oscerd opened a new pull request, #27497:
URL: https://github.com/apache/camel/pull/27497

   Follow-up to CAMEL-25409 / #27482, which fixed the three hand-written 
components but deliberately left this one out because the configuration class 
is generated.
   
   `mongodbSslInvalidHostnameAllowed` turns off TLS hostname verification, but 
the generated `MongoDbConnectorEmbeddedDebeziumConfiguration` declared it as a 
plain `@UriParam`, so the option never reached the security option map in 
`SecurityUtils` and `camel.main.profile=prod` did not refuse it.
   
   ### The generator change
   
   `camel-debezium-maven-plugin` previously emitted only `secret = true` (when 
Debezium declares the field as a `PASSWORD`) and nothing for insecure flags. It 
can now emit the `security` attribute, driven by an explicit list of Debezium 
option names in `ConnectorConfigField`:
   
   ```java
   private static final Map<String, String> SECURITY_CATEGORIES = Map.of(
           "mongodb.ssl.invalid.hostname.allowed", "insecure:ssl");
   ```
   
   An explicit list rather than a name heuristic, so that a new connector 
option cannot silently inherit a category it does not deserve, and a renamed 
one shows up as a missing entry here instead of quietly losing its marking.
   
   Regenerating all six connectors (db2, mongodb, mysql, oracle, postgres, 
sqlserver) changes **exactly one line** — the annotation on that option; the 
other five connectors are untouched.
   
   ### Deliberately not included
   
   `debezium-mysql` `databaseSslMode` and `debezium-postgres` `databaseSslmode` 
/ `databaseSslfactory` also have insecure values (`sslmode=disabled`/`disable`, 
a non-validating SSL factory). Marking them would newly fail prod-profile 
startup for anyone running those connectors without TLS, and deciding which 
value warrants that is a policy call worth making on its own rather than riding 
along here. Happy to follow up if the preference is to mark them.
   
   The generator also still emits the legacy `secret = true` rather than 
`security = "secret"` (CAMEL-23250 moved the rest of the codebase over). 
Equivalent in the catalog, so it is left alone here to keep the regenerated 
diff to the one intended line.
   
   ### Upgrade guide
   
   Added, mirroring the `camel-mongodb` entry from #27482: the prod profile now 
fails startup for 
`camel.component.debezium-mongodb.mongodbSslInvalidHostnameAllowed = true`, and 
`camel.security.allowedProperties` is the way to keep it.
   
   ### Tests
   
   `SecurityUtilsTest` already asserts the hostname-verification options reach 
the policy map; this option joins that case.
   
   JIRA: https://issues.apache.org/jira/browse/CAMEL-25414
   
   _Claude Code on behalf of @oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to