "Hello",
+                        "Authorization", GUEST, String.class));
+        NettyHttpOperationFailedException cause = 
assertIsInstanceOf(NettyHttpOperationFailedException.class, e.getCause());
+        assertEquals(401, cause.getStatusCode());
+    }
+
+    @Override
+    protected RouteBuilder createRouteBuilder() {
+        return new RouteBuilder() {
+            @Override
+            public void configure() {
+                
from("netty-http:http://0.0.0.0:{{port}}/foo?matchOnUriPrefix=true&securityConfiguration=#mySecurityConfig";)
+                        .transform().constant("Bye World");
+            }
+        };
+    }
+}
diff --git 
a/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandlerRolesTest.java
 
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandlerRolesTest.java
new file mode 100644
index 000000000000..d1c171b18bb8
--- /dev/null
+++ 
b/components/camel-netty-http/src/test/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandlerRolesTest.java
@@ -0,0 +1,65 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.netty.http.handlers;
+
+import org.apache.camel.component.netty.http.NettyHttpConsumer;
+import org.apache.camel.component.netty.http.NettyHttpEndpoint;
+import org.apache.camel.test.junit5.CamelTestSupport;
+import org.junit.jupiter.api.BeforeEach;
+import org.junit.jupiter.params.ParameterizedTest;
+import org.junit.jupiter.params.provider.CsvSource;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+
+/**
+ * The roles of a security constraint are a comma separated list of role 
names, and the user is in role when one of the
+ * user roles is equal to one of those names.
+ */
+class HttpServerChannelHandlerRolesTest extends CamelTestSupport {
+
+    private HttpServerChannelHandler handler;
+
+    @BeforeEach
+    void createHandler() {
+        NettyHttpEndpoint endpoint = 
context.getEndpoint("netty-http:http://localhost:8080/roles";, 
NettyHttpEndpoint.class);
+        handler = new HttpServerChannelHandler(new NettyHttpConsumer(endpoint, 
exchange -> {
+        }, endpoint.getConfiguration()));
+    }
+
+    @ParameterizedTest
+    @CsvSource(delimiter = '|', nullValues = "null", textBlock = """
+            # roles           | user roles       | in role
+            *                 | guest            | true
+            *                 | null             | true
+            admin             | admin,guest      | true
+            admin,guest       | guest            | true
+            'admin, guest'    | guest            | true
+            ' admin , guest ' | 'guest '         | true
+            admins            | admin            | false
+            readwrite         | read             | false
+            admin,guest       | dmin             | false
+            Admin             | admin            | false
+            admin;guest       | guest            | false
+            admin             | 'guest,,viewer'  | false
+            'admin, ops'      | 'guest, ,viewer' | false
+            'admin,,ops'      | 'guest,,viewer'  | false
+            admin             | null             | false
+            """)
+    void matchesRoles(String roles, String userRoles, boolean inRole) {
+        assertEquals(inRole, handler.matchesRoles(roles, userRoles), () -> 
"roles " + roles + ", user roles " + userRoles);
+    }
+}

Reply via email to