oscerd commented on issue #3014:
URL: 
https://github.com/apache/camel-kamelets/issues/3014#issuecomment-5792014977

   Revisiting the scope here, because I framed this issue as blocked on the 
`keystore` decision and that overstates it. **Only one of the four 
authentication types actually needs that decision.**
   
   Checking the component options in `camel-salesforce` 4.23.0-SNAPSHOT:
   
   ```
   authenticationType   enum     
org.apache.camel.component.salesforce.AuthenticationType
   jwtAudience          string
   instanceUrl          string
   refreshToken         string
   keystore             object   
org.apache.camel.support.jsse.KeyStoreParameters
   ```
   
   `keystore` is the only one that is not a scalar, and it is needed only by 
`JWT`. Mapping that onto the four types:
   
   | type | what it needs | blocked? |
   |---|---|---|
   | `USERNAME_PASSWORD` | already exposed | works today |
   | `CLIENT_CREDENTIALS` | `clientId`, `clientSecret`, already exposed, plus 
`authenticationType` | **no** |
   | `REFRESH_TOKEN` | `refreshToken`, a plain string not currently exposed, 
plus `authenticationType` | **no** |
   | `JWT` | `keystore` and `jwtAudience` | yes, needs the decision |
   
   So three of the four are reachable by adding scalar properties only — 
`authenticationType`, `refreshToken` and `instanceUrl` — with 
`USERNAME_PASSWORD` kept as the default so nothing existing changes.
   
   That is worth separating, because `CLIENT_CREDENTIALS` is a server-to-server 
flow that needs no user password, which is most of what the original question 
in #1546 was reaching for. It would land without waiting on anything.
   
   One caveat against doing the obvious thing: exposing `authenticationType` as 
the component's full enum would advertise `JWT` while `keystore` remains 
unreachable, so a user selecting it would get a Kamelet that cannot 
authenticate. If the scalar subset goes first, the enum should list only the 
three that work, and gain `JWT` when the keystore approach is settled.
   
   I have not implemented this — flagging it so the issue is not held up in 
full for a decision that only the JWT quarter of it depends on. Happy to do the 
scalar part on its own, or to wait and do all four together, whichever you 
prefer.
   
   ---
   _Claude Code on behalf of Andrea Cosentino_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to