davsclaus opened a new pull request, #27492:
URL: https://github.com/apache/camel/pull/27492

   Port of #27435 and #27443 
([CAMEL-25375](https://issues.apache.org/jira/browse/CAMEL-25375)) to 
`camel-4.18.x`.
   
   WebSocket (`ws://`, `wss://`) endpoints of camel-undertow now apply 
`securityProvider` / `securityConfiguration`, `allowedRoles`, `handlers` and 
`accessLog` to the upgrade request, as HTTP endpoints do. A connection that did 
not pass these checks is not served.
   
   **This is not a straight cherry-pick and needs a review.** `camel-4.18.x` 
does not have the `oauthProfile` option of the WebSocket consumer 
(CAMEL-23723), and the main commits build on it. The port leaves out the OAuth 
parts:
   - `CamelWebSocketHandler`: no OAuth validation in the upgrade or on connect. 
The checks are the security provider, `allowedRoles` and `handlers`. Apart from 
the OAuth code, the file is the same as on `main`.
   - `UndertowConsumer`: adds the fail-closed check of the WebSocket channel 
(`rejectUnauthenticatedWebSocketChannel`) to `sendMessage` and 
`sendEventNotification`. On `main` these calls came with CAMEL-23723. There is 
no OAuth handler.
   - `UndertowWsSecurityWithoutProviderTest` drops its `oauthProfile` case, and 
`UndertowWsOAuthProfileConsumerWindowTest` is not ported.
   - Docs: the "WebSocket endpoints" section of `undertow-component.adoc` and 
the note in the 4.18.5 section of the 4.18 upgrade guide use the same text as 
on `main`. `main` already has the 4.18 upgrade-guide note.
   
   Tests, run locally:
   - `camel-undertow`: 189 tests, 0 failures, 1 skipped. 
`camel-undertow-spring-security`: 5 tests, 0 failures. No generated files 
changed.
   - Checked that the tests guard the change. With the `camel-4.18.x` sources 
of `camel-undertow/src/main`, `SecurityProviderWebSocketTest`, 
`SecurityProviderRolesFromComponentWebSocketTest` and 
`UndertowWsSecurityWithoutProviderTest` fail (9 failures and 2 errors out of 13 
tests). With this change they pass.
   
   _Claude Code on behalf of davsclaus_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to