[ 
https://issues.apache.org/jira/browse/CAMEL-24504?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino updated CAMEL-24504:
-------------------------------------
    Fix Version/s: 4.23.0

> camel-spring-boot - extend the SpringTypeConverter String guard beyond 
> InputStream targets
> ------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24504
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24504
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-spring-boot
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>             Fix For: 4.23.0
>
>
> CAMEL-23378 added a guard to {{SpringTypeConverter.convertTo()}}:
> {code:java}
> // do not attempt to convert String -> InputStream (or subclasses like 
> FileInputStream).
> // Spring's ObjectToObjectConverter finds FileInputStream(String) constructor 
> and treats
> // the String value as a file path instead of data content.
> if (value instanceof String && InputStream.class.isAssignableFrom(type)) {
>     return null;
> }
> {code}
> (SpringTypeConverter:59)
> The reasoning applies to more than {{InputStream}}. Spring's 
> {{ObjectToObjectConverter}} will find any single-String constructor, so the 
> same "treated as a file path rather than content" behaviour is reachable for 
> {{FileReader}}, {{FileWriter}}, {{ZipFile}} and {{File}} targets, none of 
> which the current guard covers.
> *Proposal*
> Either extend the guard to cover targets assignable to {{Reader}}, 
> {{Writer}}, {{ZipFile}} and {{File}}, or - better, and in keeping with the 
> comment's reasoning - invert it into an allowlist of target types that are 
> safe to build from a String, so future JDK or Spring additions do not reopen 
> the same shape.
> Tests should cover at least the {{Reader}} and {{ZipFile}} cases alongside 
> the existing {{InputStream}} one.
> ----
> _This issue was drafted by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to