[
https://issues.apache.org/jira/browse/CAMEL-24436?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen resolved CAMEL-24436.
---------------------------------
Resolution: Fixed
> camel-platform-http-vertx - CORS handler allows any origin and always sends
> Access-Control-Allow-Credentials
> ------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-24436
> URL: https://issues.apache.org/jira/browse/CAMEL-24436
> Project: Camel
> Issue Type: Bug
> Components: camel-platform-http-vertx
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> {{VertxPlatformHttpServerSupport.createCorsHandler()}} has two problems in
> the same block:
> {code:java}
> final boolean allowsOrigin
> = ObjectHelper.isEmpty(corsConfig.getOrigins()) ||
> corsConfig.getOrigins().contains(origin);
> if (allowsOrigin) {
> response.headers().set(HttpHeaders.ACCESS_CONTROL_ALLOW_ORIGIN, origin);
> }
> response.headers().set(HttpHeaders.ACCESS_CONTROL_ALLOW_CREDENTIALS, "true");
> {code}
> 1. When {{corsConfig.getOrigins()}} is empty - which is what an operator gets
> by merely enabling CORS without listing origins - {{allowsOrigin}} is true
> for every origin, and the request's own {{Origin}} is echoed back as
> {{Access-Control-Allow-Origin}}.
> 2. {{Access-Control-Allow-Credentials: true}} is set unconditionally, outside
> the {{allowsOrigin}} check, so it is emitted even for an origin that was not
> allowed.
> The requested methods and headers are likewise echoed back when the
> corresponding config lists are unset. The handler is installed on the
> sub-router covering every consumer endpoint, and the same config object
> serves both the main and the management server.
> Proposal:
> * Only send {{Access-Control-Allow-Credentials}} when the origin was actually
> allowed, and make it configurable (it is currently not an option at all)
> rather than hardcoded true.
> * Decide explicitly what an empty origin list should mean. Echoing the
> caller's origin is not the same as {{*}} and should not be the accidental
> result of leaving the list unset - either default to no origins allowed, or
> require the operator to opt in to the permissive behaviour with an explicit
> wildcard entry.
> Either change needs an upgrade-guide entry.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)