oscerd opened a new pull request, #27053:
URL: https://github.com/apache/camel/pull/27053

   CAMEL-24739: camel-spiffe - let fetchX509Svid return the identity without 
the private key
   
   ## Problem
   
   `fetchX509Svid` sets the whole `X509Svid` as the message body, and 
`X509Svid` carries the **private
   key**. A route that only wants to know its own identity — to log it, route 
on it, or put the SPIFFE
   ID in a header — has no way to avoid handling key material, and any tracing, 
logging or error handler
   that touches the body then handles it too. Flagged in review on CAMEL-23305; 
the docs' "don't log the
   body" note mitigates the symptom, not the exposure.
   
   ## Change (additive, main-only)
   
   A new producer option `x509Response` controls what `fetchX509Svid` puts on 
the body:
   
   - `svid` (default) — the full `X509Svid`, incl. the private key. Unchanged 
behaviour; keeps
     programmatic mTLS possible.
   - `chain` — the X.509 certificate chain only 
(`List<java.security.cert.X509Certificate>`), no key.
   - `id` — the body is left untouched; the identity is exposed through headers 
only.
   
   In every case the `CamelSpiffeId` and `CamelSpiffeExpiry` headers carry the 
identity, so a route that
   only needs it can pick `chain` or `id` and never handle the private key. 
`fetchX509Svid` now also sets
   `CamelSpiffeExpiry` (the leaf certificate's `notAfter`), matching 
`fetchJwtSvid`.
   
   The full `X509Svid` stays reachable (`svid`, the default), so nothing 
existing changes unless a route
   opts in.
   
   ## Tests
   
   `SpiffeProducerTest`: `svid` (default → full SVID + id/expiry headers), 
`chain` (body is the chain, no
   key), `id` (body untouched, identity in headers). Revert-to-red verified: 
with the option ignored, the
   chain and id tests fail while the default and JWT tests pass.
   
   ## Docs
   
   `spiffe-component.adoc`: documents the option and names it as the mitigation 
in the key-material note
   (prefer `chain`/`id` when the route does not need the key). Catalog/DSL 
regenerated.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to