[
https://issues.apache.org/jira/browse/CAMEL-25134?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen reassigned CAMEL-25134:
-----------------------------------
Assignee: Claus Ibsen
> camel-main - security policy check matches options by name only, so one
> component's insecure marker applies to all
> ------------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25134
> URL: https://issues.apache.org/jira/browse/CAMEL-25134
> Project: Camel
> Issue Type: Improvement
> Components: camel-main
> Reporter: Andrea Cosentino
> Assignee: Claus Ibsen
> Priority: Minor
>
> SecurityUtils.getSecurityOption keeps only the last segment of a
> configuration key, so the insecure:ssl / insecure:dev /
> insecure:serialization markers generated from one component's
> @UriParam(security=...) apply to every component that has an option with the
> same name.
> Examples: tls=false is flagged for any component because of camel-pinecone's
> tls option, and, once CAMEL-24999 lands, ssl=false set on camel-clickhouse,
> camel-netty, camel-netty-http or camel-oaipmh is flagged because of
> camel-hivemq's ssl option. Under camel.main.profile=prod that fails startup
> for components that never declared the option insecure.
> Suggested improvement: make the check in
> BaseMainSupport.enforceSecurityPolicies component-aware, so that
> camel.component.<name>.<option> is matched against that component's own
> option metadata, and fall back to the name-only lookup only for keys that do
> not identify a component.
> Raised in the review of https://github.com/apache/camel/pull/26891
> (CAMEL-24999).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)