gnodet-bot commented on code in PR #27489:
URL: https://github.com/apache/camel/pull/27489#discussion_r4206360844
##########
components/camel-undertow/src/main/java/org/apache/camel/component/undertow/UndertowEndpoint.java:
##########
@@ -487,6 +490,43 @@ public void setAllowedRoles(String allowedRoles) {
this.allowedRoles = allowedRoles;
}
+ /**
+ * The allowed roles of this endpoint, or of the component when the
endpoint does not configure any.
+ */
+ public List<String> computeAllowedRoles() {
+ String allowedRolesString = allowedRoles != null ? allowedRoles :
getComponent().getAllowedRoles();
+ return allowedRolesString == null ? null :
Arrays.asList(allowedRolesString.split("\\s*,\\s*"));
+ }
+
+ /**
+ * Whether requests to this endpoint are checked by the {@link
UndertowSecurityProvider} or restricted to the
+ * allowed roles.
+ */
+ public boolean requiresAuthentication() {
+ List<String> roles = computeAllowedRoles();
+ return securityProvider != null || roles != null && !roles.isEmpty();
+ }
+
+ /**
+ * Applies the {@link UndertowSecurityProvider} and the allowed roles of
this endpoint to a request.
+ *
+ * @return {@link StatusCodes#OK} if the request is allowed, otherwise the
status code to reject it with
+ */
+ public int authenticate(HttpServerExchange httpExchange) throws Exception {
+ List<String> roles = computeAllowedRoles();
+ if (securityProvider != null) {
+ // security provider decides, whether endpoint is accessible
+ return securityProvider.authenticate(httpExchange, roles);
+ }
+ if (roles != null && !roles.isEmpty()) {
+ // this case could happen due to bad configuration
+ // if allowedRoles are present but securityProvider is not, access
has to be denied in this case
+ LOG.warn("Illegal state caused by missing securityProvider but
existing allowed roles!");
Review Comment:
Pre-existing behavior moved from `UndertowConsumer` with a typo fix
(`securitProvider` → `securityProvider`). This `WARN` fires on every request to
a misconfigured endpoint (one with `allowedRoles` set but no
`securityProvider`). Not introduced by this PR — pre-existing log noise pattern.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]