oscerd opened a new pull request, #27053:
URL: https://github.com/apache/camel/pull/27053
CAMEL-24739: camel-spiffe - let fetchX509Svid return the identity without
the private key
## Problem
`fetchX509Svid` sets the whole `X509Svid` as the message body, and
`X509Svid` carries the **private
key**. A route that only wants to know its own identity — to log it, route
on it, or put the SPIFFE
ID in a header — has no way to avoid handling key material, and any tracing,
logging or error handler
that touches the body then handles it too. Flagged in review on CAMEL-23305;
the docs' "don't log the
body" note mitigates the symptom, not the exposure.
## Change (additive, main-only)
A new producer option `x509Response` controls what `fetchX509Svid` puts on
the body:
- `svid` (default) — the full `X509Svid`, incl. the private key. Unchanged
behaviour; keeps
programmatic mTLS possible.
- `chain` — the X.509 certificate chain only
(`List<java.security.cert.X509Certificate>`), no key.
- `id` — the body is left untouched; the identity is exposed through headers
only.
In every case the `CamelSpiffeId` and `CamelSpiffeExpiry` headers carry the
identity, so a route that
only needs it can pick `chain` or `id` and never handle the private key.
`fetchX509Svid` now also sets
`CamelSpiffeExpiry` (the leaf certificate's `notAfter`), matching
`fetchJwtSvid`.
The full `X509Svid` stays reachable (`svid`, the default), so nothing
existing changes unless a route
opts in.
## Tests
`SpiffeProducerTest`: `svid` (default → full SVID + id/expiry headers),
`chain` (body is the chain, no
key), `id` (body untouched, identity in headers). Revert-to-red verified:
with the option ignored, the
chain and id tests fail while the default and JWT tests pass.
## Docs
`spiffe-component.adoc`: documents the option and names it as the mitigation
in the key-material note
(prefer `chain`/`id` when the route does not need the key). Catalog/DSL
regenerated.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]