[ 
https://issues.apache.org/jira/browse/CAMEL-25139?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen resolved CAMEL-25139.
---------------------------------
    Resolution: Fixed

Fixed via https://github.com/apache/camel/pull/27073 (merged to main for 
4.23.0).

_Claude Code on behalf of davsclaus_

> camel-opa - failOpen allows the exchange when OPA answered (undefined 
> decision, rejected request), not only when it is unavailable
> ----------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25139
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25139
>             Project: Camel
>          Issue Type: Bug
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> With {{failOpen=true}}, {{OpaPolicyEvaluator}} lets the exchange proceed on 
> *every* exception from the evaluation, not only when the policy decision 
> point is unavailable. The option's own documentation promises less: "allow 
> the exchange to proceed when the policy cannot be evaluated at all, for 
> example because the OPA server is unreachable".
> In the SDK (com.styra:opa 2.1.1, checked in the bytecode), 
> {{OPAClient.evaluate}}:
> * wraps any HTTP failure as {{OPAException(..., cause)}}, where the cause is 
> {{ClientError}} (400), {{SDKError}} carrying the status code (other 4xx, such 
> as 401/403/404/429, and other 5xx), {{ServerError}} (500), or an 
> {{IOException}} from the transport;
> * reports an *undefined* decision as a cause-less {{OPAException}} 
> ("succeeded, but OPA did not reply with a result"). The WASM evaluator throws 
> on an undefined rule the same way, on purpose.
> So under {{failOpen=true}} these all turn into an allow, although in none of 
> them was the decision point unavailable:
> * an undefined decision, for example {{policyPath=authz/allow}} against a 
> policy without {{default allow := false}}, where every request the rule does 
> not match becomes an allow. This is the most common Rego shape to trip it;
> * OPA rejecting the request: 400, a wrong or expired {{bearerToken}} 
> (401/403), or a wrong path (404);
> * a failure building or serializing the input document from the message, 
> which is a property of the message rather than of the decision point.
> {{failOpen}} is {{insecure:dev}}, documented as not for production, and 
> camel-opa is not released yet (4.23.0). So this is fixed as a bug before 
> release rather than treated as a vulnerability. It is the same class as the 
> finding in the camel-openfga review (CAMEL-25028), where a 4xx was also read 
> as "no verdict" under {{failOpen}}.
> Fix: {{failOpen}} applies only when the decision point is unavailable. In 
> REST mode that means transport failures ({{IOException}}, including 
> timeouts), HTTP 5xx and 429. In WASM mode it means a pool that stays busy 
> past {{borrowTimeout}}. Everything else fails closed with {{failOpen}} set 
> too: undefined decisions, other 4xx, and input-document failures. This covers 
> single and batch evaluation and {{OpaSecurityPolicy}}.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to