[ 
https://issues.apache.org/jira/browse/CAMEL-25168?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen resolved CAMEL-25168.
---------------------------------
    Resolution: Fixed

> camel-openapi-validator: a repeated request header is validated as the text 
> of a Java collection
> ------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25168
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25168
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-openapi-validator
>    Affects Versions: 4.22.1
>            Reporter: Thomas Raddatz
>            Priority: Minor
>             Fix For: 4.23.0
>
>
> The rest client request validator ({{OpenApiRestClientRequestValidator}}) 
> builds the {{SimpleRequest}} for swagger-request-validator with
> {code:java}
> builder.withHeader(key, exchange.getMessage().getHeader(key, String.class));
> {code}
> A header that occurs more than once arrives on the message as a 
> {{Collection}} ({{CollectionHelper.appendEntry}}). Converting it to 
> {{String}} falls back to {{ToStringTypeConverter}}, so the validator checks 
> the value {{[a, b]}}, which the client never sent.
> h3. Consequences
> * A header declared as a single value (e.g. {{"type": "string"}}) that is 
> repeated is never reported, because {{[a, b]}} is still a string.
> * {{pattern}}, {{enum}}, {{format}} and {{maxLength}}, and the item type of 
> an array header, are checked against the wrong value, so a valid request can 
> be rejected or an invalid one accepted.
> * A repeated array header is checked as the text {{[a, b]}}, split at the 
> comma into {{[a}} and {{ b]}}. With typed items such as {{integer}} it is 
> rejected, although per [RFC 9110 section 
> 5.3|https://www.rfc-editor.org/rfc/rfc9110#section-5.3] it is equivalent to 
> one header with the values joined by commas. With string items it passes only 
> by accident.
> Query parameters in the same method are already passed once per occurrence, 
> so the equivalent repeated query parameter is validated correctly.
> h3. Reproduce
> With the petstore contract of the module ({{DELETE /pet/\{petId\}}}, header 
> {{api_key}} {{"type": "string"}}):
> {code:java}
> exchange.getMessage().setHeader(Exchange.HTTP_METHOD, "DELETE");
> exchange.getMessage().setHeader(Exchange.HTTP_PATH, "pet/123");
> exchange.getMessage().setHeader("api_key", List.of("key-one", "key-two"));
> {code}
> *Expected:* a validation error.
> *Actual:* no error.
> h3. Known limitation (outside the scope of this issue)
> For OpenAPI 3.1 contracts swagger-request-validator 2.46.1 does not recognise 
> header parameters as arrays (the parser produces {{JsonSchema}}, the 
> validator checks for {{ArraySchema}}), so header arrays of a 3.1 contract do 
> not validate at all.
> h3. Pull request
> https://github.com/apache/camel/pull/27099



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to