urunni88 opened a new pull request, #26872:
URL: https://github.com/apache/camel/pull/26872

   # Description
   
   **JIRA:** https://issues.apache.org/jira/browse/CAMEL-24650
   
   The `fileNameExtWhitelist` check was implemented separately in 
camel-servlet's and camel-jetty's `AttachmentHttpBinding`. This PR moves it 
into a single `protected boolean isFileNameAccepted(String fileName)` on 
`DefaultHttpBinding`, which both bindings extend, and removes the two copies. 
The shared method keeps the behaviour from CAMEL-24427: exact, case-insensitive 
matching per comma-separated extension, `*` accepts everything, and files 
without an extension are accepted.
   
   **Servlet and jetty behaviour is unchanged.** 
`MultipartUploadFileNameExtWhitelistTest` and 
`MultiPartFormFileNameExtWhitelistTest` pass without modification.
   
   **One behaviour change:** `DefaultHttpBinding.populateAttachments` (the 
request-attribute path) had its own older copy of the check that the JIRA 
didn't list. It matched extensions as a substring (`whitelist.contains(ext)`) 
and overwrote the configured `fileNameExtWhitelist` with its lowercased value. 
It now uses the shared method too, so it gets the same exact matching 
CAMEL-24427 introduced for servlet and jetty.
   
   Added unit tests for `isFileNameAccepted` in `DefaultHttpBindingTest` (no 
whitelist, no extension, `*`, multiple entries, case, substring bypass, 
configured value not modified).
   
   Out of scope:
   - `VertxPlatformHttpConsumer` keeps its own check, as it does not extend 
`DefaultHttpBinding`.
   - The `FileUtil.onlyExt` multi-dot question from the JIRA (`archive.tar.gz` 
→ `tar.gz`) is left as is for a separate decision.
   
   Tests: camel-http-common 36/36, camel-servlet 102 (2 skipped), camel-jetty 
395 (32 skipped), 0 failures.
   
   AI assistance: investigation and changes were done with help from Claude 
(Anthropic). I reviewed and verified the changes, build and tests locally.
   
   # Target
   
   - [x] I checked that the commit is targeting the correct branch (Camel 4 
uses the `main` branch)
   
   # Tracking
   
   - [x] If this is a large change, bug fix, or code improvement, I checked 
there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for 
the change (usually before you start working on it).
   
   # Apache Camel coding standards and style
   
   - [x] I checked that each commit in the pull request has a meaningful 
subject line and body.
   
   - [x] I have run `mvn clean install -DskipTests` locally from root folder 
and I have committed all auto-generated changes.
   
   Built the affected modules; no generated changes resulted.
   
   # AI-assisted contributions
   
   - [x] If this PR includes AI-generated code, commits have proper 
co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR 
description identifies the AI tool used.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to