[ 
https://issues.apache.org/jira/browse/CAMEL-24436?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109186#comment-18109186
 ] 

Claus Ibsen commented on CAMEL-24436:
-------------------------------------

Fixed via https://github.com/apache/camel/pull/25820 (commit 4b557e4e8204). 
Resolving to sync JIRA status with the merged fix.

_Claude Code on behalf of Claus Ibsen_

> camel-platform-http-vertx - CORS handler allows any origin and always sends 
> Access-Control-Allow-Credentials
> ------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24436
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24436
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-platform-http-vertx
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> {{VertxPlatformHttpServerSupport.createCorsHandler()}} has two problems in 
> the same block:
> {code:java}
> final boolean allowsOrigin
>         = ObjectHelper.isEmpty(corsConfig.getOrigins()) || 
> corsConfig.getOrigins().contains(origin);
> if (allowsOrigin) {
>     response.headers().set(HttpHeaders.ACCESS_CONTROL_ALLOW_ORIGIN, origin);
> }
> response.headers().set(HttpHeaders.ACCESS_CONTROL_ALLOW_CREDENTIALS, "true");
> {code}
> 1. When {{corsConfig.getOrigins()}} is empty - which is what an operator gets 
> by merely enabling CORS without listing origins - {{allowsOrigin}} is true 
> for every origin, and the request's own {{Origin}} is echoed back as 
> {{Access-Control-Allow-Origin}}.
> 2. {{Access-Control-Allow-Credentials: true}} is set unconditionally, outside 
> the {{allowsOrigin}} check, so it is emitted even for an origin that was not 
> allowed.
> The requested methods and headers are likewise echoed back when the 
> corresponding config lists are unset. The handler is installed on the 
> sub-router covering every consumer endpoint, and the same config object 
> serves both the main and the management server.
> Proposal:
> * Only send {{Access-Control-Allow-Credentials}} when the origin was actually 
> allowed, and make it configurable (it is currently not an option at all) 
> rather than hardcoded true.
> * Decide explicitly what an empty origin list should mean. Echoing the 
> caller's origin is not the same as {{*}} and should not be the accidental 
> result of leaving the list unset - either default to no origins allowed, or 
> require the operator to opt in to the permissive behaviour with an explicit 
> wildcard entry.
> Either change needs an upgrade-guide entry.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to