This is an automated email from the ASF dual-hosted git repository.
oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new ce623be66447 CAMEL-25409: camel-mongodb, camel-aws2-transcribe,
camel-twitter - fix security metadata that does not match the code (#27482)
ce623be66447 is described below
commit ce623be6644756a7e06fe33b539f1d7617593c74
Author: Andrea Cosentino <[email protected]>
AuthorDate: Wed Oct 7 13:37:06 2026 +0200
CAMEL-25409: camel-mongodb, camel-aws2-transcribe, camel-twitter - fix
security metadata that does not match the code (#27482)
A sweep of every catalog option against the security metadata the policy
framework relies on found three options whose metadata contradicts what the
code does. All three are metadata-only defects - the runtime default is the
safe one in every case - but each defeats a mechanism meant to catch
misconfiguration.
- camel-mongodb: tlsAllowInvalidHostnames disables TLS hostname verification
(MongoDbEndpoint calls invalidHostNameAllowed(true)) but was not marked
security = "insecure:ssl", so camel.main.profile=prod did not refuse it.
The 4.23 upgrade guide documents the startup change for prod-profile users
and how to keep the setting through camel.security.allowedProperties.
- camel-aws2-transcribe: trustAllCertificates declared defaultValue = "true"
on a bare boolean field. This is a metadata-only correction with no
behavioral change: the field has no initializer, so the runtime default
was
always false; only the advertised default in the catalog, the docs and the
generated DSL builders was wrong.
- camel-twitter: the component-level httpProxyPassword was not marked as a
secret, although the endpoint-level twin in TwitterConfiguration is (it
was
already treated as sensitive at runtime through SensitiveUtils).
SecurityUtilsTest covers the hostname-verification options so a future
option
of this kind cannot silently go unregistered.
Co-Authored-By: Claude Opus 5 <[email protected]>
---
.../org/apache/camel/catalog/components/aws2-transcribe.json | 4 ++--
.../org/apache/camel/catalog/components/mongodb.json | 2 +-
.../camel/catalog/components/twitter-directmessage.json | 2 +-
.../org/apache/camel/catalog/components/twitter-search.json | 2 +-
.../org/apache/camel/catalog/components/twitter-timeline.json | 2 +-
.../camel/component/aws2/transcribe/aws2-transcribe.json | 4 ++--
.../component/aws2/transcribe/Transcribe2Configuration.java | 2 +-
.../META-INF/org/apache/camel/component/mongodb/mongodb.json | 2 +-
.../org/apache/camel/component/mongodb/MongoDbEndpoint.java | 2 +-
.../twitter/directmessage/twitter-directmessage.json | 2 +-
.../apache/camel/component/twitter/search/twitter-search.json | 2 +-
.../camel/component/twitter/timeline/twitter-timeline.json | 2 +-
.../camel/component/twitter/AbstractTwitterComponent.java | 2 +-
.../src/main/java/org/apache/camel/util/SecurityUtils.java | 3 +++
.../test/java/org/apache/camel/util/SecurityUtilsTest.java | 10 ++++++++++
.../modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc | 11 +++++++++++
.../component/dsl/Aws2TranscribeComponentBuilderFactory.java | 2 +-
.../endpoint/dsl/Transcribe2EndpointBuilderFactory.java | 4 ++--
18 files changed, 42 insertions(+), 18 deletions(-)
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
index 4fb1f99f040d..46f984f20ada 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
@@ -36,7 +36,7 @@
"proxyProtocol": { "index": 9, "kind": "property", "displayName": "Proxy
Protocol", "group": "producer", "label": "", "required": false, "type": "enum",
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS"
], "deprecated": false, "autowired": false, "secret": false, "defaultValue":
"HTTPS", "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To define a proxy proto
[...]
"region": { "index": 10, "kind": "property", "displayName": "Region",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "The region in which
Transcribe client needs to work. When using this parameter, the configuration
will expect [...]
"transcribeClient": { "index": 11, "kind": "property", "displayName":
"Transcribe Client", "group": "producer", "label": "", "required": false,
"type": "object", "javaType":
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated":
false, "autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To use a existing
configured AWS Transcribe a [...]
- "trustAllCertificates": { "index": 12, "kind": "property", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": true,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificates [...]
+ "trustAllCertificates": { "index": 12, "kind": "property", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": false,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificates [...]
