Andrea Cosentino created CAMEL-25134:
----------------------------------------
Summary: camel-main - security policy check matches options by
name only, so one component's insecure marker applies to all
Key: CAMEL-25134
URL: https://issues.apache.org/jira/browse/CAMEL-25134
Project: Camel
Issue Type: Improvement
Components: camel-main
Reporter: Andrea Cosentino
SecurityUtils.getSecurityOption keeps only the last segment of a configuration
key, so the insecure:ssl / insecure:dev / insecure:serialization markers
generated from one component's @UriParam(security=...) apply to every component
that has an option with the same name.
Examples: tls=false is flagged for any component because of camel-pinecone's
tls option, and, once CAMEL-24999 lands, ssl=false set on camel-clickhouse,
camel-netty, camel-netty-http or camel-oaipmh is flagged because of
camel-hivemq's ssl option. Under camel.main.profile=prod that fails startup for
components that never declared the option insecure.
Suggested improvement: make the check in
BaseMainSupport.enforceSecurityPolicies component-aware, so that
camel.component.<name>.<option> is matched against that component's own option
metadata, and fall back to the name-only lookup only for keys that do not
identify a component.
Raised in the review of https://github.com/apache/camel/pull/26891
(CAMEL-24999).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)