This is an automated email from the ASF dual-hosted git repository.
davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new 6cc0da03324f CAMEL-24999: camel-hivemq - annotate ssl option with
security=insecure:ssl for the security policy framework (#26891)
6cc0da03324f is described below
commit 6cc0da03324fa69d91e29b51f208ff6d01c08f2e
Author: Andrea Cosentino <[email protected]>
AuthorDate: Tue Sep 29 11:15:18 2026 +0200
CAMEL-24999: camel-hivemq - annotate ssl option with security=insecure:ssl
for the security policy framework (#26891)
* CAMEL-24999: camel-hivemq - annotate ssl option with security=insecure:ssl
* CAMEL-24999: camel-hivemq - document the effect of marking ssl
insecure:ssl
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
---
.../apache/camel/catalog/components/hivemq.json | 22 +++---
.../org/apache/camel/component/hivemq/hivemq.json | 22 +++---
.../component/hivemq/HiveMQConfiguration.java | 2 +-
.../java/org/apache/camel/util/SecurityUtils.java | 1 +
.../ROOT/pages/camel-4x-upgrade-guide-4_23.adoc | 12 +++
.../dsl/HivemqComponentBuilderFactory.java | 36 ++++-----
.../endpoint/dsl/HiveMQEndpointBuilderFactory.java | 90 +++++++++++-----------
7 files changed, 99 insertions(+), 86 deletions(-)
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
index d0cdddb1a0a3..9b0950bfb59f 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
@@ -31,11 +31,11 @@
"port": { "index": 4, "kind": "property", "displayName": "Port", "group":
"common", "label": "", "required": false, "type": "integer", "javaType": "int",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883,
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration",
"configurationField": "configuration", "description": "Port number of the
HiveMQ MQTT broker." },
"qos": { "index": 5, "kind": "property", "displayName": "Qos", "group":
"common", "label": "", "required": false, "type": "enum", "javaType":
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE",
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false,
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Default Quality [...]
"retained": { "index": 6, "kind": "property", "displayName": "Retained",
"group": "common", "label": "", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether published messages should be retained
by the MQTT broker." },
- "ssl": { "index": 7, "kind": "property", "displayName": "Ssl", "group":
"common", "label": "", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broker connection." },
- "bridgeErrorHandler": { "index": 8, "kind": "property", "displayName":
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Allows for bridging the consumer to the Camel routing Error Handler, which
mean any exceptions (if possible) occurred while the Camel consumer is trying
to pickup incoming messages, or the like [...]
- "lazyStartProducer": { "index": 9, "kind": "property", "displayName":
"Lazy Start Producer", "group": "producer", "label": "producer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Whether the producer should be started lazy (on the first message). By
starting lazy you can use this to allow CamelContext and routes to startup in
situations where a producer may otherwise fail [...]
- "autowiredEnabled": { "index": 10, "kind": "property", "displayName":
"Autowired Enabled", "group": "advanced", "label": "advanced", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": true, "description":
"Whether autowiring is enabled. This is used for automatic autowiring options
(the option must be marked as autowired) by looking up in the registry to find
if there is a single instance of matching [...]
- "password": { "index": 11, "kind": "property", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "bridgeErrorHandler": { "index": 7, "kind": "property", "displayName":
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Allows for bridging the consumer to the Camel routing Error Handler, which
mean any exceptions (if possible) occurred while the Camel consumer is trying
to pickup incoming messages, or the like [...]
+ "lazyStartProducer": { "index": 8, "kind": "property", "displayName":
"Lazy Start Producer", "group": "producer", "label": "producer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Whether the producer should be started lazy (on the first message). By
starting lazy you can use this to allow CamelContext and routes to startup in
situations where a producer may otherwise fail [...]
+ "autowiredEnabled": { "index": 9, "kind": "property", "displayName":
"Autowired Enabled", "group": "advanced", "label": "advanced", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": true, "description":
"Whether autowiring is enabled. This is used for automatic autowiring options
(the option must be marked as autowired) by looking up in the registry to find
if there is a single instance of matching t [...]
+ "password": { "index": 10, "kind": "property", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "ssl": { "index": 11, "kind": "property", "displayName": "Ssl", "group":
"security", "label": "security", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue":
false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broker [...]
