oscerd opened a new pull request, #27077:
URL: https://github.com/apache/camel/pull/27077

   CAMEL-24833: camel-spiffe - validateJwtSvid falls back to the Authorization: 
Bearer header
   
   ## Problem
   
   `spiffe:...?operation=validateJwtSvid` reads the token from the 
`CamelSpiffeToken` header or the
   message body. An HTTP caller presents a JWT-SVID as `Authorization: Bearer 
<token>` (how the SPIFFE
   JWT-SVID is meant to travel), so every route authenticating an HTTP request 
needs a small bean or
   expression to strip the scheme and copy the token into `CamelSpiffeToken`.
   
   ## Change (additive, main-only)
   
   `validateJwtSvid` now takes the token from the first of: the 
`CamelSpiffeToken` header, the message
   body, or an `Authorization: Bearer <token>` header. The `Authorization` 
header is the **last**
   fallback, so nothing changes for current users. The `Bearer` scheme is 
matched case-insensitively and
   the token trimmed; a missing, empty or non-bearer value falls through to the 
existing "token required"
   `IllegalArgumentException` (so an `onException` can answer 401), rather than 
a new error type.
   
   ## Docs
   
   `spiffe-component.adoc`: documents the token lookup order and adds a YAML 
`platform-http` example that
   validates an incoming bearer token without a bean, and drops the 
`Authorization` header afterwards
   (it is a credential). Catalog copy synced.
   
   ## Tests
   
   `SpiffeProducerTest`: token from `Authorization: Bearer`; case-insensitive 
scheme with a trimmed token;
   `CamelSpiffeToken` precedence over `Authorization`; a non-bearer 
`Authorization` falls through to the
   token-required error. Revert-to-red verified: with the fallback disabled the 
two Authorization-sourced
   tests fail while the precedence and non-bearer tests still pass.
   
   Related: CAMEL-24831.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to