[
https://issues.apache.org/jira/browse/CAMEL-25375?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123830#comment-18123830
]
Claus Ibsen commented on CAMEL-25375:
-------------------------------------
Merged in https://github.com/apache/camel/pull/27443 (commit 13a78504f2c5) for
4.23.0.
_Claude Code on behalf of davsclaus_
> camel-undertow - Apply securityProvider, allowedRoles and handlers to
> WebSocket endpoints consistently with HTTP endpoints
> --------------------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25375
> URL: https://issues.apache.org/jira/browse/CAMEL-25375
> Project: Camel
> Issue Type: Bug
> Components: camel-undertow
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.18.5, 4.22.2, 4.23.0
>
>
> The undertow component applies the {{UndertowSecurityProvider}} (configured
> with {{securityConfiguration}} or {{securityProvider}}), the {{allowedRoles}}
> option and the {{handlers}} option in the HTTP request path:
> {{UndertowConsumer.handleRequest()}} and the handler chain built in
> {{UndertowConsumer.doStart()}}.
> WebSocket endpoints ({{ws://}}, {{wss://}}) are served by
> {{CamelWebSocketHandler}} and do not go through that path, so these options
> are not applied to them. On HTTP endpoints the same configuration is applied,
> including the 403 returned when {{allowedRoles}} is set without a provider
> (CAMEL-14987).
> h3. Proposed change
> * Call the configured provider's {{authenticate()}} with the endpoint's
> allowed roles on the WebSocket upgrade request in {{CamelWebSocketHandler}},
> and return the same 403 as the HTTP path when {{allowedRoles}} is set without
> a provider.
> * Take the settings from the endpoints registered on the WebSocket path,
> producers included, not only from the consumer.
> * Record the result on the WebSocket channel, as is already done for
> {{oauthProfile}} (CAMEL-23723), so every channel is handled consistently,
> including channels opened while the consumer is stopped or restarting, for
> both inbound events and outbound sends.
> * Apply the {{handlers}} option (and the access log) to WebSocket consumers.
> * Make providers that override {{wrapHttpHandler()}} work with WebSocket
> endpoints; today the WebSocket route fails to start with a
> {{ClassCastException}}.
> * Propagate the provider's {{addHeader()}} values to WebSocket exchanges, as
> for HTTP.
> * Tests, an update to the "Security provider" section of
> {{undertow-component.adoc}}, and upgrade-guide notes: WebSocket connections
> that do not satisfy the configured provider are now rejected.
> _Claude Code on behalf of Andrea Cosentino (oscerd)_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)