oscerd opened a new pull request, #27117:
URL: https://github.com/apache/camel/pull/27117

   CAMEL-24295: anchor the security-scan option match on a token boundary, and 
mark the Simple nested option
   
   ## Background
   
   Two related changes, following the investigation on the issue.
   
   **camel-jbang security scanner (the load-bearing part).** 
`SecurityScanTools.extractOptionValue`
   found an option key with an unanchored `indexOf`: it checked a token 
boundary *after* the key
   (the `=`/`:` separator) but not *before* it. So a longer identifier that 
merely ends in a security
   option name matched — for example `startTls=false` was reported as an 
insecure `tls=false`, and
   `isNested=true` / an unrelated `...nested` field would match a `nested` 
rule. The scanner reads
   arbitrary route source text, which the catalog cannot vet, so this is a real 
false-positive risk.
   
   The extractor now also requires the character *before* the key to not be a 
letter or digit, so the
   key must start at a token boundary (`?`, `&`, `,`, `{`, `"`, line start, …). 
A boundary-delimited
   `tls=false` is still detected.
   
   **Simple `nested` option.** The `nested` attribute of `SimpleExpression` 
re-evaluates a nested Simple
   expression contained in the result (off by default). It is an opt-in option 
with security relevance
   but carried no security metadata. It now has `security = "insecure:dev"` and 
a `security` label, so it
   is generated into `SecurityUtils`' option map and the security scanner 
reports a route that enables
   it. (As noted on the issue, `camel.main.profile=prod` only tests `camel.*` 
properties, so a
   route-inline attribute is out of that detector's reach; this change gives 
the jbang scanner coverage,
   which is why fixing the scanner's matching first matters — otherwise a 
short/generic key would be
   prone to exactly the false positives fixed above.)
   
   ## Tests
   
   `SecurityScanToolsTest.securityOptionMatchingIsAnchoredOnTokenBoundaries`: 
`startTls=false` is not
   flagged, while a real `tls=false` still is. Revert-to-red verified (removing 
the boundary check
   re-introduces the `startTls` false positive).
   
   Catalog, model metadata and `SecurityUtils` regenerated.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to