oscerd commented on code in PR #26891:
URL: https://github.com/apache/camel/pull/26891#discussion_r4122391483


##########
core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java:
##########
@@ -84,6 +84,7 @@ public record SecurityOption(String category, String 
insecureValue) {
         map.put("sendenabled", new SecurityOption(INSECURE_DEV, "true"));
         map.put("serializablepackages", new 
SecurityOption(INSECURE_SERIALIZATION, ""));
         map.put("skiptlsverify", new SecurityOption(INSECURE_SSL, "true"));
+        map.put("ssl", new SecurityOption(INSECURE_SSL, VALUE_FALSE));

Review Comment:
   Good point, thanks. `SecurityUtils.getSecurityOption` keeps only the last 
segment of the key, so the new `ssl` entry does flag 
`camel.component.{clickhouse,netty,netty-http,oaipmh}.ssl=false`. That's a 
warning by default and a startup failure under `prod`. I confirmed in the 
catalog that those four, plus hivemq, are the only components with an `ssl` 
option. The check covers only the camel-main auto-configured properties 
(`BaseMainSupport.enforceSecurityPolicies`), not endpoint URIs.
   
   Done in 521cf7c: a `camel-hivemq` entry in the 4.23 upgrade guide. It covers 
the new marker, and the fact that matching is by option name, so it also 
reaches those four components. It names the existing `tls` precedent 
(camel-pinecone) and points to `camel.security.allowedProperties` for keeping 
such a setting under a `fail` policy.
   
   On the follow-up: I'd rather not annotate the four other `ssl` options as 
`insecure:ssl` just to line the catalog up with this. Plaintext netty TCP is a 
legitimate choice, and that would make the warning intentional for them. The 
cleaner fix is to make the lookup component-aware, so 
`camel.component.<name>.<option>` is checked against that component's own 
metadata. That would fix `tls` as well. I'll raise it as a separate Jira rather 
than widen this PR.
   
   _Claude Code on behalf of @oscerd_
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to