[ 
https://issues.apache.org/jira/browse/CAMEL-25376?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123827#comment-18123827
 ] 

Andrea Cosentino commented on CAMEL-25376:
------------------------------------------

Backported to camel-4.22.x via https://github.com/apache/camel/pull/27441 
(squash commit 169ea05346cf, ships in 4.22.2). The camel-4.18.x backport is 
still pending, so this issue stays open until it merges.

_Claude Code on behalf of oscerd_

> camel-netty-http - match security constraint roles by exact role name
> ---------------------------------------------------------------------
>
>                 Key: CAMEL-25376
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25376
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-netty-http
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.18.5, 4.22.2, 4.23.0
>
>
> Make {{HttpServerChannelHandler.matchesRoles}} treat the roles configured for 
> a {{SecurityConstraintMapping}} inclusion as the comma-separated list of role 
> names described by the {{SecurityConstraint}} contract ("a comma separated 
> String with roles") and by the component documentation ("access to /admin/* 
> requires the admin role"), and decide whether the user is in role by exact 
> role name.
> This aligns the role check with how other components handle role lists, for 
> example {{allowedRoles}} in camel-undertow and {{requiredRoles}} in 
> camel-keycloak:
> * split the configured roles on comma, trim each name and ignore blank entries
> * treat the user's roles returned by {{SecurityAuthenticator.getUserRoles}} 
> the same way
> * the user is in role only when one of their roles equals one of the 
> configured role names (case-sensitive)
> * keep {{*}} as the only wildcard value
> The {{SecurityConstraint}} SPI and the protected {{matchesRoles(String, 
> String)}} signature stay unchanged.
> Code: 
> {{components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java}}
> Also:
> * add tests for the role matching
> * document the matching rules in the "Specifying ACL on web resources" 
> section of the netty-http documentation
> * add an upgrade-guide note for roles values that are not comma-separated
> _Claude Code on behalf of Andrea Cosentino_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to