This is an automated email from the ASF dual-hosted git repository.

oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new d887f25e22a8 CAMEL-24734: camel-spiffe - validate a JWT-SVID against 
every configured audience (#26435)
d887f25e22a8 is described below

commit d887f25e22a8b0dccd2288e75daa3206eec8d4d7
Author: Andrea Cosentino <[email protected]>
AuthorDate: Wed Sep 16 10:33:46 2026 +0200

    CAMEL-24734: camel-spiffe - validate a JWT-SVID against every configured 
audience (#26435)
    
    validateJwtSvid used audiences[0] and discarded the rest, while 
fetchJwtSvid one
    line above honoured all of them - so the same audience option meant a list 
for
    minting and a single value for validating, and validation silently enforced 
a
    narrower rule than the operator configured.
    
    The Workload API validates one audience per call, so a configured list has 
to be
    tried in turn; the token is accepted on the first that matches and the last
    failure is rethrown only once every audience has failed. Rebased onto 
CAMEL-24730,
    which removed CamelSpiffeAudience from this path, so the loop runs over the
    configured audiences only and the header still cannot steer what a token is
    checked against.
    
    Co-authored-by: Claude Opus 5 <[email protected]>
---
 .../apache/camel/catalog/components/spiffe.json    |  4 +-
 .../camel/catalog/docs/spiffe-component.adoc       |  4 +-
 .../org/apache/camel/component/spiffe/spiffe.json  |  4 +-
 .../src/main/docs/spiffe-component.adoc            |  4 +-
 .../component/spiffe/SpiffeConfiguration.java      |  6 +-
 .../camel/component/spiffe/SpiffeProducer.java     | 30 ++++++-
 .../component/spiffe/SpiffeMultiAudienceTest.java  | 98 ++++++++++++++++++++++
 .../dsl/SpiffeComponentBuilderFactory.java         | 10 +--
 .../endpoint/dsl/SpiffeEndpointBuilderFactory.java | 10 +--
 9 files changed, 149 insertions(+), 21 deletions(-)

diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
index 1b8c1a3c3731..7487f79aa19a 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
@@ -24,7 +24,7 @@
     "remote": true
   },
   "componentProperties": {
-    "audience": { "index": 0, "kind": "property", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can b [...]
+    "audience": { "index": 0, "kind": "property", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetch [...]
     "configuration": { "index": 1, "kind": "property", "displayName": 
"Configuration", "group": "producer", "label": "", "required": false, "type": 
"object", "javaType": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"deprecated": false, "autowired": false, "secret": false, "description": "The 
component configuration." },
     "lazyStartProducer": { "index": 2, "kind": "property", "displayName": 
"Lazy Start Producer", "group": "producer", "label": "producer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Whether the producer should be started lazy (on the first message). By 
starting lazy you can use this to allow CamelContext and routes to startup in 
situations where a producer may otherwise fail [...]
     "operation": { "index": 3, "kind": "property", "displayName": "Operation", 
"group": "producer", "label": "", "required": false, "type": "enum", 
"javaType": "org.apache.camel.component.spiffe.SpiffeOperation", "enum": [ 
"fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": "fetchX509Svid", 
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"configurationField": "configuration", "descr [...]
@@ -42,7 +42,7 @@
   },
   "properties": {
     "label": { "index": 0, "kind": "path", "displayName": "Label", "group": 
"producer", "label": "", "required": false, "type": "string", "javaType": 
"java.lang.String", "deprecated": false, "deprecationNote": "", "autowired": 
false, "secret": false, "description": "Logical name of the endpoint" },
-    "audience": { "index": 1, "kind": "parameter", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can  [...]
+    "audience": { "index": 1, "kind": "parameter", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetc [...]
     "operation": { "index": 2, "kind": "parameter", "displayName": 
"Operation", "group": "producer", "label": "", "required": false, "type": 
"enum", "javaType": "org.apache.camel.component.spiffe.SpiffeOperation", 
"enum": [ "fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated": 
false, "autowired": false, "secret": false, "defaultValue": "fetchX509Svid", 
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"configurationField": "configuration", "desc [...]
     "lazyStartProducer": { "index": 3, "kind": "parameter", "displayName": 
"Lazy Start Producer", "group": "producer (advanced)", "label": 
"producer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Whether the producer should be started 
lazy (on the first message). By starting lazy you can use this to allow 
CamelContext and routes to startup in situations where a produc [...]
     "workloadApiClient": { "index": 4, "kind": "parameter", "displayName": 
"Workload Api Client", "group": "advanced", "label": "advanced", "required": 
false, "type": "object", "javaType": "io.spiffe.workloadapi.WorkloadApiClient", 
"deprecated": false, "deprecationNote": "", "autowired": true, "secret": false, 
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"configurationField": "configuration", "description": "An existing 
WorkloadApiClient to use. When set [...]
diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
index 17b45a0a1888..01c35bece736 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
@@ -63,7 +63,9 @@ header to its SPIFFE ID.
 * `fetchJwtSvid` — fetches a JWT-SVID for the configured `audience` (or the 
`CamelSpiffeAudience` header). The
 message body is set to the JWT token string, with the `CamelSpiffeSpiffeId` 
and `CamelSpiffeExpiry` headers.
 * `validateJwtSvid` — validates the JWT-SVID passed in the `CamelSpiffeToken` 
header (or the body) against the
-`audience`. The message body is set to the validated 
`io.spiffe.svid.jwtsvid.JwtSvid`.
+`audience`. When several audiences are configured the token is accepted if it 
matches *any* of them — the
+Workload API validates one audience at a time, so each is tried in turn. The 
message body is set to the validated
+`io.spiffe.svid.jwtsvid.JwtSvid`.
 
