Andrea Cosentino created CAMEL-25375:
----------------------------------------

             Summary: camel-undertow - Apply securityProvider, allowedRoles and 
handlers to WebSocket endpoints consistently with HTTP endpoints
                 Key: CAMEL-25375
                 URL: https://issues.apache.org/jira/browse/CAMEL-25375
             Project: Camel
          Issue Type: Bug
          Components: camel-undertow
            Reporter: Andrea Cosentino
            Assignee: Andrea Cosentino
             Fix For: 4.18.5, 4.23.0, 4.22.2


The undertow component applies the {{UndertowSecurityProvider}} (configured 
with {{securityConfiguration}} or {{securityProvider}}), the {{allowedRoles}} 
option and the {{handlers}} option in the HTTP request path: 
{{UndertowConsumer.handleRequest()}} and the handler chain built in 
{{UndertowConsumer.doStart()}}.

WebSocket endpoints ({{ws://}}, {{wss://}}) are served by 
{{CamelWebSocketHandler}} and do not go through that path, so these options are 
not applied to them. On HTTP endpoints the same configuration is applied, 
including the 403 returned when {{allowedRoles}} is set without a provider 
(CAMEL-14987).

h3. Proposed change
* Call the configured provider's {{authenticate()}} with the endpoint's allowed 
roles on the WebSocket upgrade request in {{CamelWebSocketHandler}}, and return 
the same 403 as the HTTP path when {{allowedRoles}} is set without a provider.
* Take the settings from the endpoints registered on the WebSocket path, 
producers included, not only from the consumer.
* Record the result on the WebSocket channel, as is already done for 
{{oauthProfile}} (CAMEL-23723), so every channel is handled consistently, 
including channels opened while the consumer is stopped or restarting, for both 
inbound events and outbound sends.
* Apply the {{handlers}} option (and the access log) to WebSocket consumers.
* Make providers that override {{wrapHttpHandler()}} work with WebSocket 
endpoints; today the WebSocket route fails to start with a 
{{ClassCastException}}.
* Propagate the provider's {{addHeader()}} values to WebSocket exchanges, as 
for HTTP.
* Tests, an update to the "Security provider" section of 
{{undertow-component.adoc}}, and upgrade-guide notes: WebSocket connections 
that do not satisfy the configured provider are now rejected.

_Claude Code on behalf of Andrea Cosentino (oscerd)_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to