"uriEndpointOverride": { "index": 13, "kind": "property", "displayName":
"Uri Endpoint Override", "group": "producer", "label": "", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set the overriding uri
endpoint. This option needs to be used in combination with [...]
"useDefaultCredentialsProvider": { "index": 14, "kind": "property",
"displayName": "Use Default Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should expe [...]
"useProfileCredentialsProvider": { "index": 15, "kind": "property",
"displayName": "Use Profile Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should expe [...]
@@ -85,7 +85,7 @@
"proxyProtocol": { "index": 8, "kind": "parameter", "displayName": "Proxy
Protocol", "group": "producer", "label": "", "required": false, "type": "enum",
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS"
], "deprecated": false, "autowired": false, "secret": false, "defaultValue":
"HTTPS", "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To define a proxy prot
[...]
"region": { "index": 9, "kind": "parameter", "displayName": "Region",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "The region in which
Transcribe client needs to work. When using this parameter, the configuration
will expect [...]
"transcribeClient": { "index": 10, "kind": "parameter", "displayName":
"Transcribe Client", "group": "producer", "label": "", "required": false,
"type": "object", "javaType":
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated":
false, "autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To use a existing
configured AWS Transcribe [...]
- "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": true,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificates [...]
+ "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": false,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificate [...]
"uriEndpointOverride": { "index": 12, "kind": "parameter", "displayName":
"Uri Endpoint Override", "group": "producer", "label": "", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set the overriding uri
endpoint. This option needs to be used in combination wit [...]
"useDefaultCredentialsProvider": { "index": 13, "kind": "parameter",
"displayName": "Use Default Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should exp [...]
"useProfileCredentialsProvider": { "index": 14, "kind": "parameter",
"displayName": "Use Profile Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should exp [...]
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
index 0118ae0c8885..0ba1c9451ab4 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
@@ -116,7 +116,7 @@
"password": { "index": 54, "kind": "parameter", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": true, "security": "secret", "description": "User password for mongodb
connection" },
"sslContextParameters": { "index": 55, "kind": "parameter", "displayName":
"Ssl Context Parameters", "group": "security", "label": "security", "required":
false, "type": "object", "javaType":
"org.apache.camel.support.jsse.SSLContextParameters", "deprecated": false,
"autowired": false, "secret": false, "description": "SSL configuration using a
Camel SSLContextParameters object. When configured, TLS is automatically
enabled on the connection." },
"tls": { "index": 56, "kind": "parameter", "displayName": "Tls", "group":
"security", "label": "security", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "defaultValue": false, "description": "Specifies that all communication
with MongoDB instances should use TLS. Supersedes the ssl option. Default:
false" },
- "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter",
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label":
"security", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "description": "Specifies that the driver should allow invalid hostnames
in the certificate for TLS connections. Supersedes sslInvalidHostNameAllowed.
Has the same effect as tlsInsecure by setti [...]
+ "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter",
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label":
"security", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "security":
"insecure:ssl", "defaultValue": false, "description": "Specifies that the
driver should allow invalid hostnames in the certificate for TLS connections.
Supersedes sslInvalidHostNameAllowed. Has the same ef [...]
"username": { "index": 58, "kind": "parameter", "displayName": "Username",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": true, "security": "secret", "description": "Username for mongodb
connection" }
}
}
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
index 905b0d49c39c..9f0ae4be0f1f 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
@@ -31,7 +31,7 @@
"healthCheckConsumerEnabled": { "index": 3, "kind": "property",
"displayName": "Health Check Consumer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all consumer based health checks
from this component" },
"healthCheckProducerEnabled": { "index": 4, "kind": "property",
"displayName": "Health Check Producer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all producer based health checks
from this component. Notice: Camel has by default disabled all producer based
health-checks. You can turn on producer [...]
"httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy host which can be used
for the camel-twitter." },
- "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "description": "The http proxy password
which can be used for the camel-twitter." },
+ "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": true, "security": "secret", "description": "The
http proxy password which can be used for the camel-twitter." },
"httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type":
"integer", "javaType": "int", "deprecated": false, "autowired": false,
"secret": false, "description": "The http proxy port which can be used for the
camel-twitter." },
"httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy user which can be used
for the camel-twitter." },
"accessToken": { "index": 9, "kind": "property", "displayName": "Access
Token", "group": "security", "label": "security", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": true, "security": "secret", "description": "The access token"
},
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
index 346e50896a23..7b828c775f4c 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
@@ -31,7 +31,7 @@
"healthCheckConsumerEnabled": { "index": 3, "kind": "property",
"displayName": "Health Check Consumer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all consumer based health checks
from this component" },
"healthCheckProducerEnabled": { "index": 4, "kind": "property",
"displayName": "Health Check Producer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all producer based health checks
from this component. Notice: Camel has by default disabled all producer based
health-checks. You can turn on producer [...]
"httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy host which can be used
for the camel-twitter." },
- "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "description": "The http proxy password
which can be used for the camel-twitter." },
+ "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": true, "security": "secret", "description": "The
http proxy password which can be used for the camel-twitter." },
"httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type":
"integer", "javaType": "int", "deprecated": false, "autowired": false,
"secret": false, "description": "The http proxy port which can be used for the
camel-twitter." },
"httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy user which can be used
for the camel-twitter." },
"accessToken": { "index": 9, "kind": "property", "displayName": "Access
Token", "group": "security", "label": "security", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": true, "security": "secret", "description": "The access token"
},
diff --git
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
index d85cb6f8e83e..4b633cda9130 100644
---
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
+++
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
@@ -31,7 +31,7 @@
"healthCheckConsumerEnabled": { "index": 3, "kind": "property",
"displayName": "Health Check Consumer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all consumer based health checks
from this component" },
"healthCheckProducerEnabled": { "index": 4, "kind": "property",
"displayName": "Health Check Producer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all producer based health checks
from this component. Notice: Camel has by default disabled all producer based
health-checks. You can turn on producer [...]
"httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy host which can be used
for the camel-twitter." },
- "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "description": "The http proxy password
which can be used for the camel-twitter." },
+ "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": true, "security": "secret", "description": "The
http proxy password which can be used for the camel-twitter." },
"httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type":
"integer", "javaType": "int", "deprecated": false, "autowired": false,
"secret": false, "description": "The http proxy port which can be used for the
camel-twitter." },
"httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy user which can be used
for the camel-twitter." },
"accessToken": { "index": 9, "kind": "property", "displayName": "Access
Token", "group": "security", "label": "security", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": true, "security": "secret", "description": "The access token"
},
diff --git
a/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
b/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
index 4fb1f99f040d..46f984f20ada 100644
---
a/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
+++
b/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
@@ -36,7 +36,7 @@
"proxyProtocol": { "index": 9, "kind": "property", "displayName": "Proxy
Protocol", "group": "producer", "label": "", "required": false, "type": "enum",
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS"
], "deprecated": false, "autowired": false, "secret": false, "defaultValue":
"HTTPS", "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To define a proxy proto
[...]
"region": { "index": 10, "kind": "property", "displayName": "Region",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "The region in which
Transcribe client needs to work. When using this parameter, the configuration
will expect [...]
"transcribeClient": { "index": 11, "kind": "property", "displayName":
"Transcribe Client", "group": "producer", "label": "", "required": false,
"type": "object", "javaType":
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated":
false, "autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To use a existing
configured AWS Transcribe a [...]
- "trustAllCertificates": { "index": 12, "kind": "property", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": true,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificates [...]
+ "trustAllCertificates": { "index": 12, "kind": "property", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": false,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificates [...]
"uriEndpointOverride": { "index": 13, "kind": "property", "displayName":
"Uri Endpoint Override", "group": "producer", "label": "", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set the overriding uri
endpoint. This option needs to be used in combination with [...]
"useDefaultCredentialsProvider": { "index": 14, "kind": "property",
"displayName": "Use Default Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should expe [...]
"useProfileCredentialsProvider": { "index": 15, "kind": "property",
"displayName": "Use Profile Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should expe [...]
@@ -85,7 +85,7 @@
"proxyProtocol": { "index": 8, "kind": "parameter", "displayName": "Proxy
Protocol", "group": "producer", "label": "", "required": false, "type": "enum",
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS"
], "deprecated": false, "autowired": false, "secret": false, "defaultValue":
"HTTPS", "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To define a proxy prot
[...]
"region": { "index": 9, "kind": "parameter", "displayName": "Region",
"group": "producer", "label": "", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "The region in which
Transcribe client needs to work. When using this parameter, the configuration
will expect [...]
