Andrea Cosentino created CAMEL-25162:
----------------------------------------
Summary: camel-oauth - confine the reconstructed post-login URL to
the configured redirect URI origin
Key: CAMEL-25162
URL: https://issues.apache.org/jira/browse/CAMEL-25162
Project: Camel
Issue Type: Improvement
Components: camel-oauth
Reporter: Andrea Cosentino
{{OAuthCodeFlowProcessor.getPostLoginUrl()}} rebuilds the absolute post-login
URL from the inbound {{X-Forwarded-Proto}} / {{X-Forwarded-Host}} /
{{X-Forwarded-Port}} request headers and stores it in the OAuth session.
{{OAuthCodeFlowCallback}} later emits that value as the {{Location}} header of
the post-login redirect.
The reconstruction was added in CAMEL-21899 so that deployments behind an
OpenShift Route/Ingress redirect to the externally reachable URL rather than
the internally observed one. That behaviour must be preserved.
The assembled origin is never compared against the deployment's own origin, so
the forwarded header values are used as-is. The component should confine the
result:
* derive the expected origin from the configured {{CAMEL_OAUTH_REDIRECT_URI}}
* accept the {{X-Forwarded-*}} reconstruction only when the resulting origin
matches it
* fall back to the configured origin otherwise
Two smaller issues in the same method:
* {{X-Forwarded-Host}} may be a comma-separated list when several proxies are
chained ({{host1, host2}}); the current code concatenates the whole list into
the URL and produces a malformed value.
* The {{else}} branch returns {{Exchange.HTTP_URL}} unchanged, with no
confinement either.
h3. Affected code
*
{{components/camel-oauth/src/main/java/org/apache/camel/oauth/OAuthCodeFlowProcessor.java}}
({{getPostLoginUrl}})
h3. Acceptance
Unit tests covering a matching origin, a non-matching origin, a comma-separated
{{X-Forwarded-Host}}, and absent forwarded headers.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)