This is an automated email from the ASF dual-hosted git repository.
oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new d887f25e22a8 CAMEL-24734: camel-spiffe - validate a JWT-SVID against
every configured audience (#26435)
d887f25e22a8 is described below
commit d887f25e22a8b0dccd2288e75daa3206eec8d4d7
Author: Andrea Cosentino <[email protected]>
AuthorDate: Wed Sep 16 10:33:46 2026 +0200
CAMEL-24734: camel-spiffe - validate a JWT-SVID against every configured
audience (#26435)
validateJwtSvid used audiences[0] and discarded the rest, while
fetchJwtSvid one
line above honoured all of them - so the same audience option meant a list
for
minting and a single value for validating, and validation silently enforced
a
narrower rule than the operator configured.
The Workload API validates one audience per call, so a configured list has
to be
tried in turn; the token is accepted on the first that matches and the last
failure is rethrown only once every audience has failed. Rebased onto
CAMEL-24730,
which removed CamelSpiffeAudience from this path, so the loop runs over the
configured audiences only and the header still cannot steer what a token is
checked against.
Co-authored-by: Claude Opus 5 <[email protected]>
---
.../apache/camel/catalog/components/spiffe.json | 4 +-
.../camel/catalog/docs/spiffe-component.adoc | 4 +-
.../org/apache/camel/component/spiffe/spiffe.json | 4 +-
.../src/main/docs/spiffe-component.adoc | 4 +-
.../component/spiffe/SpiffeConfiguration.java | 6 +-
.../camel/component/spiffe/SpiffeProducer.java | 30 ++++++-
.../component/spiffe/SpiffeMultiAudienceTest.java | 98 ++++++++++++++++++++++
.../dsl/SpiffeComponentBuilderFactory.java | 10 +--
.../endpoint/dsl/SpiffeEndpointBuilderFactory.java | 10 +--
9 files changed, 149 insertions(+), 21 deletions(-)
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
index 1b8c1a3c3731..7487f79aa19a 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/spiffe.json
@@ -24,7 +24,7 @@
"remote": true
},
"componentProperties": {
- "audience": { "index": 0, "kind": "property", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can b [...]
+ "audience": { "index": 0, "kind": "property", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetch [...]
"configuration": { "index": 1, "kind": "property", "displayName":
"Configuration", "group": "producer", "label": "", "required": false, "type":
"object", "javaType": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"deprecated": false, "autowired": false, "secret": false, "description": "The
component configuration." },
"lazyStartProducer": { "index": 2, "kind": "property", "displayName":
"Lazy Start Producer", "group": "producer", "label": "producer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Whether the producer should be started lazy (on the first message). By
starting lazy you can use this to allow CamelContext and routes to startup in
situations where a producer may otherwise fail [...]
"operation": { "index": 3, "kind": "property", "displayName": "Operation",
"group": "producer", "label": "", "required": false, "type": "enum",
"javaType": "org.apache.camel.component.spiffe.SpiffeOperation", "enum": [
"fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated": false,
"autowired": false, "secret": false, "defaultValue": "fetchX509Svid",
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"configurationField": "configuration", "descr [...]
@@ -42,7 +42,7 @@
},
"properties": {
"label": { "index": 0, "kind": "path", "displayName": "Label", "group":
"producer", "label": "", "required": false, "type": "string", "javaType":
"java.lang.String", "deprecated": false, "deprecationNote": "", "autowired":
false, "secret": false, "description": "Logical name of the endpoint" },
- "audience": { "index": 1, "kind": "parameter", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can [...]
+ "audience": { "index": 1, "kind": "parameter", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetc [...]
"operation": { "index": 2, "kind": "parameter", "displayName":
"Operation", "group": "producer", "label": "", "required": false, "type":
"enum", "javaType": "org.apache.camel.component.spiffe.SpiffeOperation",
"enum": [ "fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated":
false, "autowired": false, "secret": false, "defaultValue": "fetchX509Svid",
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"configurationField": "configuration", "desc [...]