"transcribeClient": { "index": 10, "kind": "parameter", "displayName":
"Transcribe Client", "group": "producer", "label": "", "required": false,
"type": "object", "javaType":
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated":
false, "autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "To use a existing
configured AWS Transcribe [...]
- "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": true,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificates [...]
+ "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName":
"Trust All Certificates", "group": "producer", "label": "", "required": false,
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired":
false, "secret": false, "security": "insecure:ssl", "defaultValue": false,
"configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "If we want to trust all
certificate [...]
"uriEndpointOverride": { "index": 12, "kind": "parameter", "displayName":
"Uri Endpoint Override", "group": "producer", "label": "", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set the overriding uri
endpoint. This option needs to be used in combination wit [...]
"useDefaultCredentialsProvider": { "index": 13, "kind": "parameter",
"displayName": "Use Default Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should exp [...]
"useProfileCredentialsProvider": { "index": 14, "kind": "parameter",
"displayName": "Use Profile Credentials Provider", "group": "producer",
"label": "", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "configurationClass":
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration",
"configurationField": "configuration", "description": "Set whether the
Transcribe client should exp [...]
diff --git
a/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
b/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
index 9bee49097a92..1125854fd3bc 100644
---
a/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
+++
b/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
@@ -45,7 +45,7 @@ public class Transcribe2Configuration implements Cloneable,
AwsCommonConfigurati
private boolean overrideEndpoint;
@UriParam
private String uriEndpointOverride;
- @UriParam(security = "insecure:ssl", defaultValue = "true")
+ @UriParam(security = "insecure:ssl", defaultValue = "false")
private boolean trustAllCertificates;
@UriParam(defaultValue = "false")
private boolean useDefaultCredentialsProvider;
diff --git
a/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
b/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
index 0118ae0c8885..0ba1c9451ab4 100644
---
a/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
+++
b/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
@@ -116,7 +116,7 @@
"password": { "index": 54, "kind": "parameter", "displayName": "Password",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": true, "security": "secret", "description": "User password for mongodb
connection" },
"sslContextParameters": { "index": 55, "kind": "parameter", "displayName":
"Ssl Context Parameters", "group": "security", "label": "security", "required":
false, "type": "object", "javaType":
"org.apache.camel.support.jsse.SSLContextParameters", "deprecated": false,
"autowired": false, "secret": false, "description": "SSL configuration using a
Camel SSLContextParameters object. When configured, TLS is automatically
enabled on the connection." },
"tls": { "index": 56, "kind": "parameter", "displayName": "Tls", "group":
"security", "label": "security", "required": false, "type": "boolean",
"javaType": "boolean", "deprecated": false, "autowired": false, "secret":
false, "defaultValue": false, "description": "Specifies that all communication
with MongoDB instances should use TLS. Supersedes the ssl option. Default:
false" },
- "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter",
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label":
"security", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue":
false, "description": "Specifies that the driver should allow invalid hostnames
in the certificate for TLS connections. Supersedes sslInvalidHostNameAllowed.
Has the same effect as tlsInsecure by setti [...]
+ "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter",
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label":
"security", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "security":
"insecure:ssl", "defaultValue": false, "description": "Specifies that the
driver should allow invalid hostnames in the certificate for TLS connections.
Supersedes sslInvalidHostNameAllowed. Has the same ef [...]
"username": { "index": 58, "kind": "parameter", "displayName": "Username",
"group": "security", "label": "security", "required": false, "type": "string",
"javaType": "java.lang.String", "deprecated": false, "autowired": false,
"secret": true, "security": "secret", "description": "Username for mongodb
connection" }
}
}
diff --git
a/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
b/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
index 97949cd2eb88..774d095c2b9b 100644
---
a/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
+++
b/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
@@ -139,7 +139,7 @@ public class MongoDbEndpoint extends DefaultEndpoint
implements EndpointServiceL
//Connection Configuration
@UriParam(label = "security", defaultValue = "false")
private boolean tls;
- @UriParam(label = "security", defaultValue = "false")
+ @UriParam(label = "security", defaultValue = "false", security =
"insecure:ssl")
private boolean tlsAllowInvalidHostnames;
@UriParam(label = "security")
private SSLContextParameters sslContextParameters;
diff --git
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
index 905b0d49c39c..9f0ae4be0f1f 100644
---
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
+++
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
@@ -31,7 +31,7 @@
"healthCheckConsumerEnabled": { "index": 3, "kind": "property",
"displayName": "Health Check Consumer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all consumer based health checks
from this component" },
"healthCheckProducerEnabled": { "index": 4, "kind": "property",
"displayName": "Health Check Producer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all producer based health checks
from this component. Notice: Camel has by default disabled all producer based
health-checks. You can turn on producer [...]
"httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy host which can be used
for the camel-twitter." },
- "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "description": "The http proxy password
which can be used for the camel-twitter." },
+ "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": true, "security": "secret", "description": "The
http proxy password which can be used for the camel-twitter." },
"httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type":
"integer", "javaType": "int", "deprecated": false, "autowired": false,
"secret": false, "description": "The http proxy port which can be used for the
camel-twitter." },
"httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy user which can be used
for the camel-twitter." },
"accessToken": { "index": 9, "kind": "property", "displayName": "Access
Token", "group": "security", "label": "security", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": true, "security": "secret", "description": "The access token"
},
diff --git
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
index 346e50896a23..7b828c775f4c 100644
---
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
+++
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
@@ -31,7 +31,7 @@
"healthCheckConsumerEnabled": { "index": 3, "kind": "property",
"displayName": "Health Check Consumer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all consumer based health checks
from this component" },
"healthCheckProducerEnabled": { "index": 4, "kind": "property",
"displayName": "Health Check Producer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all producer based health checks
from this component. Notice: Camel has by default disabled all producer based
health-checks. You can turn on producer [...]
"httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy host which can be used
for the camel-twitter." },
- "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "description": "The http proxy password
which can be used for the camel-twitter." },
+ "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": true, "security": "secret", "description": "The
http proxy password which can be used for the camel-twitter." },
"httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type":
"integer", "javaType": "int", "deprecated": false, "autowired": false,
"secret": false, "description": "The http proxy port which can be used for the
camel-twitter." },
"httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy user which can be used
for the camel-twitter." },
"accessToken": { "index": 9, "kind": "property", "displayName": "Access
Token", "group": "security", "label": "security", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": true, "security": "secret", "description": "The access token"
},
diff --git
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
index d85cb6f8e83e..4b633cda9130 100644
---
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
+++
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
@@ -31,7 +31,7 @@
"healthCheckConsumerEnabled": { "index": 3, "kind": "property",
"displayName": "Health Check Consumer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all consumer based health checks
from this component" },
"healthCheckProducerEnabled": { "index": 4, "kind": "property",
"displayName": "Health Check Producer Enabled", "group": "health", "label":
"health", "required": false, "type": "boolean", "javaType": "boolean",
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true,
"description": "Used for enabling or disabling all producer based health checks
from this component. Notice: Camel has by default disabled all producer based
health-checks. You can turn on producer [...]
"httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy host which can be used
for the camel-twitter." },
- "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": false, "description": "The http proxy password
which can be used for the camel-twitter." },
+ "httpProxyPassword": { "index": 6, "kind": "property", "displayName":
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false,
"type": "string", "javaType": "java.lang.String", "deprecated": false,
"autowired": false, "secret": true, "security": "secret", "description": "The
http proxy password which can be used for the camel-twitter." },
"httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type":
"integer", "javaType": "int", "deprecated": false, "autowired": false,
"secret": false, "description": "The http proxy port which can be used for the
camel-twitter." },
"httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": false, "description": "The http proxy user which can be used
for the camel-twitter." },
"accessToken": { "index": 9, "kind": "property", "displayName": "Access
Token", "group": "security", "label": "security", "required": false, "type":
"string", "javaType": "java.lang.String", "deprecated": false, "autowired":
false, "secret": true, "security": "secret", "description": "The access token"
},
diff --git
a/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
b/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
