allthingssecurity commented on code in PR #27595:
URL: https://github.com/apache/camel/pull/27595#discussion_r4225688807
##########
components/camel-rest-postman/src/main/java/org/apache/camel/component/rest/postman/RestPostmanConfiguration.java:
##########
@@ -62,6 +62,15 @@ public class RestPostmanConfiguration implements Cloneable {
+ " resolved. When false the placeholder is left
as-is.")
private boolean failOnUnresolvedVariable;
+ @UriParam(label = "common,security")
+ @Metadata(description = "Whether a {{variable}} placeholder that neither
the collection nor the variables option"
+ + " defines is resolved from Camel properties,
which by default also cover JVM system"
+ + " properties and OS environment variables. When
not set, this is done for a collection"
+ + " read from the classpath or the file system,
and not for one fetched from the Postman"
+ + " cloud, over HTTP or through any other resource
scheme, because whoever edits or serves"
+ + " such a collection could otherwise copy those
values into an outgoing request.")
+ private Boolean resolveVariablesFromProperties;
Review Comment:
Fixed in 05f1ff3b5b16. `@Metadata(defaultValue = "")` would not help:
`EndpointSchemaGeneratorMojo` writes `false` for any boolean option with an
empty default, and no attribute suppresses it. The option is now a String with
`enums = "auto,enabled,disabled"` and `defaultValue = "auto"` (same pattern as
this component's `collectionSourceType` and spring-rabbitmq's `confirm`), so
the catalog says `"defaultValue": "auto"`; `auto` keeps the source-based
decision and an unknown value fails producer creation (new tests for both).
_Claude Code on behalf of allthingssecurity_
##########
components/camel-rest-postman/src/main/java/org/apache/camel/component/rest/postman/collection/PostmanCollectionLoader.java:
##########
@@ -73,6 +73,21 @@ public static boolean isCloudSource(String source, String
sourceType) {
return UID_PATTERN.matcher(source).matches();
}
+ /**
+ * Whether the source is read from the application's own classpath or file
system: a {@code classpath:} or
+ * {@code file:} URI, or a name without a scheme, which is resolved from
the classpath. A cloud source, an
+ * {@code http:} or {@code https:} URI and any other scheme are not local.
+ *
+ * @param source the collection source
+ * @param sourceType {@code auto}, {@code resource} or {@code cloud}
+ */
+ public static boolean isLocalSource(String source, String sourceType) {
+ if (isCloudSource(source, sourceType)) {
+ return false;
+ }
+ return source.startsWith("classpath:") || source.startsWith("file:")
|| source.indexOf(':') < 0;
Review Comment:
Checked: such a path is not loadable at all. `DefaultResourceLoader` takes
`C` for a scheme and fails with "Cannot find a ResourceResolver in classpath
supporting the scheme: C", so a file system path needs a `file:` URI anyway and
classifying it as remote changes nothing. 05f1ff3b5b16 adds a comment in
`isLocalSource` and a test that `C:\petstore.json` and `C:/petstore.json` are
not local and fail to load.
_Claude Code on behalf of allthingssecurity_
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]