allthingssecurity opened a new pull request, #27346:
URL: https://github.com/apache/camel/pull/27346

   # Description
   
   [CAMEL-25305](https://issues.apache.org/jira/browse/CAMEL-25305)
   
   camel-netty-http converted a `String` body with the exchange charset 
(`CamelCharsetName`, UTF-8 by default), also when the `Content-Type` declared 
another charset, so a route answering `text/plain; charset=ISO-8859-1` with 
`Grüße aus Köln` sent 17 UTF-8 bytes labelled ISO-8859-1; the producer did the 
same for the request body. And the request charset was found with the 
deprecated `HttpUtil.getCharsetFromContentType`, which only matches `charset=` 
in lower case (parameter names are case-insensitive, RFC 9110 5.6.6), so 
`Charset=ISO-8859-1` was decoded as UTF-8.
   
   The same defect was fixed for camel-platform-http-vertx (CAMEL-25217) and 
camel-undertow (CAMEL-25248).
   
   This change:
   - converts a `String` body with the charset the `Content-Type` declares, 
when there is a supported one (consumer response and producer request); other 
bodies and messages without a declared charset are converted as before;
   - adds `NettyHttpHelper.getCharsetFromContentType` (case-insensitive, no 
UTF-8 default) and uses it in the consumer and in `NettyHttpConverter`;
   - adds an upgrade guide note.
   
   Tests: new `NettyHttpStringBodyCharsetTest`: response with a declared 
ISO-8859-1, request with `Charset=ISO-8859-1`, producer request with a declared 
ISO-8859-1; control: a response without a charset is UTF-8; a unit test of 
`NettyHttpHelper.getCharsetFromContentType` (case-insensitive, quoted value, 
and `null` without a charset parameter, so the exchange charset stays in use). 
Without the change 3 fail (2 runs), the control passes; with it the module 
passes (281 tests, 8 skipped).
   
   Found with the Lean 4 model of the String body encoding written for 
CAMEL-25217: "a peer that decodes with the declared charset reads back the 
text" fails for every text with a character outside US-ASCII and holds with the 
change.
   
   # Target
   
   - [x] I checked that the commit is targeting the correct branch (Camel 4 
uses the `main` branch)
   
   # Tracking
   - [x] If this is a large change, bug fix, or code improvement, I checked 
there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for 
the change (usually before you start working on it).
   
   # Apache Camel coding standards and style
   
   - [x] I checked that each commit in the pull request has a meaningful 
subject line and body.
   - [ ] I have run `mvn clean install -DskipTests` locally from root folder 
and I have committed all auto-generated changes.
     (I built and tested the affected module, including the formatter and 
import-sort plugins. I did not run the full root build.)
   
   # AI-assisted contributions
   
   - [x] If this PR includes AI-generated code, commits have proper 
co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR 
description identifies the AI tool used.
     This PR was prepared with Claude Code (Claude Opus 5.5). The commit 
carries a `Co-Authored-By` trailer.
   
   _Claude Code on behalf of allthingssecurity_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to