oscerd opened a new pull request, #27481:
URL: https://github.com/apache/camel/pull/27481

   ## Backport of #27432
   
   Cherry-pick of #27432 onto `camel-4.18.x`.
   
   **Original PR:** #27432 - CAMEL-25376: camel-netty-http - match security 
constraint roles by exact role name
   **Original author:** @oscerd
   **Target branch:** `camel-4.18.x`
   
   Adapted for `camel-4.18.x`, so not a straight cherry-pick:
   
   - the two new tests import `org.apache.camel.test.junit5` instead of 
`junit6`, because this branch is still on camel-test-junit5
   - the catalog copy of the component docs is not included, because 
`camel-4.18.x` does not mirror component docs into the catalog
   
   The code and the component docs are identical to #27432 (and to the 
`camel-4.22.x` backport #27441). The upgrade-guide notes are not part of this 
backport: all the guides live on `main`, and #27432 already added the 4.18.5 
note to `camel-4x-upgrade-guide-4_18.adoc` there.
   
   ### Original description
   
   [CAMEL-25376](https://issues.apache.org/jira/browse/CAMEL-25376)
   
   `HttpServerChannelHandler.matchesRoles` now treats the roles of a 
`SecurityConstraintMapping` inclusion as the comma-separated list of role names 
that the `SecurityConstraint` contract and the component documentation 
describe, and accepts the user only when one of the user roles is equal to one 
of those names:
   
   - the configured roles and the user roles are split on comma and trimmed, 
and blank entries are ignored
   - the comparison is case-sensitive
   - a value of `*` still accepts any role
   - the `SecurityConstraint` SPI and the protected `matchesRoles(String, 
String)` signature are unchanged
   
   This matches how role lists are handled elsewhere, for example 
`allowedRoles` in camel-undertow and `requiredRoles` in camel-keycloak.
   
   ### Tests
   
   - `HttpServerChannelHandlerRolesTest`: configured roles against user roles, 
covering the wildcard, lists with and without whitespace, whole-name matching, 
case, blank entries and a user without roles
   - `NettyHttpBasicAuthConstraintRolesTest`: end to end through the JAAS test 
login, with role-restricted `SecurityConstraintMapping` inclusions
   
   ### Docs
   
   - netty-http component docs: the matching rules in "Specifying ACL on web 
resources" (plus the catalog copy)
   - upgrade-guide notes for 4.23, 4.22.2 and 4.18.5. All the guides live on 
`main`, so the 4.22.x and 4.18.x backports will carry the code, tests and 
component docs only
   
   _Claude Code on behalf of Andrea Cosentino_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to