 [NOTE]
 ====
diff --git 
a/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
 
b/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
index 1b8c1a3c3731..7487f79aa19a 100644
--- 
a/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
+++ 
b/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
@@ -24,7 +24,7 @@
     "remote": true
   },
   "componentProperties": {
-    "audience": { "index": 0, "kind": "property", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can b [...]
+    "audience": { "index": 0, "kind": "property", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetch [...]
     "configuration": { "index": 1, "kind": "property", "displayName": 
"Configuration", "group": "producer", "label": "", "required": false, "type": 
"object", "javaType": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"deprecated": false, "autowired": false, "secret": false, "description": "The 
component configuration." },
     "lazyStartProducer": { "index": 2, "kind": "property", "displayName": 
"Lazy Start Producer", "group": "producer", "label": "producer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Whether the producer should be started lazy (on the first message). By 
starting lazy you can use this to allow CamelContext and routes to startup in 
situations where a producer may otherwise fail [...]
     "operation": { "index": 3, "kind": "property", "displayName": "Operation", 
"group": "producer", "label": "", "required": false, "type": "enum", 
"javaType": "org.apache.camel.component.spiffe.SpiffeOperation", "enum": [ 
"fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": "fetchX509Svid", 
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"configurationField": "configuration", "descr [...]
@@ -42,7 +42,7 @@
   },
   "properties": {
     "label": { "index": 0, "kind": "path", "displayName": "Label", "group": 
"producer", "label": "", "required": false, "type": "string", "javaType": 
"java.lang.String", "deprecated": false, "deprecationNote": "", "autowired": 
false, "secret": false, "description": "Logical name of the endpoint" },
-    "audience": { "index": 1, "kind": "parameter", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can  [...]
+    "audience": { "index": 1, "kind": "parameter", "displayName": "Audience", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField": 
"configuration", "description": "The comma-separated audience(s) to request for 
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetc [...]
     "operation": { "index": 2, "kind": "parameter", "displayName": 
"Operation", "group": "producer", "label": "", "required": false, "type": 
"enum", "javaType": "org.apache.camel.component.spiffe.SpiffeOperation", 
"enum": [ "fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated": 
false, "autowired": false, "secret": false, "defaultValue": "fetchX509Svid", 
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"configurationField": "configuration", "desc [...]
     "lazyStartProducer": { "index": 3, "kind": "parameter", "displayName": 
"Lazy Start Producer", "group": "producer (advanced)", "label": 
"producer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Whether the producer should be started 
lazy (on the first message). By starting lazy you can use this to allow 
CamelContext and routes to startup in situations where a produc [...]
     "workloadApiClient": { "index": 4, "kind": "parameter", "displayName": 
"Workload Api Client", "group": "advanced", "label": "advanced", "required": 
false, "type": "object", "javaType": "io.spiffe.workloadapi.WorkloadApiClient", 
"deprecated": false, "deprecationNote": "", "autowired": true, "secret": false, 
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration", 
"configurationField": "configuration", "description": "An existing 
WorkloadApiClient to use. When set [...]
diff --git a/components/camel-spiffe/src/main/docs/spiffe-component.adoc 
b/components/camel-spiffe/src/main/docs/spiffe-component.adoc
index 17b45a0a1888..01c35bece736 100644
--- a/components/camel-spiffe/src/main/docs/spiffe-component.adoc
+++ b/components/camel-spiffe/src/main/docs/spiffe-component.adoc
@@ -63,7 +63,9 @@ header to its SPIFFE ID.
 * `fetchJwtSvid` — fetches a JWT-SVID for the configured `audience` (or the 
`CamelSpiffeAudience` header). The
 message body is set to the JWT token string, with the `CamelSpiffeSpiffeId` 
and `CamelSpiffeExpiry` headers.
 * `validateJwtSvid` — validates the JWT-SVID passed in the `CamelSpiffeToken` 
header (or the body) against the
-`audience`. The message body is set to the validated 
`io.spiffe.svid.jwtsvid.JwtSvid`.
+`audience`. When several audiences are configured the token is accepted if it 
matches *any* of them — the
+Workload API validates one audience at a time, so each is tried in turn. The 
message body is set to the validated
+`io.spiffe.svid.jwtsvid.JwtSvid`.
 
