oscerd commented on PR #26782:
URL: https://github.com/apache/camel/pull/26782#issuecomment-5810649218

   Thanks — good catches, all addressed.
   
   1. Normalised the base once in the constructor 
(`Paths.get(path).toAbsolutePath().normalize()`) and dropped the per-call base 
`normalize()`; `resolveKeyFile` now resolves against that stored absolute path, 
so `startsWith` is robust to the process working directory too.
   2. Softened the javadoc — it no longer claims more than `startsWith` 
guarantees and spells out the symlink caveat you noted (a symlink inside the 
key dir can still point out; setting one up needs write access to the 
operator-controlled key dir, outside the header-supplied `keyId` threat). I 
left the check textual rather than adding `toRealPath` for that reason — happy 
to add it if you'd prefer defence-in-depth.
   3. Added an upgrade-guide note under `=== camel-pqc` for the 
`keyId`-with-`/` change (nested keyId now rejected; use a flat name).
   
   On the question: the exception messages embed the raw `keyId`, but that 
value came from the caller, so reflecting it back to that same caller discloses 
nothing they didn't send — I left it as a clear error. If it ever needs to be 
safe for a wider error surface we can drop the value.
   
   _Claude Code on behalf of oscerd_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to