shashank created CAMEL-25081:
--------------------------------

             Summary: camel-bean - a comma inside ${...} in the method 
parameters splits the parameter, so OGNL calls with several arguments fail 
(e.g. ${body.substring(0, 2)})
                 Key: CAMEL-25081
                 URL: https://issues.apache.org/jira/browse/CAMEL-25081
             Project: Camel
          Issue Type: Bug
          Components: camel-bean
            Reporter: shashank


When the method option of the Bean EIP binds parameters from the method name, 
{{MethodInfo}} 
({{core/camel-core-processor/.../component/bean/MethodInfo.java:606-613}} on 
main) takes the text between the outer parentheses with 
{{StringHelper.betweenOuterPair}} and splits it with 
{{StringQuoteHelper.splitSafeQuote(methodParameters, ',', true, true)}}. 
{{splitSafeQuote}} only honours quotes, so it also splits at a comma inside a 
Simple expression {{$\{...\}}}, for example the arguments of an OGNL method 
call. Each half is then evaluated as its own Simple expression, which is not 
closed, and every exchange fails.

h3. Reproduction

Main (dbdd4b381), bean {{echo(String s)}} returns {{[s]}} and {{two(String a, 
String b)}} returns {{[a|b]}}:
{noformat}
bean(MyBean.class, "echo(${body.substring(0, 3)})")               body abcdef
  -> SimpleParserException: expected symbol functionEnd but was eol: missing } 
to close the function
  expected [abc]
bean(MyBean.class, "two(${body}, ${header.v.replace('a', 'b')})") body X, 
header v = aaa
  -> SimpleParserException: expected symbol functionEnd but was eol: missing } 
to close the function
  expected [X|bbb]
controls: echo(${body}), two(${body}, ${header.v}), echo('a,b') work
{noformat}
It fails loudly (not silently) and there is a workaround: compute the value 
into a header first and pass {{$\{header.x\}}}. A jqwik property over 
{{$\{body.substring(i, j)\}}} fails for every input.

This is the same class of problem that CAMEL-24967 fixed for the arguments of 
Simple functions (a comma or parenthesis inside a nested {{$\{...\}}} or a 
quoted argument split the arguments). The bean parameter parsing was not part 
of that change. It was found while working on CAMEL-25033 (PR #26908), which 
changes how the parameter values are evaluated but not how the parameter text 
is split.

h3. Proposed fix

Split the parameter text with a depth-aware splitter that ignores the separator 
inside quotes, inside {{$\{...\}}} and inside parentheses, as CAMEL-24967 did 
for Simple functions. A Lean model of the splitter shows that for every input 
in which no comma sits inside brackets, the depth-aware splitter gives exactly 
the result of {{splitSafeQuote}} today (for example {{$\{body\}, 
$\{header.foo\}}}, {{'a,b', 5}}, {{*, true}}), so only the inputs that fail 
today change.

Tests: {{BeanParameterValueTest}} (or similar) with {{echo($\{body.substring(0, 
3)\})}} and {{two($\{body\}, $\{header.v.replace('a', 'b')\})}}; the existing 
parameter binding tests must keep passing.

Duplicate check (2026-09-28): JIRA {{component = camel-bean AND text ~ OGNL AND 
text ~ parameter}} and {{text ~ "method name" AND text ~ comma}} return only 
CAMEL-24967 (Simple functions). No open PR.

_Filed with Claude Code on behalf of allthingssecurity._




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to