[ 
https://issues.apache.org/jira/browse/CAMEL-24509?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on CAMEL-24509 started by Andrea Cosentino.
------------------------------------------------
> camel-mina - an inbound DefaultExchangeHolder is unmarshalled without 
> checking transferExchange
> -----------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24509
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24509
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-mina
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> {{MinaPayloadHelper.setIn()}} and {{setOut()}} unmarshal an inbound 
> {{DefaultExchangeHolder}} unconditionally:
> {code:java}
> public static void setIn(Exchange exchange, Object payload) {
>     if (payload instanceof DefaultExchangeHolder) {
>         DefaultExchangeHolder.unmarshal(exchange, (DefaultExchangeHolder) 
> payload);
>     } else {
>         // normal transfer using the body only
>         exchange.getIn().setBody(payload);
>     }
> }
> {code}
> There is no check that the endpoint actually enabled {{transferExchange}}. 
> Whenever the decoded object happens to be a {{DefaultExchangeHolder}}, the 
> whole Exchange is rebuilt from it: {{DefaultExchangeHolder.unmarshal()}} sets 
> the exchange id, the in body, the in headers (via {{setHeaders}}, which 
> replaces the map wholesale - including the {{MINA_*}} headers the consumer 
> set moments earlier), the out body and headers, and every exchange property.
> The equivalent path in camel-jms is gated. {{JmsBinding}} checks 
> {{isObjectMessageEnabled()}} and calls {{checkDeserializedClass(payload)}} 
> before it will unmarshal a holder:
> {code:java}
> if (message instanceof ObjectMessage objectMessage) {
>     if (!isObjectMessageEnabled()) {
>         throw objectMessageDisabled("receiving ObjectMessage");
>     }
>     Object payload = objectMessage.getObject();
>     checkDeserializedClass(payload);
>     if (payload instanceof DefaultExchangeHolder holder) {
>         DefaultExchangeHolder.unmarshal(exchange, holder);
> {code}
> camel-mina has neither gate, and the exposure is wider than in camel-jms 
> because object decoding is the default rather than an opt-in: 
> {{MinaConfiguration.textline}} defaults to {{false}}, so {{MinaConsumer}} 
> installs {{ObjectSerializationCodecFactory}}. The {{objectCodecPattern}} 
> allow-list does not help here, since {{DefaultExchangeHolder}} lives in the 
> {{org.apache.camel}} namespace that any reasonable allow-list permits.
> Proposal: gate the holder unmarshal on the endpoint's {{transferExchange}} 
> setting, so a decoded holder is treated as an ordinary body unless the 
> endpoint asked for exchange transfer. That matches the camel-jms behaviour 
> and leaves the documented {{transferExchange=true}} deployments working.
> Present on {{main}}, {{camel-4.22.x}} and {{camel-4.18.x}} - identical code 
> on all three ({{MinaPayloadHelper}} lines 56 and 65, {{textline}} default at 
> {{MinaConfiguration}} line 50).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to