[
https://issues.apache.org/jira/browse/CAMEL-24973?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Work on CAMEL-24973 started by Andrea Cosentino.
------------------------------------------------
> camel-util - URISupport.sanitizeUri does not follow the endpoint URI parser
> for RAW values, userinfo, dash-case option names and additional keywords
> ----------------------------------------------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-24973
> URL: https://issues.apache.org/jira/browse/CAMEL-24973
> Project: Camel
> Issue Type: Bug
> Components: camel-core
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Minor
> Fix For: 4.23.0
>
>
> URISupport.sanitizeUri() masks option values with regular expressions that do
> not always match how Camel parses and binds endpoint URIs, so some values are
> only partly masked or not masked:
> * RAW values: the sanitizer ends RAW(...) and RAW\{...\} at the first closing
> bracket, while URIScanner ends them at a closing bracket followed by & or the
> end of the string (see URISupportTest#testParseQuery).
> EndpointUriFactorySupport and YamlSupport wrap secret options in RAW()
> automatically.
> * Userinfo: USERINFO_PASSWORD is not limited to the authority component, so
> when a later part of the string contains another :// and @ the wrong segment
> is replaced.
> * Option names: names are matched literally against the sensitive keywords,
> but property binding also accepts dash-case names
> (PropertyBindingSupport.undashKey) and SensitiveUtils.containsSensitive()
> ignores '-' (CAMEL-16146). Dash-case forms such as connection-string,
> private-key, shared-access-key or sasl-jaas-config are not masked.
> * addSanitizeKeywords() (CAMEL-22365): the extra pattern is applied with
> replaceFirst, each call replaces the previously added keywords although the
> javadoc says they are added, and a call with only built-in keywords compiles
> an empty alternation.
> Related: DefaultComponent.validateParameters(), ScheduledPollConsumer and
> JettyHttpComponent12 list unknown parameters with their values ("Unknown
> parameters=\[...\]") without applying the same masking.
> Proposed change: align RAW termination with URIScanner, scope the userinfo
> match to the authority, normalize option names before keyword matching, apply
> additional keywords to every match and accumulate them, mask sensitive values
> in the unknown-parameters message, and add URISupportTest coverage for each
> case.
> _Claude Code on behalf of oscerd_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)