oscerd commented on code in PR #27482:
URL: https://github.com/apache/camel/pull/27482#discussion_r4205307339


##########
components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java:
##########
@@ -139,7 +139,7 @@ public class MongoDbEndpoint extends DefaultEndpoint 
implements EndpointServiceL
     //Connection Configuration
     @UriParam(label = "security", defaultValue = "false")
     private boolean tls;
-    @UriParam(label = "security", defaultValue = "false")
+    @UriParam(label = "security", defaultValue = "false", security = 
"insecure:ssl")

Review Comment:
   Good catch — added in 1082933, modelled on the camel-hivemq `ssl` entry: it 
spells out that the prod profile now fails startup for 
`camel.component.mongodb.tlsAllowInvalidHostnames = true` and how to keep the 
setting via `camel.security.allowedProperties`.
   
   I left the other two out of the guide on purpose: aws2-transcribe only 
corrects the *advertised* default (the runtime default was already `false`, 
since the field is a bare boolean), and the twitter `httpProxyPassword` was 
already treated as sensitive at runtime because `httpproxypassword` is in 
`SensitiveUtils` — the plain-text-secret check goes through 
`CamelContextHelper.containsSensitive`, not the catalog flag — so only the 
catalog metadata changes there. Happy to add notes for those too if you'd 
rather have them recorded.
   
   _Claude Code on behalf of @oscerd_



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to