oscerd commented on issue #2980:
URL: 
https://github.com/apache/camel-kamelets/issues/2980#issuecomment-5865434576

   Direction (a) chosen — PR: #3066.
   
   Dropped the `args` / `ce-args` mapping from the template and the Optional 
Headers section from the doc partial. `camel-exec`'s secure default is left 
alone; option (b) stays on the table if the feature is ever actually wanted, 
with the upgrade-guide entry and PMC sign-off it would need.
   
   **Confirmed the removal is a no-op** before shipping it. `camel run` on 
Camel 4.22.0, calling the Kamelet with `executable=echo` and an `args` header, 
against the template before and after:
   
   | | stdout | `CamelExecCommandArgs` after the call |
   |---|---|---|
   | old | `[\n]` — echo ran with no args | `HEADER-ARGS` — mapped, then 
ignored |
   | new | `[\n]` — identical | *(unset)* |
   
   Control on the same runtime, so the empty stdout is the header being ignored 
and not a silent exec failure:
   
   ```
   A) CamelExecCommandArgs header -> stdout=[]
   B) exec:echo?args=URI-ARGS     -> stdout=[URI-ARGS]
   ```
   
   One thing I had not expected: the mapping's only observable effect was 
leaving `CamelExecCommandArgs` set on the *outgoing* message. Removing it also 
stops that internal dispatch header propagating downstream, which is a small 
win given what the security model says about stray `Camel*` headers.
   
   **One extra file in the PR.** `docs/modules/ROOT/pages/security-model.adoc` 
used this exact mapping as its worked example of "a Kamelet doing, by design, 
the dangerous thing it is named for", so it would have been left describing 
behaviour that no longer exists. Corrected in the same change — `exec-sink` 
still belongs in that bullet, it just no longer reads anything from the message.
   
   ---
   _Claude Code on behalf of Andrea Cosentino_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to