[
https://issues.apache.org/jira/browse/CAMEL-24737?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Work on CAMEL-24737 started by Andrea Cosentino.
------------------------------------------------
> camel-opa - allowKey cannot read a verdict nested inside the decision document
> ------------------------------------------------------------------------------
>
> Key: CAMEL-24737
> URL: https://issues.apache.org/jira/browse/CAMEL-24737
> Project: Camel
> Issue Type: Improvement
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Minor
>
> h2. Problem
> {{OpaPolicyEvaluator.isAllowed}} reads the verdict from a single top-level
> key:
> {code:java}
> if (decision instanceof Map<?, ?> map && map.get(allowKey) instanceof Boolean
> b) {
> return b;
> }
> {code}
> So a decision document shaped {{\{"result": \{"allow": true\}\}}} - a common
> shape when a policy returns a structured result, or when querying a package
> rather than a specific rule head - cannot be read. The component then treats
> it as "no boolean verdict" and denies.
> Failing closed is the right default, but the failure is indistinguishable
> from a genuine policy denial: the route sees {{CamelOpaDecisionAllow=false}}
> exactly as it would for a real deny, so a configuration mistake looks like an
> authorization decision. The raw document is on {{CamelOpaDecision}}, but
> nothing points the operator at it.
> h2. Proposal
> Support a dotted path in {{allowKey}}, e.g. {{allowKey=result.allow}},
> walking nested maps. A plain name keeps working unchanged.
> Separately, and cheaper: log at WARN rather than DEBUG when a decision
> document is returned but no verdict can be read, since that is a
> configuration error rather than a routine deny.
> h2. Scope
> {{main}} only. Backwards compatible - a key with no dot behaves as today.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)