davsclaus opened a new pull request, #27070:
URL: https://github.com/apache/camel/pull/27070

   [CAMEL-25134](https://issues.apache.org/jira/browse/CAMEL-25134)
   
   The security policy check matched an insecure option by its **name only** 
(`SecurityUtils.getSecurityOption` kept only the last segment of the key). So 
an option of one component that is marked insecure was also reported for every 
other component, data format or language with an option of the same name:
   
   - `tls=false` was reported for every component because of the `tls` option 
of camel-pinecone
   - since #26891 (CAMEL-24999), `ssl=false` on camel-clickhouse, camel-netty, 
camel-netty-http and camel-oaipmh is reported because of the `ssl` option of 
camel-hivemq
   
   Under `camel.main.profile=prod` that fails startup for components that never 
declared the option insecure. Raised by @oscerd in the review of #26891.
   
   **Change**
   
   - `UpdateSensitizeHelper` (camel-package-maven-plugin) now also generates 
which components, data formats and languages declare each security option 
(`SECURITY-OPTION-OWNERS` block in `SecurityUtils`). Components are listed by 
their scheme and alternative schemes. The block is between `@formatter:off/on`, 
one owner per line, as `trustAllCertificates` has 37 owners.
   - `SecurityUtils.getSecurityOption`: a key that identifies a component, data 
format or language (`camel.component.<name>.<option>`, 
`camel.dataformat.<name>.<option>`, `camel.language.<name>.<option>`) is only 
matched against the security options of that component, data format or 
language. The name is matched in any case and with or without dashes.
   - Any other key is still matched by the option name, as before: 
`camel.ssl.*`, `camel.main.*` (such as `devConsoleEnabled`, which has no owning 
component), `camel.beans.*`, and plain option names as used by the MCP security 
scan.
   
   So `camel.component.netty.ssl=false` and `camel.component.kafka.tls=false` 
are no longer reported, while `camel.component.hivemq.ssl=false` and 
`camel.component.pinecone.tls=false` still are.
   
   **Docs**
   
   - `security-policy.adoc`: explains how options are matched. The examples 
used `camel.component.http.trustAllCertificates`, which is not an option of 
camel-http, and now use camel-aws2-s3.
   - 4.23 upgrade guide: new camel-main entry. The camel-hivemq entry from 
#26891 said the `ssl` marker also applies to the other components with an `ssl` 
option; it now says it applies to camel-hivemq only.
   
   **Tests**
   
   - `SecurityUtilsTest`: a component option only matches its own security 
option (ssl/tls), component name with dashes and case, alternative schemes 
(llm/openai), nested keys, data formats, keys without a component matched by 
name, and `detectViolations`.
   - `MainSecurityPolicyTest`: a component with a `tls` option and 
`insecureSslPolicy=fail` starts. This test fails without the fix.
   - Two existing tests used keys that are not options of those components 
(`camel.component.http.trustAllCertificates`, 
`camel.component.jms.allowJavaSerializedObject`); they now use real ones.
   
   `SecurityUtilsTest` (16) and `MainSecurityPolicy*Test` (42) pass locally. 
Full reactor build (`mvn clean install -DskipTests`) passes with no generated 
changes.
   
   _Claude Code on behalf of davsclaus_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to