"lazyStartProducer": { "index": 3, "kind": "parameter", "displayName":
"Lazy Start Producer", "group": "producer (advanced)", "label":
"producer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Whether the producer should be started
lazy (on the first message). By starting lazy you can use this to allow
CamelContext and routes to startup in situations where a produc [...]
"workloadApiClient": { "index": 4, "kind": "parameter", "displayName":
"Workload Api Client", "group": "advanced", "label": "advanced", "required":
false, "type": "object", "javaType": "io.spiffe.workloadapi.WorkloadApiClient",
"deprecated": false, "deprecationNote": "", "autowired": true, "secret": false,
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"configurationField": "configuration", "description": "An existing
WorkloadApiClient to use. When set [...]
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
index 17b45a0a1888..01c35bece736 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/spiffe-component.adoc
@@ -63,7 +63,9 @@ header to its SPIFFE ID.
* `fetchJwtSvid` — fetches a JWT-SVID for the configured `audience` (or the
`CamelSpiffeAudience` header). The
message body is set to the JWT token string, with the `CamelSpiffeSpiffeId`
and `CamelSpiffeExpiry` headers.
* `validateJwtSvid` — validates the JWT-SVID passed in the `CamelSpiffeToken`
header (or the body) against the
-`audience`. The message body is set to the validated
`io.spiffe.svid.jwtsvid.JwtSvid`.
+`audience`. When several audiences are configured the token is accepted if it
matches *any* of them — the
+Workload API validates one audience at a time, so each is tried in turn. The
message body is set to the validated
+`io.spiffe.svid.jwtsvid.JwtSvid`.
[NOTE]
====
diff --git
a/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
b/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
index 1b8c1a3c3731..7487f79aa19a 100644
---
a/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
+++
b/components/camel-spiffe/src/generated/resources/META-INF/org/apache/camel/component/spiffe/spiffe.json
@@ -24,7 +24,7 @@
"remote": true
},
"componentProperties": {
- "audience": { "index": 0, "kind": "property", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can b [...]
+ "audience": { "index": 0, "kind": "property", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetch [...]
"configuration": { "index": 1, "kind": "property", "displayName":
"Configuration", "group": "producer", "label": "", "required": false, "type":
"object", "javaType": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"deprecated": false, "autowired": false, "secret": false, "description": "The
component configuration." },
"lazyStartProducer": { "index": 2, "kind": "property", "displayName":
"Lazy Start Producer", "group": "producer", "label": "producer", "required":
false, "type": "boolean", "javaType": "boolean", "deprecated": false,
"autowired": false, "secret": false, "defaultValue": false, "description":
"Whether the producer should be started lazy (on the first message). By
starting lazy you can use this to allow CamelContext and routes to startup in
situations where a producer may otherwise fail [...]
"operation": { "index": 3, "kind": "property", "displayName": "Operation",
"group": "producer", "label": "", "required": false, "type": "enum",
"javaType": "org.apache.camel.component.spiffe.SpiffeOperation", "enum": [
"fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated": false,
"autowired": false, "secret": false, "defaultValue": "fetchX509Svid",
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"configurationField": "configuration", "descr [...]
@@ -42,7 +42,7 @@
},
"properties": {
"label": { "index": 0, "kind": "path", "displayName": "Label", "group":
"producer", "label": "", "required": false, "type": "string", "javaType":
"java.lang.String", "deprecated": false, "deprecationNote": "", "autowired":
false, "secret": false, "description": "Logical name of the endpoint" },
- "audience": { "index": 1, "kind": "parameter", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). Can [...]
+ "audience": { "index": 1, "kind": "parameter", "displayName": "Audience",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.spiffe.SpiffeConfiguration", "configurationField":
"configuration", "description": "The comma-separated audience(s) to request for
a JWT-SVID (fetchJwtSvid) or to validate against (validateJwtSvid). fetc [...]
