[ 
https://issues.apache.org/jira/browse/CAMEL-25026?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino updated CAMEL-25026:
-------------------------------------
    Fix Version/s: 4.23.0

> camel-package-maven-plugin - @Metadata(security/secret) is dropped for model, 
> dataformat and language options
> -------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25026
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25026
>             Project: Camel
>          Issue Type: Bug
>          Components: tooling
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>             Fix For: 4.23.0
>
>
> CAMEL-23250 introduced the {{security}} attribute on {{@Metadata}} and wired 
> it through the *component* JSON pipeline. The model/dataformat/language 
> pipeline was never wired up, so {{@Metadata(security = ...)}} and 
> {{@Metadata(secret = true)}} are silently dropped for every option that is 
> not a component option.
> h3. Root cause
> {{SchemaGeneratorMojo.createOption(...)}} is the single factory for every 
> model, dataformat and language option. It sets name, type, label, default 
> value, deprecation and enums, but never calls {{setSecurity}}, {{setSecret}} 
> or {{setInsecureValue}}. The only {{setSecurity}} call in that class is on 
> the separate {{exchangeProperty}} branch.
> h3. Evidence
> || source annotation || generated catalog ||
> | {{AvroDataFormat.serializablePackages}} -> {{security = 
> "insecure:serialization"}} | {{dataformats/avro.json}}: no {{security}} |
> | {{XMLSecurityDataFormat.passPhrase}} -> {{security = "secret"}} | 
> {{dataformats/xmlSecurity.json}}: {{secret: false}}, no {{security}} |
> | {{XMLSecurityDataFormat.passPhraseByte}}, {{.keyPassword}} -> {{security = 
> "secret"}} | same |
> Catalog-wide: 1370 component options carry {{security}} and *0* of the 2562 
> options under {{dataformats/}}, {{languages/}}, {{models/}} and 
> {{models-app/}} do. Same for {{secret: true}} - 1165 in components, 0 
> elsewhere.
> h3. Consequences
> * The dataformat and language branches of the {{SECURITY_OPTIONS}} generator 
> ({{UpdateSensitizeHelper}}) are dead code: they iterate those models and call 
> {{collectSecurityOption}}, but the input can never carry a marker.
> * {{PackageLanguageMojo}} already copies {{secret}}, {{security}} and 
> {{insecureValue}} from the model option, which shows the propagation is 
> intended - it is simply inert because the upstream value is never set. 
> {{PackageDataFormatMojo}} copies {{secret}} but not 
> {{security}}/{{insecureValue}}, a second and narrower gap.
> * The generated docs are wrong: {{xmlSecurity}}'s {{passPhrase}} renders in 
> the dataformat options table as an ordinary non-secret string option.
> h3. Impact
> No known runtime impact today. All four affected option names are covered by 
> coincidence, because the {{SecurityUtils}}/{{SensitiveUtils}} maps are keyed 
> by bare option name: {{serializablepackages}} reaches {{SECURITY_OPTIONS}} 
> via the avro *component*, and {{passphrase}}/{{keypassword}} are already in 
> the sensitive-keys list via other components.
> The defect is that the failure is silent. The next {{@Metadata(security = 
> ...)}} added to a dataformat or language model whose name is not already 
> covered elsewhere gets no prod-profile enforcement, no camel-jbang scanner 
> coverage and no value masking, with no build error and no visible signal.
> This was found while auditing security-marker consistency across the catalog, 
> not from a user report.
> _Filed by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to