gnodet-bot commented on code in PR #27053:
URL: https://github.com/apache/camel/pull/27053#discussion_r4131247785
##########
components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java:
##########
@@ -52,8 +52,17 @@ public void process(Exchange exchange) throws Exception {
private void fetchX509Svid(WorkloadApiClient client, Exchange exchange)
throws Exception {
X509Svid svid = client.fetchX509Context().getDefaultSvid();
Message message = getMessageForResponse(exchange);
- message.setBody(svid);
+ // the identity is always available through the headers, so a route
that only needs it can avoid the key
message.setHeader(SpiffeConstants.SPIFFE_ID,
svid.getSpiffeId().toString());
+ message.setHeader(SpiffeConstants.EXPIRY,
svid.getLeaf().getNotAfter());
+ switch (getEndpoint().getConfiguration().getX509Response()) {
+ // the full SVID carries the private key; the chain does not; id
leaves the body untouched
+ case svid -> message.setBody(svid);
+ case chain -> message.setBody(svid.getChain());
+ case id -> {
+ // leave the body untouched: the identity is exposed through
the headers only
+ }
+ }
Review Comment:
💡 **Suggestion (low):** This switch has no `default` branch. If a new value
is added to `SpiffeX509Response` later, this will silently do nothing — no body
set, no error. The outer switch at line 44 already has a `default -> throw`, so
this is inconsistent.
```suggestion
switch (getEndpoint().getConfiguration().getX509Response()) {
// the full SVID carries the private key; the chain does not; id
leaves the body untouched
case svid -> message.setBody(svid);
case chain -> message.setBody(svid.getChain());
case id -> {
// leave the body untouched: the identity is exposed through
the headers only
}
default -> throw new IllegalArgumentException("Unsupported
x509Response: " + getEndpoint().getConfiguration().getX509Response());
}
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]