davsclaus opened a new pull request, #27490: URL: https://github.com/apache/camel/pull/27490
Backport of #26725 ([CAMEL-24440](https://issues.apache.org/jira/browse/CAMEL-24440)) to `camel-4.22.x`. The backport bot stopped on a conflict in the 4.23 upgrade guide and never opened this PR. `CryptoDataFormat` now: - generates a per-message initialization vector when inlining, - reports one uniform `Message authentication failed` error instead of a distinguishable padding or MAC error (a padding-oracle), - no longer includes the MAC values in the error message, - limits the length of the inlined vector. None of these changes affects the format of data that was already written. Differences from the original: - the upgrade note goes into `camel-4x-upgrade-guide-4_22.adoc`, in the 4.22.2 section, instead of `4_23`. A follow-up PR on `main` adds the same note there, since `main` holds all the upgrade guides. - `CryptoDataFormatLargePayloadTest` uses the version from `main` again. The CAMEL-25179 backport (#27175) had changed it to expect the old `Expected mac did not match actual mac` message, which this change replaces. The production code applied without conflicts. Tested locally: `camel-crypto` ran 86 tests with 0 failures. _Claude Code on behalf of davsclaus_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
