allthingssecurity commented on code in PR #27595:
URL: https://github.com/apache/camel/pull/27595#discussion_r4227457895


##########
components/camel-rest-postman/src/main/java/org/apache/camel/component/rest/postman/RestPostmanEndpoint.java:
##########
@@ -369,6 +373,15 @@ String buildDelegateUri(PostmanRequestBinding binding) {
         if (!query.isEmpty()) {
             uri = uri + "?" + query;
         }
+        // getEndpoint resolves the property placeholders of a URI, functions 
such as {{env:NAME}} included, so a
+        // placeholder that the collection's variables left unresolved must 
not reach it
+        if (uri.contains("{{")) {
+            throw new IllegalArgumentException(
+                    "Postman request " + binding.item().describe() + " still 
contains a {{placeholder}} after variable"
+                                               + " substitution, in its URL, 
Accept or Content-Type, which would be"
+                                               + " resolved from Camel 
properties: " + URISupport.sanitizeUri(uri)
+                                               + ". Define it in the 
collection, or supply it with the variables option.");
+        }

Review Comment:
   Confirmed with a test first: without the change, a cloud collection with 
`queryParameterMode=literal` and query key `{{leakProbe}}` sent 
`from-camel-properties=probe`, and a `{{env:PATH}}` key in a classpath 
collection sent the PATH value. Applied your check on 
`binding.queryParameters()` in 20db1a361b2e, with both tests (producer creation 
fails, no request reaches the API); it also covers the header-bound names of 
the default mode and an `apikey` block with `in: query`.
   
   _Claude Code on behalf of allthingssecurity_



##########
components/camel-rest-postman/src/main/docs/rest-postman-component.adoc:
##########
@@ -176,13 +177,28 @@ from("direct:start")
 ----
 
 Postman environment files are not supported. Unresolved placeholders are left 
as they are unless
-`failOnUnresolvedVariable=true`.
+`failOnUnresolvedVariable=true`. The exception is one left in the `Accept` or 
`Content-Type` header of a request: these

Review Comment:
   Updated the sentence to name the URL host, a query parameter name, and the 
Accept/Content-Type header, and regenerated the catalog copy, in 20db1a361b2e.
   
   _Claude Code on behalf of allthingssecurity_



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to