[ 
https://issues.apache.org/jira/browse/CAMEL-25134?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120690#comment-18120690
 ] 

Claus Ibsen commented on CAMEL-25134:
-------------------------------------

PR: https://github.com/apache/camel/pull/27070

_Claude Code on behalf of davsclaus_

> camel-main - security policy check matches options by name only, so one 
> component's insecure marker applies to all
> ------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25134
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25134
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-main
>            Reporter: Andrea Cosentino
>            Assignee: Claus Ibsen
>            Priority: Minor
>
> SecurityUtils.getSecurityOption keeps only the last segment of a 
> configuration key, so the insecure:ssl / insecure:dev / 
> insecure:serialization markers generated from one component's 
> @UriParam(security=...) apply to every component that has an option with the 
> same name.
> Examples: tls=false is flagged for any component because of camel-pinecone's 
> tls option, and, once CAMEL-24999 lands, ssl=false set on camel-clickhouse, 
> camel-netty, camel-netty-http or camel-oaipmh is flagged because of 
> camel-hivemq's ssl option. Under camel.main.profile=prod that fails startup 
> for components that never declared the option insecure.
> Suggested improvement: make the check in 
> BaseMainSupport.enforceSecurityPolicies component-aware, so that 
> camel.component.<name>.<option> is matched against that component's own 
> option metadata, and fall back to the name-only lookup only for keys that do 
> not identify a component.
> Raised in the review of https://github.com/apache/camel/pull/26891 
> (CAMEL-24999).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to