davsclaus opened a new pull request, #27492: URL: https://github.com/apache/camel/pull/27492
Port of #27435 and #27443 ([CAMEL-25375](https://issues.apache.org/jira/browse/CAMEL-25375)) to `camel-4.18.x`. WebSocket (`ws://`, `wss://`) endpoints of camel-undertow now apply `securityProvider` / `securityConfiguration`, `allowedRoles`, `handlers` and `accessLog` to the upgrade request, as HTTP endpoints do. A connection that did not pass these checks is not served. **This is not a straight cherry-pick and needs a review.** `camel-4.18.x` does not have the `oauthProfile` option of the WebSocket consumer (CAMEL-23723), and the main commits build on it. The port leaves out the OAuth parts: - `CamelWebSocketHandler`: no OAuth validation in the upgrade or on connect. The checks are the security provider, `allowedRoles` and `handlers`. Apart from the OAuth code, the file is the same as on `main`. - `UndertowConsumer`: adds the fail-closed check of the WebSocket channel (`rejectUnauthenticatedWebSocketChannel`) to `sendMessage` and `sendEventNotification`. On `main` these calls came with CAMEL-23723. There is no OAuth handler. - `UndertowWsSecurityWithoutProviderTest` drops its `oauthProfile` case, and `UndertowWsOAuthProfileConsumerWindowTest` is not ported. - Docs: the "WebSocket endpoints" section of `undertow-component.adoc` and the note in the 4.18.5 section of the 4.18 upgrade guide use the same text as on `main`. `main` already has the 4.18 upgrade-guide note. Tests, run locally: - `camel-undertow`: 189 tests, 0 failures, 1 skipped. `camel-undertow-spring-security`: 5 tests, 0 failures. No generated files changed. - Checked that the tests guard the change. With the `camel-4.18.x` sources of `camel-undertow/src/main`, `SecurityProviderWebSocketTest`, `SecurityProviderRolesFromComponentWebSocketTest` and `UndertowWsSecurityWithoutProviderTest` fail (9 failures and 2 errors out of 13 tests). With this change they pass. _Claude Code on behalf of davsclaus_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
