oscerd opened a new pull request, #27117:
URL: https://github.com/apache/camel/pull/27117
CAMEL-24295: anchor the security-scan option match on a token boundary, and
mark the Simple nested option
## Background
Two related changes, following the investigation on the issue.
**camel-jbang security scanner (the load-bearing part).**
`SecurityScanTools.extractOptionValue`
found an option key with an unanchored `indexOf`: it checked a token
boundary *after* the key
(the `=`/`:` separator) but not *before* it. So a longer identifier that
merely ends in a security
option name matched — for example `startTls=false` was reported as an
insecure `tls=false`, and
`isNested=true` / an unrelated `...nested` field would match a `nested`
rule. The scanner reads
arbitrary route source text, which the catalog cannot vet, so this is a real
false-positive risk.
The extractor now also requires the character *before* the key to not be a
letter or digit, so the
key must start at a token boundary (`?`, `&`, `,`, `{`, `"`, line start, …).
A boundary-delimited
`tls=false` is still detected.
**Simple `nested` option.** The `nested` attribute of `SimpleExpression`
re-evaluates a nested Simple
expression contained in the result (off by default). It is an opt-in option
with security relevance
but carried no security metadata. It now has `security = "insecure:dev"` and
a `security` label, so it
is generated into `SecurityUtils`' option map and the security scanner
reports a route that enables
it. (As noted on the issue, `camel.main.profile=prod` only tests `camel.*`
properties, so a
route-inline attribute is out of that detector's reach; this change gives
the jbang scanner coverage,
which is why fixing the scanner's matching first matters — otherwise a
short/generic key would be
prone to exactly the false positives fixed above.)
## Tests
`SecurityScanToolsTest.securityOptionMatchingIsAnchoredOnTokenBoundaries`:
`startTls=false` is not
flagged, while a real `tls=false` still is. Revert-to-red verified (removing
the boundary check
re-introduces the `startTls` false positive).
Catalog, model metadata and `SecurityUtils` regenerated.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]