[
https://issues.apache.org/jira/browse/CAMEL-24509?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Work on CAMEL-24509 started by Andrea Cosentino.
------------------------------------------------
> camel-mina - an inbound DefaultExchangeHolder is unmarshalled without
> checking transferExchange
> -----------------------------------------------------------------------------------------------
>
> Key: CAMEL-24509
> URL: https://issues.apache.org/jira/browse/CAMEL-24509
> Project: Camel
> Issue Type: Bug
> Components: camel-mina
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> {{MinaPayloadHelper.setIn()}} and {{setOut()}} unmarshal an inbound
> {{DefaultExchangeHolder}} unconditionally:
> {code:java}
> public static void setIn(Exchange exchange, Object payload) {
> if (payload instanceof DefaultExchangeHolder) {
> DefaultExchangeHolder.unmarshal(exchange, (DefaultExchangeHolder)
> payload);
> } else {
> // normal transfer using the body only
> exchange.getIn().setBody(payload);
> }
> }
> {code}
> There is no check that the endpoint actually enabled {{transferExchange}}.
> Whenever the decoded object happens to be a {{DefaultExchangeHolder}}, the
> whole Exchange is rebuilt from it: {{DefaultExchangeHolder.unmarshal()}} sets
> the exchange id, the in body, the in headers (via {{setHeaders}}, which
> replaces the map wholesale - including the {{MINA_*}} headers the consumer
> set moments earlier), the out body and headers, and every exchange property.
> The equivalent path in camel-jms is gated. {{JmsBinding}} checks
> {{isObjectMessageEnabled()}} and calls {{checkDeserializedClass(payload)}}
> before it will unmarshal a holder:
> {code:java}
> if (message instanceof ObjectMessage objectMessage) {
> if (!isObjectMessageEnabled()) {
> throw objectMessageDisabled("receiving ObjectMessage");
> }
> Object payload = objectMessage.getObject();
> checkDeserializedClass(payload);
> if (payload instanceof DefaultExchangeHolder holder) {
> DefaultExchangeHolder.unmarshal(exchange, holder);
> {code}
> camel-mina has neither gate, and the exposure is wider than in camel-jms
> because object decoding is the default rather than an opt-in:
> {{MinaConfiguration.textline}} defaults to {{false}}, so {{MinaConsumer}}
> installs {{ObjectSerializationCodecFactory}}. The {{objectCodecPattern}}
> allow-list does not help here, since {{DefaultExchangeHolder}} lives in the
> {{org.apache.camel}} namespace that any reasonable allow-list permits.
> Proposal: gate the holder unmarshal on the endpoint's {{transferExchange}}
> setting, so a decoded holder is treated as an ordinary body unless the
> endpoint asked for exchange transfer. That matches the camel-jms behaviour
> and leaves the documented {{transferExchange=true}} deployments working.
> Present on {{main}}, {{camel-4.22.x}} and {{camel-4.18.x}} - identical code
> on all three ({{MinaPayloadHelper}} lines 56 and 65, {{textline}} default at
> {{MinaConfiguration}} line 50).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)