davsclaus commented on code in PR #27053:
URL: https://github.com/apache/camel/pull/27053#discussion_r4132780078
##########
components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java:
##########
@@ -54,6 +57,22 @@ public void setOperation(SpiffeOperation operation) {
this.operation = operation;
}
+ public SpiffeX509Response getX509Response() {
+ return x509Response;
+ }
+
+ /**
+ * What the {@code fetchX509Svid} operation returns in the message body.
+ * <p/>
+ * Defaults to {@code svid}: the whole {@code X509Svid}, which carries the
<em>private key</em>. A route that only
+ * needs its identity - to log it, route on it, or set a header - can
choose {@code chain} (the X.509 certificate
+ * chain without the key) or {@code id} (the body is left untouched) and
never handle key material. The SPIFFE ID
+ * and expiry are exposed through the {@code CamelSpiffeId} and {@code
CamelSpiffeExpiry} headers in every case.
Review Comment:
The header is `CamelSpiffeSpiffeId` (`HEADER_PREFIX + "SpiffeId"`), not
`CamelSpiffeId`. The same wrong name is in `SpiffeX509Response.java:22`, and it
has been copied into the generated `spiffe.json` (component and catalog) and
the DSL builder descriptions.
##########
components/camel-spiffe/src/main/java/org/apache/camel/component/spiffe/SpiffeConfiguration.java:
##########
@@ -28,6 +28,9 @@ public class SpiffeConfiguration implements Cloneable {
@UriParam(defaultValue = "fetchX509Svid")
private SpiffeOperation operation = SpiffeOperation.fetchX509Svid;
+ @UriParam(label = "producer,security", defaultValue = "svid")
+ private SpiffeX509Response x509Response = SpiffeX509Response.svid;
Review Comment:
Question: camel-spiffe is new in 4.23 and has not been released, so there
are no existing users to keep compatible. Should the default be `chain` or
`id`, with `svid` (body carries the private key) as the opt-in? That follows
the "denied unless opted in" rule for defaults, and changing it after the
release would need an upgrade-guide entry.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]