"operation": { "index": 2, "kind": "parameter", "displayName":
"Operation", "group": "producer", "label": "", "required": false, "type":
"enum", "javaType": "org.apache.camel.component.spiffe.SpiffeOperation",
"enum": [ "fetchX509Svid", "fetchJwtSvid", "validateJwtSvid" ], "deprecated":
false, "autowired": false, "secret": false, "defaultValue": "fetchX509Svid",
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"configurationField": "configuration", "desc [...]
"lazyStartProducer": { "index": 3, "kind": "parameter", "displayName":
"Lazy Start Producer", "group": "producer (advanced)", "label":
"producer,advanced", "required": false, "type": "boolean", "javaType":
"boolean", "deprecated": false, "autowired": false, "secret": false,
"defaultValue": false, "description": "Whether the producer should be started
lazy (on the first message). By starting lazy you can use this to allow
CamelContext and routes to startup in situations where a produc [...]
"workloadApiClient": { "index": 4, "kind": "parameter", "displayName":
"Workload Api Client", "group": "advanced", "label": "advanced", "required":
false, "type": "object", "javaType": "io.spiffe.workloadapi.WorkloadApiClient",
"deprecated": false, "deprecationNote": "", "autowired": true, "secret": false,
"configurationClass": "org.apache.camel.component.spiffe.SpiffeConfiguration",
"configurationField": "configuration", "description": "An existing
WorkloadApiClient to use. When set [...]
diff --git a/components/camel-spiffe/src/main/docs/spiffe-component.adoc
b/components/camel-spiffe/src/main/docs/spiffe-component.adoc
index 17b45a0a1888..01c35bece736 100644
--- a/components/camel-spiffe/src/main/docs/spiffe-component.adoc
+++ b/components/camel-spiffe/src/main/docs/spiffe-component.adoc
@@ -63,7 +63,9 @@ header to its SPIFFE ID.
* `fetchJwtSvid` — fetches a JWT-SVID for the configured `audience` (or the
`CamelSpiffeAudience` header). The
message body is set to the JWT token string, with the `CamelSpiffeSpiffeId`
and `CamelSpiffeExpiry` headers.
* `validateJwtSvid` — validates the JWT-SVID passed in the `CamelSpiffeToken`
header (or the body) against the
-`audience`. The message body is set to the validated
`io.spiffe.svid.jwtsvid.JwtSvid`.
+`audience`. When several audiences are configured the token is accepted if it
matches *any* of them — the
+Workload API validates one audience at a time, so each is tried in turn. The
message body is set to the validated
+`io.spiffe.svid.jwtsvid.JwtSvid`.
[NOTE]
====
diff --git
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
index f34dad7f40e3..92d6ca7d3370 100644
---
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
+++
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java
@@ -68,9 +68,9 @@ public class SpiffeConfiguration implements Cloneable {
/**
* The comma-separated audience(s) to request for a JWT-SVID
(fetchJwtSvid) or to validate against
- * (validateJwtSvid). Can be overridden per-message with the {@code
CamelSpiffeAudience} header. Note that
- * validateJwtSvid validates against a single audience, so when several
comma-separated audiences are given only the
- * first one is used for validation; fetchJwtSvid requests all of them.
+ * (validateJwtSvid). fetchJwtSvid requests all of them and can be
overridden per-message with the
+ * {@code CamelSpiffeAudience} header; validateJwtSvid ignores that header
and uses this configuration only,
+ * accepting the token if it matches any of the configured audiences,
trying each in turn.
*/
public String getAudience() {
return audience;
diff --git
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
index ec38b420261f..227e1bddb0fa 100644
---
a/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
+++
b/components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeProducer.java
@@ -18,6 +18,7 @@ package org.apache.camel.component.spiffe;
import java.util.Arrays;
+import io.spiffe.exception.JwtSvidException;
import io.spiffe.svid.jwtsvid.JwtSvid;
import io.spiffe.svid.x509svid.X509Svid;
import io.spiffe.workloadapi.WorkloadApiClient;
@@ -78,13 +79,38 @@ public class SpiffeProducer extends DefaultProducer {
// the audience is the check here, not a parameter: it is what binds
the token to THIS workload, so it
// comes from the configuration only. Honouring CamelSpiffeAudience
would let a caller validate a token
// minted for someone else against an audience of their choosing.