"username": { "index": 12, "kind": "property", "displayName": "Username",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Username for authentication with the HiveMQ
broker." }
},
"headers": {
@@ -52,12 +52,12 @@
"port": { "index": 4, "kind": "parameter", "displayName": "Port", "group":
"common", "label": "", "required": false, "type": "integer", "javaType": "int",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883,
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration",
"configurationField": "configuration", "description": "Port number of the
HiveMQ MQTT broker." },
"qos": { "index": 5, "kind": "parameter", "displayName": "Qos", "group":
"common", "label": "", "required": false, "type": "enum", "javaType":
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE",
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false,
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Default Quality [...]
"retained": { "index": 6, "kind": "parameter", "displayName": "Retained",
"group": "common", "label": "", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether published messages should be retained
by the MQTT broker." },
- "ssl": { "index": 7, "kind": "parameter", "displayName": "Ssl", "group":
"common", "label": "", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broker connection." },
- "bridgeErrorHandler": { "index": 8, "kind": "parameter", "displayName":
"Bridge Error Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Allows for bridging the consumer to the
Camel routing Error Handler, which mean any exceptions (if possible) occurred
while the Camel consumer is trying to pickup incoming [...]
- "exceptionHandler": { "index": 9, "kind": "parameter", "displayName":
"Exception Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "object", "javaType":
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.",
"deprecated": false, "autowired": false, "secret": false, "description": "To
let the consumer use a custom ExceptionHandler. Notice if the option
bridgeErrorHandler is enabled then this option is not in use. By def [...]
- "exchangePattern": { "index": 10, "kind": "parameter", "displayName":
"Exchange Pattern", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "enum", "javaType":
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ],
"deprecated": false, "autowired": false, "secret": false, "description": "Sets
the exchange pattern when the consumer creates an exchange." },
- "lazyStartProducer": { "index": 11, "kind": "parameter", "displayName":
"Lazy Start Producer", "group": "producer (advanced)", "label":
"producer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Whether the producer should be started
lazy (on the first message). By starting lazy you can use this to allow
CamelContext and routes to startup in situations where a produ [...]
- "password": { "index": 12, "kind": "parameter", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "bridgeErrorHandler": { "index": 7, "kind": "parameter", "displayName":
"Bridge Error Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Allows for bridging the consumer to the
Camel routing Error Handler, which mean any exceptions (if possible) occurred
while the Camel consumer is trying to pickup incoming [...]
+ "exceptionHandler": { "index": 8, "kind": "parameter", "displayName":
"Exception Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "object", "javaType":
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.",
"deprecated": false, "autowired": false, "secret": false, "description": "To
let the consumer use a custom ExceptionHandler. Notice if the option
bridgeErrorHandler is enabled then this option is not in use. By def [...]
+ "exchangePattern": { "index": 9, "kind": "parameter", "displayName":
"Exchange Pattern", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "enum", "javaType":
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ],
"deprecated": false, "autowired": false, "secret": false, "description": "Sets
the exchange pattern when the consumer creates an exchange." },
+ "lazyStartProducer": { "index": 10, "kind": "parameter", "displayName":
"Lazy Start Producer", "group": "producer (advanced)", "label":
"producer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Whether the producer should be started
lazy (on the first message). By starting lazy you can use this to allow
CamelContext and routes to startup in situations where a produ [...]
+ "password": { "index": 11, "kind": "parameter", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "ssl": { "index": 12, "kind": "parameter", "displayName": "Ssl", "group":
"security", "label": "security", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue":
false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broke [...]
"username": { "index": 13, "kind": "parameter", "displayName": "Username",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Username for authentication with the HiveMQ
broker." }
}
}
diff --git
a/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
b/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
index d0cdddb1a0a3..9b0950bfb59f 100644
---
a/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
+++
b/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
@@ -31,11 +31,11 @@
"port": { "index": 4, "kind": "property", "displayName": "Port", "group":
"common", "label": "", "required": false, "type": "integer", "javaType": "int",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883,
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration",
"configurationField": "configuration", "description": "Port number of the
HiveMQ MQTT broker." },
"qos": { "index": 5, "kind": "property", "displayName": "Qos", "group":
"common", "label": "", "required": false, "type": "enum", "javaType":
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE",
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false,
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Default Quality [...]
