oscerd opened a new pull request, #27077: URL: https://github.com/apache/camel/pull/27077
CAMEL-24833: camel-spiffe - validateJwtSvid falls back to the Authorization: Bearer header ## Problem `spiffe:...?operation=validateJwtSvid` reads the token from the `CamelSpiffeToken` header or the message body. An HTTP caller presents a JWT-SVID as `Authorization: Bearer <token>` (how the SPIFFE JWT-SVID is meant to travel), so every route authenticating an HTTP request needs a small bean or expression to strip the scheme and copy the token into `CamelSpiffeToken`. ## Change (additive, main-only) `validateJwtSvid` now takes the token from the first of: the `CamelSpiffeToken` header, the message body, or an `Authorization: Bearer <token>` header. The `Authorization` header is the **last** fallback, so nothing changes for current users. The `Bearer` scheme is matched case-insensitively and the token trimmed; a missing, empty or non-bearer value falls through to the existing "token required" `IllegalArgumentException` (so an `onException` can answer 401), rather than a new error type. ## Docs `spiffe-component.adoc`: documents the token lookup order and adds a YAML `platform-http` example that validates an incoming bearer token without a bean, and drops the `Authorization` header afterwards (it is a credential). Catalog copy synced. ## Tests `SpiffeProducerTest`: token from `Authorization: Bearer`; case-insensitive scheme with a trimmed token; `CamelSpiffeToken` precedence over `Authorization`; a non-bearer `Authorization` falls through to the token-required error. Revert-to-red verified: with the fallback disabled the two Authorization-sourced tests fail while the precedence and non-bearer tests still pass. Related: CAMEL-24831. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
