oscerd commented on code in PR #26891:
URL: https://github.com/apache/camel/pull/26891#discussion_r4122391483
##########
core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java:
##########
@@ -84,6 +84,7 @@ public record SecurityOption(String category, String
insecureValue) {
map.put("sendenabled", new SecurityOption(INSECURE_DEV, "true"));
map.put("serializablepackages", new
SecurityOption(INSECURE_SERIALIZATION, ""));
map.put("skiptlsverify", new SecurityOption(INSECURE_SSL, "true"));
+ map.put("ssl", new SecurityOption(INSECURE_SSL, VALUE_FALSE));
Review Comment:
Good point, thanks. `SecurityUtils.getSecurityOption` keeps only the last
segment of the key, so the new `ssl` entry does flag
`camel.component.{clickhouse,netty,netty-http,oaipmh}.ssl=false`. That's a
warning by default and a startup failure under `prod`. I confirmed in the
catalog that those four, plus hivemq, are the only components with an `ssl`
option. The check covers only the camel-main auto-configured properties
(`BaseMainSupport.enforceSecurityPolicies`), not endpoint URIs.
Done in 521cf7c: a `camel-hivemq` entry in the 4.23 upgrade guide. It covers
the new marker, and the fact that matching is by option name, so it also
reaches those four components. It names the existing `tls` precedent
(camel-pinecone) and points to `camel.security.allowedProperties` for keeping
such a setting under a `fail` policy.
On the follow-up: I'd rather not annotate the four other `ssl` options as
`insecure:ssl` just to line the catalog up with this. Plaintext netty TCP is a
legitimate choice, and that would make the warning intentional for them. The
cleaner fix is to make the lookup component-aware, so
`camel.component.<name>.<option>` is checked against that component's own
metadata. That would fix `tls` as well. I'll raise it as a separate Jira rather
than widen this PR.
_Claude Code on behalf of @oscerd_
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]