- String[] audiences = resolveConfiguredAudiences();
- JwtSvid svid = client.validateJwtSvid(token, audiences[0]);
+ JwtSvid svid = validateAgainstAnyAudience(client, token,
resolveConfiguredAudiences());
Message message = getMessageForResponse(exchange);
message.setBody(svid);
message.setHeader(SpiffeConstants.SPIFFE_ID,
svid.getSpiffeId().toString());
}
+ /**
+ * Validates the token against the configured audiences, accepting it if
<em>any</em> of them matches.
+ * <p/>
+ * The Workload API validates against one audience at a time, so a
configured list has to be tried in turn. Taking
+ * only the first would silently enforce a narrower rule than the
configuration asks for, which is the wrong failure
+ * mode for a check that decides whether a caller is authenticated.
+ */
+ private JwtSvid validateAgainstAnyAudience(WorkloadApiClient client,
String token, String[] audiences)
+ throws JwtSvidException {
+ JwtSvidException failure = null;
+ for (String audience : audiences) {
+ try {
+ return client.validateJwtSvid(token, audience);
+ } catch (JwtSvidException e) {
+ // could be this audience, or the token itself; only once
every audience has failed do we know
+ failure = e;
+ }
+ }
+ // resolveConfiguredAudiences never returns an empty array, so the
loop ran and failure is set; be explicit
+ // rather than leaving a reader (or a static analyser) to prove it
+ if (failure == null) {
+ throw new IllegalStateException("No audience was configured to
validate against");
+ }
+ throw failure;
+ }
+
private SpiffeOperation determineOperation(Exchange exchange) {
SpiffeOperation configured =
getEndpoint().getConfiguration().getOperation();
if (!getEndpoint().getConfiguration().isAllowOperationHeader()) {
diff --git
a/components/camel-spiffe/src/test/java/org/apache/camel/component/spiffe/SpiffeMultiAudienceTest.java
b/components/camel-spiffe/src/test/java/org/apache/camel/component/spiffe/SpiffeMultiAudienceTest.java
new file mode 100644
index 000000000000..0434d2a0c8af
--- /dev/null
+++
b/components/camel-spiffe/src/test/java/org/apache/camel/component/spiffe/SpiffeMultiAudienceTest.java
@@ -0,0 +1,98 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.spiffe;
+
+import io.spiffe.exception.JwtSvidException;
+import io.spiffe.spiffeid.SpiffeId;
+import io.spiffe.svid.jwtsvid.JwtSvid;
+import io.spiffe.workloadapi.WorkloadApiClient;
+import org.apache.camel.BindToRegistry;
+import org.apache.camel.Exchange;
+import org.apache.camel.test.junit6.CamelTestSupport;
+import org.junit.jupiter.api.Test;
+
+import static org.assertj.core.api.Assertions.assertThat;
+import static org.mockito.Mockito.mock;
+import static org.mockito.Mockito.never;
+import static org.mockito.Mockito.verify;
+import static org.mockito.Mockito.when;
+
+/**
+ * A configured audience list means "any of these is acceptable", so
validation must try each rather than silently
+ * enforcing only the first.
