davsclaus commented on code in PR #27077:
URL: https://github.com/apache/camel/pull/27077#discussion_r4132779601
##########
components/camel-spiffe/src/main/docs/spiffe-component.adoc:
##########
@@ -88,6 +90,23 @@ from("direct:start")
.to("http://backend.example.org/api");
------------------------------------------------------------
+Validate an incoming bearer token on a `platform-http` route, without a bean
to strip the scheme:
+
+[source,yaml]
+------------------------------------------------------------
+- from:
+ uri: "platform-http:/api"
+ steps:
+ # the Authorization: Bearer <token> header is picked up automatically
+ - to:
"spiffe:auth?operation=validateJwtSvid&audience=spiffe://example.org/api"
+ # the token is a credential; drop it before the exchange goes further
+ - removeHeaders: "Authorization"
+ - to: "direct:handleRequest"
+------------------------------------------------------------
+
+A rejected token throws an `IllegalArgumentException`, so an
`onException(IllegalArgumentException.class)` can answer
Review Comment:
This only holds when the token is missing. An invalid or expired token, or a
wrong audience, fails with `io.spiffe.exception.JwtSvidException`, which
extends `java.lang.Exception`, not `IllegalArgumentException`. So the
documented handler misses exactly the rejected-token case, and those requests
get a 500 instead of a 401.
##########
components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java:
##########
@@ -72,9 +72,15 @@ private void validateJwtSvid(WorkloadApiClient client,
Exchange exchange) throws
if (ObjectHelper.isEmpty(token)) {
token = exchange.getIn().getBody(String.class);
}
+ if (ObjectHelper.isEmpty(token)) {
+ // last fallback: a JWT-SVID is presented over HTTP as
"Authorization: Bearer <token>", so an HTTP route
+ // can validate it without a bean to strip the scheme
+ token = bearerToken(exchange.getIn().getHeader("Authorization",
String.class));
Review Comment:
The body is checked before `Authorization`, so on a POST/PUT with a payload
the payload is taken as the token and validation fails, even with a valid
bearer header. And when validation succeeds, the body is replaced with the
`JwtSvid`, so the documented `direct:handleRequest` never sees the request
payload. Suggest checking `Authorization` before the body, or an explicit
token-source option. At minimum the docs should say the fallback only fits
bodiless requests and that the body is replaced.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]