oscerd opened a new pull request, #27481: URL: https://github.com/apache/camel/pull/27481
## Backport of #27432 Cherry-pick of #27432 onto `camel-4.18.x`. **Original PR:** #27432 - CAMEL-25376: camel-netty-http - match security constraint roles by exact role name **Original author:** @oscerd **Target branch:** `camel-4.18.x` Adapted for `camel-4.18.x`, so not a straight cherry-pick: - the two new tests import `org.apache.camel.test.junit5` instead of `junit6`, because this branch is still on camel-test-junit5 - the catalog copy of the component docs is not included, because `camel-4.18.x` does not mirror component docs into the catalog The code and the component docs are identical to #27432 (and to the `camel-4.22.x` backport #27441). The upgrade-guide notes are not part of this backport: all the guides live on `main`, and #27432 already added the 4.18.5 note to `camel-4x-upgrade-guide-4_18.adoc` there. ### Original description [CAMEL-25376](https://issues.apache.org/jira/browse/CAMEL-25376) `HttpServerChannelHandler.matchesRoles` now treats the roles of a `SecurityConstraintMapping` inclusion as the comma-separated list of role names that the `SecurityConstraint` contract and the component documentation describe, and accepts the user only when one of the user roles is equal to one of those names: - the configured roles and the user roles are split on comma and trimmed, and blank entries are ignored - the comparison is case-sensitive - a value of `*` still accepts any role - the `SecurityConstraint` SPI and the protected `matchesRoles(String, String)` signature are unchanged This matches how role lists are handled elsewhere, for example `allowedRoles` in camel-undertow and `requiredRoles` in camel-keycloak. ### Tests - `HttpServerChannelHandlerRolesTest`: configured roles against user roles, covering the wildcard, lists with and without whitespace, whole-name matching, case, blank entries and a user without roles - `NettyHttpBasicAuthConstraintRolesTest`: end to end through the JAAS test login, with role-restricted `SecurityConstraintMapping` inclusions ### Docs - netty-http component docs: the matching rules in "Specifying ACL on web resources" (plus the catalog copy) - upgrade-guide notes for 4.23, 4.22.2 and 4.18.5. All the guides live on `main`, so the 4.22.x and 4.18.x backports will carry the code, tests and component docs only _Claude Code on behalf of Andrea Cosentino_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
