Andrea Cosentino created CAMEL-25376:
----------------------------------------

             Summary: camel-netty-http - match security constraint roles by 
exact role name
                 Key: CAMEL-25376
                 URL: https://issues.apache.org/jira/browse/CAMEL-25376
             Project: Camel
          Issue Type: Bug
          Components: camel-netty-http
            Reporter: Andrea Cosentino
            Assignee: Andrea Cosentino
             Fix For: 4.18.5, 4.23.0, 4.22.2


Make {{HttpServerChannelHandler.matchesRoles}} treat the roles configured for a 
{{SecurityConstraintMapping}} inclusion as the comma-separated list of role 
names described by the {{SecurityConstraint}} contract ("a comma separated 
String with roles") and by the component documentation ("access to /admin/* 
requires the admin role"), and decide whether the user is in role by exact role 
name.

This aligns the role check with how other components handle role lists, for 
example {{allowedRoles}} in camel-undertow and {{requiredRoles}} in 
camel-keycloak:

* split the configured roles on comma, trim each name and ignore blank entries
* treat the user's roles returned by {{SecurityAuthenticator.getUserRoles}} the 
same way
* the user is in role only when one of their roles equals one of the configured 
role names (case-sensitive)
* keep {{*}} as the only wildcard value

The {{SecurityConstraint}} SPI and the protected {{matchesRoles(String, 
String)}} signature stay unchanged.

Code: 
{{components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java}}

Also:
* add tests for the role matching
* document the matching rules in the "Specifying ACL on web resources" section 
of the netty-http documentation
* add an upgrade-guide note for roles values that are not comma-separated

_Claude Code on behalf of Andrea Cosentino_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to