 [NOTE]
 ====
diff --git 
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
 
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
index f34dad7f40e3..92d6ca7d3370 100644
--- 
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
+++ 
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
@@ -68,9 +68,9 @@ public class SpiffeConfiguration implements Cloneable {
 
     /**
      * The comma-separated audience(s) to request for a JWT-SVID 
(fetchJwtSvid) or to validate against
-     * (validateJwtSvid). Can be overridden per-message with the {@code 
CamelSpiffeAudience} header. Note that
-     * validateJwtSvid validates against a single audience, so when several 
comma-separated audiences are given only the
-     * first one is used for validation; fetchJwtSvid requests all of them.
+     * (validateJwtSvid). fetchJwtSvid requests all of them and can be 
overridden per-message with the
+     * {@code CamelSpiffeAudience} header; validateJwtSvid ignores that header 
and uses this configuration only,
+     * accepting the token if it matches any of the configured audiences, 
trying each in turn.
      */
     public String getAudience() {
         return audience;
diff --git 
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
 
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
index ec38b420261f..227e1bddb0fa 100644
--- 
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
+++ 
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
@@ -18,6 +18,7 @@ package org.apache.camel.component.spiffe;
 
 import java.util.Arrays;
 
+import io.spiffe.exception.JwtSvidException;
 import io.spiffe.svid.jwtsvid.JwtSvid;
 import io.spiffe.svid.x509svid.X509Svid;
 import io.spiffe.workloadapi.WorkloadApiClient;
@@ -78,13 +79,38 @@ public class SpiffeProducer extends DefaultProducer {
         // the audience is the check here, not a parameter: it is what binds 
the token to THIS workload, so it
         // comes from the configuration only. Honouring CamelSpiffeAudience 
would let a caller validate a token
         // minted for someone else against an audience of their choosing.
-        String[] audiences = resolveConfiguredAudiences();
-        JwtSvid svid = client.validateJwtSvid(token, audiences[0]);
+        JwtSvid svid = validateAgainstAnyAudience(client, token, 
resolveConfiguredAudiences());
         Message message = getMessageForResponse(exchange);
         message.setBody(svid);
         message.setHeader(SpiffeConstants.SPIFFE_ID, 
svid.getSpiffeId().toString());
     }
 
