[ 
https://issues.apache.org/jira/browse/CAMEL-24554?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109783#comment-18109783
 ] 

Andrea Cosentino commented on CAMEL-24554:
------------------------------------------

Upgrade-guide entry for this change is in apache/camel PR 
https://github.com/apache/camel/pull/25932 
(docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc).

----
_Comment added by Claude Code on behalf of Andrea Cosentino._

> camel-jolokia-starter - agent binds all interfaces by default and the bundled 
> restrictor gates on MBean domain only
> -------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24554
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24554
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-spring-boot-starters
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> The Jolokia starter's shipped defaults are broader than the defaults of the 
> Jolokia agent it wraps, and the
> bundled restrictor is narrower in name than in effect.
> *Bind address and activation*
> {code:java}
> @ConditionalOnProperty(name = "camel.component.jolokia.enabled", havingValue 
> = "true", matchIfMissing = true)
> ...
> setDefaultConfigValue("host", "0.0.0.0");
> setDefaultConfigValue("autoStart", "true");
> {code}
> (JolokiaComponentAutoConfiguration:39, 87-88)
> With {{matchIfMissing=true}}, adding the starter to the classpath is enough 
> to start the agent, and the starter
> hard-defaults the bind address to all interfaces. The Jolokia JVM agent's own 
> upstream default is loopback. TLS
> is configured only when the Kubernetes service-account CA file is present on 
> disk, so other deployment shapes
> get plain HTTP, and {{discoveryEnabled}} is turned on off-Kubernetes.
> *Restrictor capability gating*
> {code:java}
> public class CamelRestrictor extends AllowAllRestrictor {
>     @Override
>     public boolean isAttributeWriteAllowed(ObjectName pName, String 
> pAttribute) {
>         return objectNameEvaluator.apply(pName);
>     }
>     @Override
>     public boolean isOperationAllowed(ObjectName pName, String pOperation) {
>         return objectNameEvaluator.apply(pName);
>     }
> {code}
> (restrictor/CamelRestrictor:26)
> {{CamelRestrictor}} extends {{AllowAllRestrictor}} and evaluates the MBean 
> *domain* only. Attribute writes and
> operation invocations are therefore permitted for every MBean in the allowed 
> domains, and {{isOriginAllowed}} is
> not overridden at all, so the permissive base-class behaviour applies. The 
> starter documentation describes the
> restrictor as limiting access to Camel MBeans, which describes the namespace 
> but not the capability.
> Note that {{camel-management-starter}} is a compile dependency of this 
> starter (pom.xml), so the management
> MBeans are present whenever the starter is.
> *Proposal*
> - Default {{host}} to {{127.0.0.1}}, matching the wrapped agent's own default.
> - Gate attribute write and operation invocation behind an explicit opt-in, 
> defaulting to read-only.
> - Override {{isOriginAllowed}} with a configurable allowlist rather than 
> inheriting the permissive default.
> - Update {{intro.adoc}} / {{usage.adoc}} to state the actual default posture.
> Both items live in the same starter and share the same reachability, so they 
> are best changed together. Tests
> should assert the default bind address and that write and exec are refused 
> unless explicitly enabled.
> These are deliberate changes to shipped defaults and need an upgrade-guide 
> entry.
> ----
> _This issue was drafted by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to