davsclaus opened a new pull request, #27490:
URL: https://github.com/apache/camel/pull/27490

   Backport of #26725 
([CAMEL-24440](https://issues.apache.org/jira/browse/CAMEL-24440)) to 
`camel-4.22.x`. The backport bot stopped on a conflict in the 4.23 upgrade 
guide and never opened this PR.
   
   `CryptoDataFormat` now:
   - generates a per-message initialization vector when inlining,
   - reports one uniform `Message authentication failed` error instead of a 
distinguishable padding or MAC error (a padding-oracle),
   - no longer includes the MAC values in the error message,
   - limits the length of the inlined vector.
   
   None of these changes affects the format of data that was already written.
   
   Differences from the original:
   - the upgrade note goes into `camel-4x-upgrade-guide-4_22.adoc`, in the 
4.22.2 section, instead of `4_23`. A follow-up PR on `main` adds the same note 
there, since `main` holds all the upgrade guides.
   - `CryptoDataFormatLargePayloadTest` uses the version from `main` again. The 
CAMEL-25179 backport (#27175) had changed it to expect the old `Expected mac 
did not match actual mac` message, which this change replaces.
   
   The production code applied without conflicts.
   
   Tested locally: `camel-crypto` ran 86 tests with 0 failures.
   
   _Claude Code on behalf of davsclaus_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to