oscerd opened a new pull request, #26583:
URL: https://github.com/apache/camel/pull/26583

   Backport of #25406 to `camel-4.22.x`.
   
   Straight cherry-pick of `54041cce545322f7ff1bb362ecc02999b3d96ba0`, with the 
upgrade-guide changes dropped — those live on `main` only.
   
   `WebhookUrlValidator` classified a webhook host in two places that did not 
agree. A host written as an IP literal was matched against a string prefix 
list, while a host reached through a name was classified with the `InetAddress` 
predicates — and those do not cover the same ground, since `isSiteLocalAddress` 
reports the deprecated `fec0::/10` block and not the `fc00::/7` unique local 
addresses that replaced it. The same address was therefore accepted or rejected 
depending on how it was written. The literal pre-check was also wrong in the 
other direction: it prefix-matched the raw host string without first 
establishing that the host was an IP literal, so any name beginning with `fc` 
or `fd` (e.g. `fcm.googleapis.com`) was refused outright.
   
   Both paths now resolve the host and classify the resulting address with one 
shared raw-byte classifier.
   
   Verified locally: `mvn install -DskipITs` in `components/camel-ai/camel-a2a` 
— 519 tests, 0 failures (30 in `WebhookUrlValidatorTest`).
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to