[ 
https://issues.apache.org/jira/browse/CAMEL-24507?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino updated CAMEL-24507:
-------------------------------------
    Fix Version/s: 4.23.0

> camel-mcp-server-starter - documentation attributes authentication to a 
> property namespace that does not provide it
> -------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24507
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24507
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-mcp-server, camel-spring-boot-starters
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>             Fix For: 4.23.0
>
>
> The starter's configuration class and its intro documentation both say:
> {code:java}
> /**
>  * Bridge-owned configuration of the Camel MCP server. Serving concerns 
> (endpoint path, protocol, server identity,
>  * authentication) are owned by the Spring AI MCP server and configured via 
> {@code spring.ai.mcp.server.*}.
>  */
> {code}
> (McpServerConfigurationProperties:32, and src/main/doc/intro.adoc:12)
> {{spring.ai.mcp.server.*}} configures endpoint path, protocol and server 
> identity, but it has no authentication property. A reader following this 
> sentence would look for an authentication knob in that namespace, not find 
> one, and may conclude the endpoint is covered when it is not.
> The default posture itself is reasonable: {{tags}} defaults to null and, as 
> the property javadoc says, "the untagged default pool is never exposed", so 
> no tools are served until an operator opts in by setting 
> {{camel.mcp-server.tags}}. The issue is the documentation, not the default.
> CAMEL-24314 added a security section to the upstream camel-mcp-server 
> component page covering the trust boundary and authentication wiring via 
> platform-http authentication / camel-oauth. This starter's own docs should 
> agree with it.
> *Proposal*
> - Correct the sentence in {{McpServerConfigurationProperties}} and 
> {{intro.adoc}}/{{usage.adoc}}: state that {{spring.ai.mcp.server.*}} provides 
> no authentication and that the endpoint must be protected by the application.
> - Add a short "Securing the MCP endpoint" section with a Spring Security 
> {{SecurityFilterChain}} example matching the MCP endpoint path, pointing at 
> CAMEL-24314's section for the general model.
> - Optionally log at startup when {{tags}} is set - i.e. when tools are 
> actually exposed - so the opt-in is visible in the log.
> ----
> _This issue was drafted by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to