[ 
https://issues.apache.org/jira/browse/CAMEL-24815?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on CAMEL-24815 started by Andrea Cosentino.
------------------------------------------------
> camel-opensearch: producer ignores socketTimeout without SSL and scopes basic 
> auth to the first host only
> ---------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24815
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24815
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-opensearch
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> Two divergences in {{OpensearchProducer.createClient()}} versus the 
> camel-elasticsearch equivalent, both affecting real deployments:
> *1. socketTimeout is ignored unless SSL is enabled.* The request-config 
> callback sets only {{setConnectTimeout(...)}}. The {{socketTimeout}} option 
> is applied only inside the {{if (configuration.isEnableSSL())}} branch, via 
> the {{ConnectionConfig}} of the pooling connection manager. So on a 
> *plain-HTTP* OpenSearch endpoint the configured {{socketTimeout}} has no 
> effect, and a slow/stalled node can block the calling thread indefinitely. 
> camel-elasticsearch applies both connect and socket timeouts unconditionally.
> *2. Basic-auth credentials are scoped to the first host only.* Credentials 
> are registered with {{new 
> AuthScope(configuration.getHostAddressesList().get(0))}}, i.e. bound to the 
> first configured host/port. In a multi-host cluster, requests routed to any 
> other node carry no credentials and are rejected with HTTP 401. 
> camel-elasticsearch uses {{AuthScope.ANY}} (match all hosts).
> *Fix:*
> - Add a response timeout to the request-config callback so {{socketTimeout}} 
> is honoured for both plain-HTTP and SSL connections (HttpClient 5: 
> {{setResponseTimeout(...)}}).
> - Register the credentials with a match-all {{AuthScope}} (HttpClient 5: 
> {{new AuthScope(null, null, -1, null, null)}}) so basic auth works across 
> every node of the cluster.
> Backport candidate for camel-4.22.x and camel-4.18.x.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to