This is an automated email from the ASF dual-hosted git repository.
davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new d0e92a5eaf55 chore: docs - sync the CAMEL-25162 camel-oauth post login
url entry into the 4.22 and 4.18 upgrade guides
d0e92a5eaf55 is described below
commit d0e92a5eaf5588346965d182192e5bfb3f45acde
Author: Claus Ibsen <[email protected]>
AuthorDate: Thu Oct 1 10:10:24 2026 +0200
chore: docs - sync the CAMEL-25162 camel-oauth post login url entry into
the 4.22 and 4.18 upgrade guides
CAMEL-25162 is being backported to camel-4.22.x (#27179) and camel-4.18.x
(#27180), and the
upgrade guides for every release line live on main, so the entry #27118
added to the 4.23 guide
needs its counterpart under the matching 4.22.1 -> 4.22.2 and 4.18.4 ->
4.18.5 sections.
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
Signed-off-by: Claus Ibsen <[email protected]>
---
.../modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc | 12 ++++++++++++
.../modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc | 12 ++++++++++++
2 files changed, 24 insertions(+)
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
index a123740946f4..5eb98fe56444 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_18.adoc
@@ -24,6 +24,18 @@ than the configured `maxDecompressedSize` fails with an
`IOException`, as docume
`IOHelper.copy(InputStream, OutputStream, int, boolean, long)` now returns
`Integer.MAX_VALUE`, instead of a
negative number, when it copies more than `Integer.MAX_VALUE` bytes.
+=== camel-oauth - the post login url is confined to the configured redirect
uri origin
+
+The post login url of the authorization code flow is now always built from the
origin (`scheme://host[:port]`)
+of the configured `camel.oauth.redirect-uri`, plus the requested path.
`OAuthCodeFlowProcessor` previously
+rebuilt that url from the `X-Forwarded-Proto` / `X-Forwarded-Host` /
`X-Forwarded-Port` request headers, or
+from the `Host` header behind `CamelHttpUrl` when those were absent. All of
those are set by the caller, so
+a request could point the post login redirect at any origin. A deployment
behind an ingress or an OpenShift
+Route still redirects to its externally reachable address, because
`camel.oauth.redirect-uri` is the address
+the identity provider sends the browser back to. Deployments whose external
address differs from that
+property must set it to the address the browser actually reaches; a request
announcing another origin is now
+redirected to the configured one and a warning is logged.
+
=== camel-core - masking of sensitive values in endpoint URIs
`URISupport.sanitizeUri()`, which masks secrets in endpoint URIs shown in
logs, events, JMX names and error
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
index 980426dfa44e..3a928bf16255 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
@@ -24,6 +24,18 @@ than the configured `maxDecompressedSize` fails with an
`IOException`, as docume
`IOHelper.copy(InputStream, OutputStream, int, boolean, long)` now returns
`Integer.MAX_VALUE`, instead of a
negative number, when it copies more than `Integer.MAX_VALUE` bytes.
+=== camel-oauth - the post login url is confined to the configured redirect
uri origin
+
+The post login url of the authorization code flow is now always built from the
origin (`scheme://host[:port]`)
+of the configured `camel.oauth.redirect-uri`, plus the requested path.
`OAuthCodeFlowProcessor` previously
+rebuilt that url from the `X-Forwarded-Proto` / `X-Forwarded-Host` /
`X-Forwarded-Port` request headers, or
+from the `Host` header behind `CamelHttpUrl` when those were absent. All of
those are set by the caller, so
+a request could point the post login redirect at any origin. A deployment
behind an ingress or an OpenShift
+Route still redirects to its externally reachable address, because
`camel.oauth.redirect-uri` is the address
+the identity provider sends the browser back to. Deployments whose external
address differs from that
+property must set it to the address the browser actually reaches; a request
announcing another origin is now
+redirected to the configured one and a warning is logged.
+
=== camel-core - masking of sensitive values in endpoint URIs
`URISupport.sanitizeUri()`, which masks secrets in endpoint URIs shown in
logs, events, JMX names and error