gnodet-bot commented on code in PR #27053:
URL: https://github.com/apache/camel/pull/27053#discussion_r4131247785


##########
components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java:
##########
@@ -52,8 +52,17 @@ public void process(Exchange exchange) throws Exception {
     private void fetchX509Svid(WorkloadApiClient client, Exchange exchange) 
throws Exception {
         X509Svid svid = client.fetchX509Context().getDefaultSvid();
         Message message = getMessageForResponse(exchange);
-        message.setBody(svid);
+        // the identity is always available through the headers, so a route 
that only needs it can avoid the key
         message.setHeader(SpiffeConstants.SPIFFE_ID, 
svid.getSpiffeId().toString());
+        message.setHeader(SpiffeConstants.EXPIRY, 
svid.getLeaf().getNotAfter());
+        switch (getEndpoint().getConfiguration().getX509Response()) {
+            // the full SVID carries the private key; the chain does not; id 
leaves the body untouched
+            case svid -> message.setBody(svid);
+            case chain -> message.setBody(svid.getChain());
+            case id -> {
+                // leave the body untouched: the identity is exposed through 
the headers only
+            }
+        }

Review Comment:
   💡 **Suggestion (low):** This switch has no `default` branch. If a new value 
is added to `SpiffeX509Response` later, this will silently do nothing — no body 
set, no error. The outer switch at line 44 already has a `default -> throw`, so 
this is inconsistent.
   
   ```suggestion
           switch (getEndpoint().getConfiguration().getX509Response()) {
               // the full SVID carries the private key; the chain does not; id 
leaves the body untouched
               case svid -> message.setBody(svid);
               case chain -> message.setBody(svid.getChain());
               case id -> {
                   // leave the body untouched: the identity is exposed through 
the headers only
               }
               default -> throw new IllegalArgumentException("Unsupported 
x509Response: " + getEndpoint().getConfiguration().getX509Response());
           }
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to