Andrea Cosentino created CAMEL-25376:
----------------------------------------
Summary: camel-netty-http - match security constraint roles by
exact role name
Key: CAMEL-25376
URL: https://issues.apache.org/jira/browse/CAMEL-25376
Project: Camel
Issue Type: Bug
Components: camel-netty-http
Reporter: Andrea Cosentino
Assignee: Andrea Cosentino
Fix For: 4.18.5, 4.23.0, 4.22.2
Make {{HttpServerChannelHandler.matchesRoles}} treat the roles configured for a
{{SecurityConstraintMapping}} inclusion as the comma-separated list of role
names described by the {{SecurityConstraint}} contract ("a comma separated
String with roles") and by the component documentation ("access to /admin/*
requires the admin role"), and decide whether the user is in role by exact role
name.
This aligns the role check with how other components handle role lists, for
example {{allowedRoles}} in camel-undertow and {{requiredRoles}} in
camel-keycloak:
* split the configured roles on comma, trim each name and ignore blank entries
* treat the user's roles returned by {{SecurityAuthenticator.getUserRoles}} the
same way
* the user is in role only when one of their roles equals one of the configured
role names (case-sensitive)
* keep {{*}} as the only wildcard value
The {{SecurityConstraint}} SPI and the protected {{matchesRoles(String,
String)}} signature stay unchanged.
Code:
{{components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java}}
Also:
* add tests for the role matching
* document the matching rules in the "Specifying ACL on web resources" section
of the netty-http documentation
* add an upgrade-guide note for roles values that are not comma-separated
_Claude Code on behalf of Andrea Cosentino_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)