"retained": { "index": 6, "kind": "property", "displayName": "Retained",
"group": "common", "label": "", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether published messages should be retained
by the MQTT broker." },
- "ssl": { "index": 7, "kind": "property", "displayName": "Ssl", "group":
"common", "label": "", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broker connection." },
- "bridgeErrorHandler": { "index": 8, "kind": "property", "displayName":
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Allows for bridging the consumer to the Camel routing Error Handler, which
mean any exceptions (if possible) occurred while the Camel consumer is trying
to pickup incoming messages, or the like [...]
- "lazyStartProducer": { "index": 9, "kind": "property", "displayName":
"Lazy Start Producer", "group": "producer", "label": "producer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Whether the producer should be started lazy (on the first message). By
starting lazy you can use this to allow CamelContext and routes to startup in
situations where a producer may otherwise fail [...]
- "autowiredEnabled": { "index": 10, "kind": "property", "displayName":
"Autowired Enabled", "group": "advanced", "label": "advanced", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": true, "description":
"Whether autowiring is enabled. This is used for automatic autowiring options
(the option must be marked as autowired) by looking up in the registry to find
if there is a single instance of matching [...]
- "password": { "index": 11, "kind": "property", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "bridgeErrorHandler": { "index": 7, "kind": "property", "displayName":
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Allows for bridging the consumer to the Camel routing Error Handler, which
mean any exceptions (if possible) occurred while the Camel consumer is trying
to pickup incoming messages, or the like [...]
+ "lazyStartProducer": { "index": 8, "kind": "property", "displayName":
"Lazy Start Producer", "group": "producer", "label": "producer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Whether the producer should be started lazy (on the first message). By
starting lazy you can use this to allow CamelContext and routes to startup in
situations where a producer may otherwise fail [...]
+ "autowiredEnabled": { "index": 9, "kind": "property", "displayName":
"Autowired Enabled", "group": "advanced", "label": "advanced", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": true, "description":
"Whether autowiring is enabled. This is used for automatic autowiring options
(the option must be marked as autowired) by looking up in the registry to find
if there is a single instance of matching t [...]
+ "password": { "index": 10, "kind": "property", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "ssl": { "index": 11, "kind": "property", "displayName": "Ssl", "group":
"security", "label": "security", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue":
false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broker [...]
"username": { "index": 12, "kind": "property", "displayName": "Username",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Username for authentication with the HiveMQ
broker." }
},
"headers": {
@@ -52,12 +52,12 @@
"port": { "index": 4, "kind": "parameter", "displayName": "Port", "group":
"common", "label": "", "required": false, "type": "integer", "javaType": "int",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883,
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration",
"configurationField": "configuration", "description": "Port number of the
HiveMQ MQTT broker." },
"qos": { "index": 5, "kind": "parameter", "displayName": "Qos", "group":
"common", "label": "", "required": false, "type": "enum", "javaType":
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE",
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false,
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Default Quality [...]
"retained": { "index": 6, "kind": "parameter", "displayName": "Retained",
"group": "common", "label": "", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether published messages should be retained
by the MQTT broker." },
- "ssl": { "index": 7, "kind": "parameter", "displayName": "Ssl", "group":
"common", "label": "", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broker connection." },
- "bridgeErrorHandler": { "index": 8, "kind": "parameter", "displayName":
"Bridge Error Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Allows for bridging the consumer to the
Camel routing Error Handler, which mean any exceptions (if possible) occurred
while the Camel consumer is trying to pickup incoming [...]
- "exceptionHandler": { "index": 9, "kind": "parameter", "displayName":
"Exception Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "object", "javaType":
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.",
"deprecated": false, "autowired": false, "secret": false, "description": "To
let the consumer use a custom ExceptionHandler. Notice if the option
bridgeErrorHandler is enabled then this option is not in use. By def [...]
- "exchangePattern": { "index": 10, "kind": "parameter", "displayName":
"Exchange Pattern", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "enum", "javaType":
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ],
"deprecated": false, "autowired": false, "secret": false, "description": "Sets
the exchange pattern when the consumer creates an exchange." },
- "lazyStartProducer": { "index": 11, "kind": "parameter", "displayName":
"Lazy Start Producer", "group": "producer (advanced)", "label":
"producer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Whether the producer should be started
lazy (on the first message). By starting lazy you can use this to allow
CamelContext and routes to startup in situations where a produ [...]
