davsclaus opened a new pull request, #27070: URL: https://github.com/apache/camel/pull/27070
[CAMEL-25134](https://issues.apache.org/jira/browse/CAMEL-25134) The security policy check matched an insecure option by its **name only** (`SecurityUtils.getSecurityOption` kept only the last segment of the key). So an option of one component that is marked insecure was also reported for every other component, data format or language with an option of the same name: - `tls=false` was reported for every component because of the `tls` option of camel-pinecone - since #26891 (CAMEL-24999), `ssl=false` on camel-clickhouse, camel-netty, camel-netty-http and camel-oaipmh is reported because of the `ssl` option of camel-hivemq Under `camel.main.profile=prod` that fails startup for components that never declared the option insecure. Raised by @oscerd in the review of #26891. **Change** - `UpdateSensitizeHelper` (camel-package-maven-plugin) now also generates which components, data formats and languages declare each security option (`SECURITY-OPTION-OWNERS` block in `SecurityUtils`). Components are listed by their scheme and alternative schemes. The block is between `@formatter:off/on`, one owner per line, as `trustAllCertificates` has 37 owners. - `SecurityUtils.getSecurityOption`: a key that identifies a component, data format or language (`camel.component.<name>.<option>`, `camel.dataformat.<name>.<option>`, `camel.language.<name>.<option>`) is only matched against the security options of that component, data format or language. The name is matched in any case and with or without dashes. - Any other key is still matched by the option name, as before: `camel.ssl.*`, `camel.main.*` (such as `devConsoleEnabled`, which has no owning component), `camel.beans.*`, and plain option names as used by the MCP security scan. So `camel.component.netty.ssl=false` and `camel.component.kafka.tls=false` are no longer reported, while `camel.component.hivemq.ssl=false` and `camel.component.pinecone.tls=false` still are. **Docs** - `security-policy.adoc`: explains how options are matched. The examples used `camel.component.http.trustAllCertificates`, which is not an option of camel-http, and now use camel-aws2-s3. - 4.23 upgrade guide: new camel-main entry. The camel-hivemq entry from #26891 said the `ssl` marker also applies to the other components with an `ssl` option; it now says it applies to camel-hivemq only. **Tests** - `SecurityUtilsTest`: a component option only matches its own security option (ssl/tls), component name with dashes and case, alternative schemes (llm/openai), nested keys, data formats, keys without a component matched by name, and `detectViolations`. - `MainSecurityPolicyTest`: a component with a `tls` option and `insecureSslPolicy=fail` starts. This test fails without the fix. - Two existing tests used keys that are not options of those components (`camel.component.http.trustAllCertificates`, `camel.component.jms.allowJavaSerializedObject`); they now use real ones. `SecurityUtilsTest` (16) and `MainSecurityPolicy*Test` (42) pass locally. Full reactor build (`mvn clean install -DskipTests`) passes with no generated changes. _Claude Code on behalf of davsclaus_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
