[ 
https://issues.apache.org/jira/browse/CAMEL-24831?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen reassigned CAMEL-24831:
-----------------------------------

    Assignee: Andrea Cosentino

> camel-ai-tool - component-level authorization hook so tool routes are guarded 
> by construction
> ---------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24831
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24831
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-ai
>            Reporter: Claus Ibsen
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> h2. Problem
> A route exposed with {{ai-tool:}} is invoked by an AI agent (LangChain4j, 
> Spring AI, OpenAI, or the built-in MCP server) based on model output, so the 
> tool call is the security boundary. Today an authorization check has to be 
> added per route, either with {{.policy(authorizationPolicy)}} or with 
> {{routeConfigurationId}} pointing at a route configuration with an 
> {{interceptFrom}} guard. Both are opt-in: a tool route whose author forgets 
> the line is silently unguarded, which is the wrong default for a security 
> control.
> h2. Proposal
> Let {{camel-ai-tool}} own the guard so every tool route is protected by 
> construction:
> * Add an {{authorizationPolicy}} option (a {{#bean}} reference to an 
> {{org.apache.camel.spi.AuthorizationPolicy}}) on the {{ai-tool}} component, 
> applied to all tool routes, with an endpoint-level override.
> * Implementation options: wrap the consumer's processor with 
> {{Policy.wrap(route, processor)}}, or ship a {{RoutePolicyFactory}} that 
> matches routes whose {{from}} is {{ai-tool:}} and wraps them. The check must 
> run inside the route's processors (not as an internal-processor advice) so a 
> deny is visible to tracing, route dump and the TUI.
> * A deny ({{CamelAuthorizationException}}) should surface to the agent as a 
> short refusal the model can relay, instead of a silent failure or a stack 
> trace.
> * Make the policy input trustworthy: the tool name comes from the route/tool 
> id, never from model output; caller identity from an exchange property set 
> before the agent runs (e.g. by camel-spiffe or camel-keycloak) which the 
> model cannot set.
> * The same guard must apply when the tools are served over the MCP server 
> (camel-mcp-server), since it uses the same registry.
> Related: CAMEL-24743 and CAMEL-24830 (OpaSecurityPolicy WASM mode; in-process 
> OPA is the natural policy to plug in here).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to