- "password": { "index": 12, "kind": "parameter", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "bridgeErrorHandler": { "index": 7, "kind": "parameter", "displayName":
"Bridge Error Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Allows for bridging the consumer to the
Camel routing Error Handler, which mean any exceptions (if possible) occurred
while the Camel consumer is trying to pickup incoming [...]
+ "exceptionHandler": { "index": 8, "kind": "parameter", "displayName":
"Exception Handler", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "object", "javaType":
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.",
"deprecated": false, "autowired": false, "secret": false, "description": "To
let the consumer use a custom ExceptionHandler. Notice if the option
bridgeErrorHandler is enabled then this option is not in use. By def [...]
+ "exchangePattern": { "index": 9, "kind": "parameter", "displayName":
"Exchange Pattern", "group": "consumer (advanced)", "label":
"consumer,advanced", "required": false, "type": "enum", "javaType":
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ],
"deprecated": false, "autowired": false, "secret": false, "description": "Sets
the exchange pattern when the consumer creates an exchange." },
+ "lazyStartProducer": { "index": 10, "kind": "parameter", "displayName":
"Lazy Start Producer", "group": "producer (advanced)", "label":
"producer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Whether the producer should be started
lazy (on the first message). By starting lazy you can use this to allow
CamelContext and routes to startup in situations where a produ [...]
+ "password": { "index": 11, "kind": "parameter", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": true, "security": "secret", "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Password for authentication with the HiveMQ
broker." },
+ "ssl": { "index": 12, "kind": "parameter", "displayName": "Ssl", "group":
"security", "label": "security", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue":
false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Whether to enable SSL\/TLS encryption for the
broke [...]
"username": { "index": 13, "kind": "parameter", "displayName": "Username",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "",
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField":
"configuration", "description": "Username for authentication with the HiveMQ
broker." }
}
}
diff --git
a/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
b/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
index aead89a0fde6..47bd662534e4 100644
---
a/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
+++
b/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
@@ -78,7 +78,7 @@ public class HiveMQConfiguration implements Cloneable {
/**
* Whether to enable SSL/TLS encryption for the broker connection.
*/
- @UriParam(defaultValue = "false")
+ @UriParam(defaultValue = "false", label = "security", security =
"insecure:ssl", insecureValue = "false")
private boolean ssl;
public String getHost() {
diff --git
a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
index 8cdcd2972e95..ed7178491d1b 100644
--- a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
+++ b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
@@ -84,6 +84,7 @@ public final class SecurityUtils {
map.put("sendenabled", new SecurityOption(INSECURE_DEV, "true"));
map.put("serializablepackages", new
SecurityOption(INSECURE_SERIALIZATION, ""));
map.put("skiptlsverify", new SecurityOption(INSECURE_SSL, "true"));
+ map.put("ssl", new SecurityOption(INSECURE_SSL, VALUE_FALSE));
map.put("sslendpointalgorithm", new SecurityOption(INSECURE_SSL,
"none"));
map.put("stricthostkeychecking", new SecurityOption(INSECURE_SSL, ""));
map.put("tls", new SecurityOption(INSECURE_SSL, VALUE_FALSE));
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index c62c31eddd11..04d6027f2ded 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -1230,6 +1230,18 @@ component publishes events in the CloudEvents schema,
which has no `dataVersion`
belongs to the legacy Event Grid event schema), so the header was read but
never applied to the
published event. Remove any use of that header; there is no CloudEvents
equivalent.
+=== camel-hivemq
+
+The `ssl` option is now marked `insecure:ssl`, so setting it to `false` in the
configuration is reported
+by the xref:security-policy.adoc[security policy] check: a warning by default,
and a startup failure with
+the `prod` profile or `camel.security.insecureSslPolicy = fail`.
+
+The check matches a configuration property by its option name, not by its
component. It therefore also
+applies when `ssl=false` is set on the other components that have an `ssl`
option: `camel-clickhouse`,
+`camel-netty`, `camel-netty-http` and `camel-oaipmh`, for example
`camel.component.netty.ssl = false` in
+`application.properties`. The `tls` option of `camel-pinecone` already worked
this way for `tls=false`. To
+keep such a setting under a `fail` policy, list it in
`camel.security.allowedProperties`.