+    /**
+     * Validates the token against the configured audiences, accepting it if 
<em>any</em> of them matches.
+     * <p/>
+     * The Workload API validates against one audience at a time, so a 
configured list has to be tried in turn. Taking
+     * only the first would silently enforce a narrower rule than the 
configuration asks for, which is the wrong failure
+     * mode for a check that decides whether a caller is authenticated.
+     */
+    private JwtSvid validateAgainstAnyAudience(WorkloadApiClient client, 
String token, String[] audiences)
+            throws JwtSvidException {
+        JwtSvidException failure = null;
+        for (String audience : audiences) {
+            try {
+                return client.validateJwtSvid(token, audience);
+            } catch (JwtSvidException e) {
+                // could be this audience, or the token itself; only once 
every audience has failed do we know
+                failure = e;
+            }
+        }
+        // resolveConfiguredAudiences never returns an empty array, so the 
loop ran and failure is set; be explicit
+        // rather than leaving a reader (or a static analyser) to prove it
+        if (failure == null) {
+            throw new IllegalStateException("No audience was configured to 
validate against");
+        }
+        throw failure;
+    }
+
     private SpiffeOperation determineOperation(Exchange exchange) {
         SpiffeOperation configured = 
getEndpoint().getConfiguration().getOperation();
         if (!getEndpoint().getConfiguration().isAllowOperationHeader()) {
diff --git 
a/components/camel-spiffe/src/test/java/org/apache/camel/component/spiffe/SpiffeMultiAudienceTest.java
 
b/components/camel-spiffe/src/test/java/org/apache/camel/component/spiffe/SpiffeMultiAudienceTest.java
new file mode 100644
index 000000000000..0434d2a0c8af
--- /dev/null
+++ 
b/components/camel-spiffe/src/test/java/org/apache/camel/component/spiffe/SpiffeMultiAudienceTest.java
@@ -0,0 +1,98 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.spiffe;
+
+import io.spiffe.exception.JwtSvidException;
+import io.spiffe.spiffeid.SpiffeId;
+import io.spiffe.svid.jwtsvid.JwtSvid;
+import io.spiffe.workloadapi.WorkloadApiClient;
+import org.apache.camel.BindToRegistry;
+import org.apache.camel.Exchange;
+import org.apache.camel.test.junit6.CamelTestSupport;
+import org.junit.jupiter.api.Test;
+
+import static org.assertj.core.api.Assertions.assertThat;
+import static org.mockito.Mockito.mock;
+import static org.mockito.Mockito.never;
+import static org.mockito.Mockito.verify;
+import static org.mockito.Mockito.when;
+
+/**
+ * A configured audience list means "any of these is acceptable", so 
validation must try each rather than silently
+ * enforcing only the first.
+ */
+class SpiffeMultiAudienceTest extends CamelTestSupport {
+
+    private static final String FIRST = "spiffe://example.org/first";
+    private static final String SECOND = "spiffe://example.org/second";
+
+    @BindToRegistry("client")
+    private final WorkloadApiClient client = mock(WorkloadApiClient.class);
+
+    private static JwtSvid svid() {
+        JwtSvid svid = mock(JwtSvid.class);
+        
when(svid.getSpiffeId()).thenReturn(SpiffeId.parse("spiffe://example.org/caller"));
+        return svid;
+    }
+
+    private String endpoint() {
+        return 
"spiffe:v?workloadApiClient=#client&operation=validateJwtSvid&audience=" + 
FIRST + "," + SECOND;
+    }
+
+    private Exchange validate() {
+        return template.request(endpoint(), e -> 
e.getIn().setHeader(SpiffeConstants.TOKEN, "a-token"));
+    }
+
+    @Test
+    void acceptsATokenMatchingTheSecondConfiguredAudience() throws Exception {
+        JwtSvid stub = svid();
+        when(client.validateJwtSvid("a-token", FIRST)).thenThrow(new 
JwtSvidException("wrong audience"));
+        when(client.validateJwtSvid("a-token", SECOND)).thenReturn(stub);
+
+        Exchange out = validate();
+
+        assertThat(out.getException()).isNull();
+        assertThat(out.getMessage().getBody()).isSameAs(stub);
+        verify(client).validateJwtSvid("a-token", FIRST);
+        verify(client).validateJwtSvid("a-token", SECOND);
+    }
+
+    @Test
+    void stopsAtTheFirstAudienceThatMatches() throws Exception {
+        JwtSvid stub = svid();
+        when(client.validateJwtSvid("a-token", FIRST)).thenReturn(stub);
+
+        Exchange out = validate();
+
+        assertThat(out.getException()).isNull();
+        // no point asking the Workload API again once one audience has 
accepted the token
+        verify(client).validateJwtSvid("a-token", FIRST);
+        verify(client, never()).validateJwtSvid("a-token", SECOND);
+    }
+
+    @Test
+    void failsWhenNoConfiguredAudienceMatches() throws Exception {
+        when(client.validateJwtSvid("a-token", FIRST)).thenThrow(new 
JwtSvidException("wrong audience"));
+        when(client.validateJwtSvid("a-token", SECOND)).thenThrow(new 
JwtSvidException("wrong audience"));
+
+        Exchange out = validate();
+
+        assertThat(out.getException()).isInstanceOf(JwtSvidException.class);
+        verify(client).validateJwtSvid("a-token", FIRST);
+        verify(client).validateJwtSvid("a-token", SECOND);
+    }
+}
diff --git 
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
 
