[
https://issues.apache.org/jira/browse/CAMEL-25168?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18121249#comment-18121249
]
Claus Ibsen commented on CAMEL-25168:
-------------------------------------
Merged to main via https://github.com/apache/camel/pull/27099 (fix version
4.23.0).
_Claude Code on behalf of davsclaus_
> camel-openapi-validator: a repeated request header is validated as the text
> of a Java collection
> ------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25168
> URL: https://issues.apache.org/jira/browse/CAMEL-25168
> Project: Camel
> Issue Type: Bug
> Components: camel-openapi-validator
> Affects Versions: 4.22.1
> Reporter: Thomas Raddatz
> Priority: Minor
> Fix For: 4.23.0
>
>
> The rest client request validator ({{OpenApiRestClientRequestValidator}})
> builds the {{SimpleRequest}} for swagger-request-validator with
> {code:java}
> builder.withHeader(key, exchange.getMessage().getHeader(key, String.class));
> {code}
> A header that occurs more than once arrives on the message as a
> {{Collection}} ({{CollectionHelper.appendEntry}}). Converting it to
> {{String}} falls back to {{ToStringTypeConverter}}, so the validator checks
> the value {{[a, b]}}, which the client never sent.
> h3. Consequences
> * A header declared as a single value (e.g. {{"type": "string"}}) that is
> repeated is never reported, because {{[a, b]}} is still a string.
> * {{pattern}}, {{enum}}, {{format}} and {{maxLength}}, and the item type of
> an array header, are checked against the wrong value, so a valid request can
> be rejected or an invalid one accepted.
> * A repeated array header is checked as the text {{[a, b]}}, split at the
> comma into {{[a}} and {{ b]}}. With typed items such as {{integer}} it is
> rejected, although per [RFC 9110 section
> 5.3|https://www.rfc-editor.org/rfc/rfc9110#section-5.3] it is equivalent to
> one header with the values joined by commas. With string items it passes only
> by accident.
> Query parameters in the same method are already passed once per occurrence,
> so the equivalent repeated query parameter is validated correctly.
> h3. Reproduce
> With the petstore contract of the module ({{DELETE /pet/\{petId\}}}, header
> {{api_key}} {{"type": "string"}}):
> {code:java}
> exchange.getMessage().setHeader(Exchange.HTTP_METHOD, "DELETE");
> exchange.getMessage().setHeader(Exchange.HTTP_PATH, "pet/123");
> exchange.getMessage().setHeader("api_key", List.of("key-one", "key-two"));
> {code}
> *Expected:* a validation error.
> *Actual:* no error.
> h3. Known limitation (outside the scope of this issue)
> For OpenAPI 3.1 contracts swagger-request-validator 2.46.1 does not recognise
> header parameters as arrays (the parser produces {{JsonSchema}}, the
> validator checks for {{ArraySchema}}), so header arrays of a 3.1 contract do
> not validate at all.
> h3. Pull request
> https://github.com/apache/camel/pull/27099
--
This message was sent by Atlassian Jira
(v8.20.10#820010)