+
=== camel-hazelcast
`ReplicatedHazelcastAggregationRepository` now applies the same default
diff --git
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
index 8259ec7da490..01a5ac2a0b7e 100644
---
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
+++
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
@@ -170,23 +170,6 @@ public interface HivemqComponentBuilderFactory {
}
- /**
- * Whether to enable SSL/TLS encryption for the broker connection.
- *
- * The option is a: <code>boolean</code> type.
- *
- * Default: false
- * Group: common
- *
- * @param ssl the value to set
- * @return the dsl builder
- */
- default HivemqComponentBuilder ssl(boolean ssl) {
- doSetProperty("ssl", ssl);
- return this;
- }
-
-
/**
* Allows for bridging the consumer to the Camel routing Error Handler,
* which mean any exceptions (if possible) occurred while the Camel
@@ -276,6 +259,23 @@ public interface HivemqComponentBuilderFactory {
return this;
}
+
+ /**
+ * Whether to enable SSL/TLS encryption for the broker connection.
+ *
+ * The option is a: <code>boolean</code> type.
+ *
+ * Default: false
+ * Group: security
+ *
+ * @param ssl the value to set
+ * @return the dsl builder
+ */
+ default HivemqComponentBuilder ssl(boolean ssl) {
+ doSetProperty("ssl", ssl);
+ return this;
+ }
+
/**
* Username for authentication with the HiveMQ broker.
*
@@ -318,11 +318,11 @@ public interface HivemqComponentBuilderFactory {
case "port": getOrCreateConfiguration((HiveMQComponent)
component).setPort((int) value); return true;
case "qos": getOrCreateConfiguration((HiveMQComponent)
component).setQos((com.hivemq.client.mqtt.datatypes.MqttQos) value); return
true;
case "retained": getOrCreateConfiguration((HiveMQComponent)
component).setRetained((boolean) value); return true;
- case "ssl": getOrCreateConfiguration((HiveMQComponent)
component).setSsl((boolean) value); return true;
case "bridgeErrorHandler": ((HiveMQComponent)
component).setBridgeErrorHandler((boolean) value); return true;
case "lazyStartProducer": ((HiveMQComponent)
component).setLazyStartProducer((boolean) value); return true;
case "autowiredEnabled": ((HiveMQComponent)
component).setAutowiredEnabled((boolean) value); return true;
case "password": getOrCreateConfiguration((HiveMQComponent)
component).setPassword((java.lang.String) value); return true;
+ case "ssl": getOrCreateConfiguration((HiveMQComponent)
component).setSsl((boolean) value); return true;
case "username": getOrCreateConfiguration((HiveMQComponent)
component).setUsername((java.lang.String) value); return true;
default: return false;
}
diff --git
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
index ab433976f180..80a520c3918c 100644
---
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
+++
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
@@ -197,47 +197,47 @@ public interface HiveMQEndpointBuilderFactory {
return this;
}
/**
- * Whether to enable SSL/TLS encryption for the broker connection.
+ * Password for authentication with the HiveMQ broker.
*
- * The option is a: <code>boolean</code> type.
+ * The option is a: <code>java.lang.String</code> type.
*
- * Default: false
- * Group: common
+ * Group: security
*
- * @param ssl the value to set
+ * @param password the value to set
* @return the dsl builder
*/
- default HiveMQEndpointConsumerBuilder ssl(boolean ssl) {
- doSetProperty("ssl", ssl);
+ default HiveMQEndpointConsumerBuilder password(String password) {
+ doSetProperty("password", password);
return this;
}
/**
* Whether to enable SSL/TLS encryption for the broker connection.
*
- * The option will be converted to a <code>boolean</code> type.
+ * The option is a: <code>boolean</code> type.
*
* Default: false
- * Group: common
+ * Group: security
*
* @param ssl the value to set
* @return the dsl builder
*/
- default HiveMQEndpointConsumerBuilder ssl(String ssl) {
+ default HiveMQEndpointConsumerBuilder ssl(boolean ssl) {
doSetProperty("ssl", ssl);
return this;
}
/**
- * Password for authentication with the HiveMQ broker.