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
index adbba0194947..b9495f540e09 100644
--- 
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
+++ 
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
@@ -54,11 +54,11 @@ public interface SpiffeComponentBuilderFactory {
     
         /**
          * The comma-separated audience(s) to request for a JWT-SVID
-         * (fetchJwtSvid) or to validate against (validateJwtSvid). Can be
-         * overridden per-message with the CamelSpiffeAudience header. Note 
that
-         * validateJwtSvid validates against a single audience, so when several
-         * comma-separated audiences are given only the first one is used for
-         * validation; fetchJwtSvid requests all of them.
+         * (fetchJwtSvid) or to validate against (validateJwtSvid). 
fetchJwtSvid
+         * requests all of them and can be overridden per-message with the
+         * CamelSpiffeAudience header; validateJwtSvid ignores that header and
+         * uses this configuration only, accepting the token if it matches any
+         * of the configured audiences, trying each in turn.
          * 
          * The option is a: &lt;code&gt;java.lang.String&lt;/code&gt; type.
          * 
diff --git 
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
 
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
index 3e5c862c05e7..f48784f220d9 100644
--- 
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
+++ 
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
@@ -47,11 +47,11 @@ public interface SpiffeEndpointBuilderFactory {
 
         /**
          * The comma-separated audience(s) to request for a JWT-SVID
-         * (fetchJwtSvid) or to validate against (validateJwtSvid). Can be
-         * overridden per-message with the CamelSpiffeAudience header. Note 
that
-         * validateJwtSvid validates against a single audience, so when several
-         * comma-separated audiences are given only the first one is used for
-         * validation; fetchJwtSvid requests all of them.
+         * (fetchJwtSvid) or to validate against (validateJwtSvid). 
fetchJwtSvid
+         * requests all of them and can be overridden per-message with the
+         * CamelSpiffeAudience header; validateJwtSvid ignores that header and
+         * uses this configuration only, accepting the token if it matches any
+         * of the configured audiences, trying each in turn.
          * 
          * The option is a: <code>java.lang.String</code> type.
          * 

Reply via email to