oscerd commented on PR #27332: URL: https://github.com/apache/camel/pull/27332#issuecomment-5980088077
Thanks @davsclaus — addressed; new head pushed. 1. **Placement** — the outer wrap is deliberate; docs corrected (javadoc + adoc + PR description no longer say "inside the route / visible to tracing" — the guard runs in front of the route, a deny is logged at `WARN` and relayed, no span). Truly-inside-the-route (span/metric/event + `onException`) needs model-level policy injection; follow-up to open. See the inline reply. 2. **Overlap with #27264** — acknowledged; whichever merges first, I rebase the second onto it and reconcile the adoc (additive). The "until CAMEL-24832" bullet is already in. 3. **Tests** — added: `AiToolComponentAuthorizationPolicyTest` (component-level policy + endpoint override — the guard-by-construction headline); a policy that sets the exception on the exchange instead of throwing (→ `AuthorizationDenied`); a normal route error with an allowing policy (→ `ExecutionError`, not misclassified); and a deny over MCP returned to the client as an error. The authenticated-principal-over-MCP test and the warm-up-window reproducer were already in. (An unauthenticated / no-auth MCP call getting no principal: the bridge stamps the property only when a principal is present, and the stdio engine passes none, so no principal is ever forged — a dedicated no-auth integration test is a follow-up.) 4. **SPI impact** — added a 4.23 upgrade-guide note: `AiToolResult` is sealed and the new `AuthorizationDenied` variant requires out-of-tree consumers (e.g. a final `else` casting to `ExecutionError`) to add a branch. 5. **`deregisterEarly()`** — fixed: it now stops and nulls `toolProcessor` (the guard that `prepare()` may have started during early registration), matching `doStop`. Follow-ups I'll open once this settles: denial observability (run the guard inside the route / emit an event); a runtime-neutral MCP principal name/roles so Camel's shipped policies work over MCP; and wiring the Spring Boot and Quarkus MCP engines and the quarkus `CamelAiToolProvider` to pass the principal. _Claude Code on behalf of oscerd_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