+ * Whether to enable SSL/TLS encryption for the broker connection.
*
- * The option is a: <code>java.lang.String</code> type.
+ * The option will be converted to a <code>boolean</code> type.
*
+ * Default: false
* Group: security
*
- * @param password the value to set
+ * @param ssl the value to set
* @return the dsl builder
*/
- default HiveMQEndpointConsumerBuilder password(String password) {
- doSetProperty("password", password);
+ default HiveMQEndpointConsumerBuilder ssl(String ssl) {
+ doSetProperty("ssl", ssl);
return this;
}
/**
@@ -548,47 +548,47 @@ public interface HiveMQEndpointBuilderFactory {
return this;
}
/**
- * Whether to enable SSL/TLS encryption for the broker connection.
+ * Password for authentication with the HiveMQ broker.
*
- * The option is a: <code>boolean</code> type.
+ * The option is a: <code>java.lang.String</code> type.
*
- * Default: false
- * Group: common
+ * Group: security
*
- * @param ssl the value to set
+ * @param password the value to set
* @return the dsl builder
*/
- default HiveMQEndpointProducerBuilder ssl(boolean ssl) {
- doSetProperty("ssl", ssl);
+ default HiveMQEndpointProducerBuilder password(String password) {
+ doSetProperty("password", password);
return this;
}
/**
* Whether to enable SSL/TLS encryption for the broker connection.
*
- * The option will be converted to a <code>boolean</code> type.
+ * The option is a: <code>boolean</code> type.
*
* Default: false
- * Group: common
+ * Group: security
*
* @param ssl the value to set
* @return the dsl builder
*/
- default HiveMQEndpointProducerBuilder ssl(String ssl) {
+ default HiveMQEndpointProducerBuilder ssl(boolean ssl) {
doSetProperty("ssl", ssl);
return this;
}
/**
- * Password for authentication with the HiveMQ broker.
+ * Whether to enable SSL/TLS encryption for the broker connection.
*
- * The option is a: <code>java.lang.String</code> type.
+ * The option will be converted to a <code>boolean</code> type.
*
+ * Default: false
* Group: security
*
- * @param password the value to set
+ * @param ssl the value to set
* @return the dsl builder
*/
- default HiveMQEndpointProducerBuilder password(String password) {
- doSetProperty("password", password);
+ default HiveMQEndpointProducerBuilder ssl(String ssl) {
+ doSetProperty("ssl", ssl);
return this;
}
/**
@@ -828,47 +828,47 @@ public interface HiveMQEndpointBuilderFactory {
return this;
}
/**
- * Whether to enable SSL/TLS encryption for the broker connection.
+ * Password for authentication with the HiveMQ broker.
*
- * The option is a: <code>boolean</code> type.
+ * The option is a: <code>java.lang.String</code> type.
*
- * Default: false
- * Group: common
+ * Group: security
*
- * @param ssl the value to set
+ * @param password the value to set
* @return the dsl builder
*/
- default HiveMQEndpointBuilder ssl(boolean ssl) {
- doSetProperty("ssl", ssl);
+ default HiveMQEndpointBuilder password(String password) {
+ doSetProperty("password", password);
return this;
}
/**
* Whether to enable SSL/TLS encryption for the broker connection.
*
- * The option will be converted to a <code>boolean</code> type.
+ * The option is a: <code>boolean</code> type.
*
* Default: false
- * Group: common
+ * Group: security
*
* @param ssl the value to set
* @return the dsl builder
*/
- default HiveMQEndpointBuilder ssl(String ssl) {
+ default HiveMQEndpointBuilder ssl(boolean ssl) {
doSetProperty("ssl", ssl);
return this;
}
/**
- * Password for authentication with the HiveMQ broker.
+ * Whether to enable SSL/TLS encryption for the broker connection.
*
- * The option is a: <code>java.lang.String</code> type.
+ * The option will be converted to a <code>boolean</code> type.
*
+ * Default: false
* Group: security
*
- * @param password the value to set
+ * @param ssl the value to set
* @return the dsl builder
*/
- default HiveMQEndpointBuilder password(String password) {
- doSetProperty("password", password);
+ default HiveMQEndpointBuilder ssl(String ssl) {
+ doSetProperty("ssl", ssl);
return this;
}
/**