index 443ef3c872bd..09bdec01f4f9 100644
---
a/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
+++
b/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
@@ -39,7 +39,7 @@ public abstract class AbstractTwitterComponent extends
HealthCheckComponent {
private String httpProxyHost;
@Metadata(label = "proxy")
private String httpProxyUser;
- @Metadata(label = "proxy")
+ @Metadata(label = "proxy", security = "secret")
private String httpProxyPassword;
@Metadata(label = "proxy")
private Integer httpProxyPort;
diff --git
a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
index 7019fd2c1801..be1f32cf6e28 100644
--- a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
+++ b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
@@ -91,6 +91,7 @@ public final class SecurityUtils {
map.put("sslendpointalgorithm", new SecurityOption(INSECURE_SSL,
"none"));
map.put("stricthostkeychecking", new SecurityOption(INSECURE_SSL, ""));
map.put("tls", new SecurityOption(INSECURE_SSL, VALUE_FALSE));
+ map.put("tlsallowinvalidhostnames", new SecurityOption(INSECURE_SSL,
"true"));
map.put("transferexception", new
SecurityOption(INSECURE_SERIALIZATION, "true"));
map.put("transferexchange", new SecurityOption(INSECURE_SERIALIZATION,
"true"));
map.put("trustallcertificates", new SecurityOption(INSECURE_SSL,
"true"));
@@ -203,6 +204,8 @@ public final class SecurityUtils {
"component:sftp"));
owners.put("tls", Set.of(
"component:pinecone"));
+ owners.put("tlsallowinvalidhostnames", Set.of(
+ "component:mongodb"));
owners.put("transferexception", Set.of(
"component:activemq",
"component:activemq6",
diff --git
a/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java
b/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java
index ce1f1816ccd9..02b06367ee21 100644
--- a/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java
+++ b/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java
@@ -48,6 +48,16 @@ class SecurityUtilsTest {
assertEquals("true", options.get("acceptanyspiffeid").insecureValue());
}
+ @Test
+ void testHostnameVerificationOptionsAreRegistered() {
+ // every option that turns off TLS hostname verification must reach
this map, otherwise
+ // camel.main.profile=prod cannot refuse it (CAMEL-25409)
+
assertTrue(SecurityUtils.isInsecureValue("camel.component.mongodb.tlsAllowInvalidHostnames",
true));
+
assertFalse(SecurityUtils.isInsecureValue("camel.component.mongodb.tlsAllowInvalidHostnames",
false));
+
assertTrue(SecurityUtils.isInsecureValue("camel.component.netty-http.hostnameVerification",
false));
+
assertTrue(SecurityUtils.isInsecureValue("camel.component.splunk-hec.skipTlsVerify",
true));
+ }
+
@Test
void testIsPlainTextSecret() {
// plain text values should be detected
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index 380ef42e8968..d2523fd2258c 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -1775,6 +1775,17 @@ This applies only to `camel-hivemq`: setting `ssl=false`
on the other components
policy check below. To keep `camel.component.hivemq.ssl = false` under a
`fail` policy, list it in
`camel.security.allowedProperties`.
+=== camel-mongodb
+
+The `tlsAllowInvalidHostnames` option is now marked `insecure:ssl`. The option
turns off TLS hostname
+verification, so setting `camel.component.mongodb.tlsAllowInvalidHostnames =
true` in the configuration is
+reported by the xref:security-policy.adoc[security policy] check: a warning by
default, and a startup failure
+with the `prod` profile or `camel.security.insecureSslPolicy = fail`.
+
+Only the option of `camel-mongodb` is reported, see the `camel-main` section
about the security policy check
+below. To keep `camel.component.mongodb.tlsAllowInvalidHostnames = true` under
a `fail` policy, list it in
+`camel.security.allowedProperties`.
+
=== camel-main - security policy check matches component options by component
The xref:security-policy.adoc[security policy] check matched an insecure
option by its name only, so an
diff --git
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
index a5df74ab294b..9c57807fb472 100644
---
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
+++
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
@@ -265,7 +265,7 @@ public interface Aws2TranscribeComponentBuilderFactory {
*
* The option is a: <code>boolean</code> type.
*
- * Default: true
+ * Default: false
* Group: producer
*
* @param trustAllCertificates the value to set
diff --git
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
index 1dfd0656a6be..656ad0618a2b 100644
---
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
+++
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
@@ -311,7 +311,7 @@ public interface Transcribe2EndpointBuilderFactory {
*
* The option is a: <code>boolean</code> type.
*
- * Default: true
+ * Default: false
* Group: producer
*
* @param trustAllCertificates the value to set
@@ -327,7 +327,7 @@ public interface Transcribe2EndpointBuilderFactory {
*
* The option will be converted to a <code>boolean</code> type.
*
- * Default: true
+ * Default: false
* Group: producer
*
* @param trustAllCertificates the value to set