Andrea Cosentino created CAMEL-25134:
----------------------------------------

             Summary: camel-main - security policy check matches options by 
name only, so one component's insecure marker applies to all
                 Key: CAMEL-25134
                 URL: https://issues.apache.org/jira/browse/CAMEL-25134
             Project: Camel
          Issue Type: Improvement
          Components: camel-main
            Reporter: Andrea Cosentino


SecurityUtils.getSecurityOption keeps only the last segment of a configuration 
key, so the insecure:ssl / insecure:dev / insecure:serialization markers 
generated from one component's @UriParam(security=...) apply to every component 
that has an option with the same name.

Examples: tls=false is flagged for any component because of camel-pinecone's 
tls option, and, once CAMEL-24999 lands, ssl=false set on camel-clickhouse, 
camel-netty, camel-netty-http or camel-oaipmh is flagged because of 
camel-hivemq's ssl option. Under camel.main.profile=prod that fails startup for 
components that never declared the option insecure.

Suggested improvement: make the check in 
BaseMainSupport.enforceSecurityPolicies component-aware, so that 
camel.component.<name>.<option> is matched against that component's own option 
metadata, and fall back to the name-only lookup only for keys that do not 
identify a component.

Raised in the review of https://github.com/apache/camel/pull/26891 
(CAMEL-24999).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to