+ */
+class SpiffeMultiAudienceTest extends CamelTestSupport {
+
+ private static final String FIRST = "spiffe://example.org/first";
+ private static final String SECOND = "spiffe://example.org/second";
+
+ @BindToRegistry("client")
+ private final WorkloadApiClient client = mock(WorkloadApiClient.class);
+
+ private static JwtSvid svid() {
+ JwtSvid svid = mock(JwtSvid.class);
+
when(svid.getSpiffeId()).thenReturn(SpiffeId.parse("spiffe://example.org/caller"));
+ return svid;
+ }
+
+ private String endpoint() {
+ return
"spiffe:v?workloadApiClient=#client&operation=validateJwtSvid&audience=" +
FIRST + "," + SECOND;
+ }
+
+ private Exchange validate() {
+ return template.request(endpoint(), e ->
e.getIn().setHeader(SpiffeConstants.TOKEN, "a-token"));
+ }
+
+ @Test
+ void acceptsATokenMatchingTheSecondConfiguredAudience() throws Exception {
+ JwtSvid stub = svid();
+ when(client.validateJwtSvid("a-token", FIRST)).thenThrow(new
JwtSvidException("wrong audience"));
+ when(client.validateJwtSvid("a-token", SECOND)).thenReturn(stub);
+
+ Exchange out = validate();
+
+ assertThat(out.getException()).isNull();
+ assertThat(out.getMessage().getBody()).isSameAs(stub);
+ verify(client).validateJwtSvid("a-token", FIRST);
+ verify(client).validateJwtSvid("a-token", SECOND);
+ }
+
+ @Test
+ void stopsAtTheFirstAudienceThatMatches() throws Exception {
+ JwtSvid stub = svid();
+ when(client.validateJwtSvid("a-token", FIRST)).thenReturn(stub);
+
+ Exchange out = validate();
+
+ assertThat(out.getException()).isNull();
+ // no point asking the Workload API again once one audience has
accepted the token
+ verify(client).validateJwtSvid("a-token", FIRST);
+ verify(client, never()).validateJwtSvid("a-token", SECOND);
+ }
+
+ @Test
+ void failsWhenNoConfiguredAudienceMatches() throws Exception {
+ when(client.validateJwtSvid("a-token", FIRST)).thenThrow(new
JwtSvidException("wrong audience"));
+ when(client.validateJwtSvid("a-token", SECOND)).thenThrow(new
JwtSvidException("wrong audience"));
+
+ Exchange out = validate();
+
+ assertThat(out.getException()).isInstanceOf(JwtSvidException.class);
+ verify(client).validateJwtSvid("a-token", FIRST);
+ verify(client).validateJwtSvid("a-token", SECOND);
+ }
+}
diff --git
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
index adbba0194947..b9495f540e09 100644
---
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
+++
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/SpiffeComponentBuilderFactory.java
@@ -54,11 +54,11 @@ public interface SpiffeComponentBuilderFactory {
/**
* The comma-separated audience(s) to request for a JWT-SVID
- * (fetchJwtSvid) or to validate against (validateJwtSvid). Can be
- * overridden per-message with the CamelSpiffeAudience header. Note
that
- * validateJwtSvid validates against a single audience, so when several
- * comma-separated audiences are given only the first one is used for
- * validation; fetchJwtSvid requests all of them.
+ * (fetchJwtSvid) or to validate against (validateJwtSvid).
fetchJwtSvid
+ * requests all of them and can be overridden per-message with the
+ * CamelSpiffeAudience header; validateJwtSvid ignores that header and
+ * uses this configuration only, accepting the token if it matches any
+ * of the configured audiences, trying each in turn.
*
* The option is a: <code>java.lang.String</code> type.
*
diff --git
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
index 3e5c862c05e7..f48784f220d9 100644
---
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
+++
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/SpiffeEndpointBuilderFactory.java
@@ -47,11 +47,11 @@ public interface SpiffeEndpointBuilderFactory {
/**
* The comma-separated audience(s) to request for a JWT-SVID
- * (fetchJwtSvid) or to validate against (validateJwtSvid). Can be
- * overridden per-message with the CamelSpiffeAudience header. Note
that
- * validateJwtSvid validates against a single audience, so when several
- * comma-separated audiences are given only the first one is used for
- * validation; fetchJwtSvid requests all of them.
+ * (fetchJwtSvid) or to validate against (validateJwtSvid).
fetchJwtSvid
+ * requests all of them and can be overridden per-message with the
+ * CamelSpiffeAudience header; validateJwtSvid ignores that header and
+ * uses this configuration only, accepting the token if it matches any
+ * of the configured audiences, trying each in turn.
*
* The option is a: <code>java.lang.String</code> type.
*