[
https://issues.apache.org/jira/browse/CAMEL-24716?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Guillaume Nodet reassigned CAMEL-24716:
---------------------------------------
Assignee: Guillaume Nodet
> camel-xmlsecurity - the cipher algorithm values listed by the model are
> rejected by the data format
> ---------------------------------------------------------------------------------------------------
>
> Key: CAMEL-24716
> URL: https://issues.apache.org/jira/browse/CAMEL-24716
> Project: Camel
> Issue Type: Bug
> Components: camel-xmlsecurity
> Affects Versions: 4.18.3, 4.22.0
> Reporter: Karol Krawczyk
> Assignee: Guillaume Nodet
> Priority: Major
>
> The xmlSecurity data format model lists the cipher algorithms as enums of
> XMLCipher constant names:
> * {{xmlCipherAlgorithm}}: {{TRIPLEDES, AES_128, AES_128_GCM, AES_192,
> AES_192_GCM, AES_256, AES_256_GCM, SEED_128, CAMELLIA_128, CAMELLIA_192,
> CAMELLIA_256}}, default {{AES-256-GCM}}
> * {{keyCipherAlgorithm}}: {{RSA_v1dot5, RSA_OAEP, RSA_OAEP_11}}, default
> {{RSA_OAEP}}
> These enums end up in the YAML DSL schema, the catalog and the generated
> option tables. The data format does not map them:
> {{XMLSecurityDataFormatReifier}} passes the value unchanged, and
> {{XMLSecurityDataFormat}} hands it to {{XMLCipher.getInstance(...)}}, which
> only knows the algorithm URIs:
> {noformat}
> XMLCipher.getInstance("AES_128") ->
> XMLEncryptionException: Null or empty transformation
> XMLCipher.getInstance("http://www.w3.org/2001/04/xmlenc#aes128-cbc") -> ok
> XMLCipher.getInstance("RSA_v1dot5") ->
> XMLEncryptionException: Null or empty transformation
> XMLCipher.getInstance("http://www.w3.org/2001/04/xmlenc#rsa-1_5") -> ok
> {noformat}
> (xmlsec 4.0.4)
> {{marshal}} also compares {{keyCipherAlgorithm}} with the {{XMLCipher.RSA_*}}
> URIs to choose asymmetric encryption, so {{RSA_OAEP}} written as the enum
> says is not recognised there either. The default {{AES-256-GCM}} is neither
> an enum value nor a URI; the real default is {{XMLCipher.AES_256_GCM}}.
> So a YAML route that follows the schema fails at runtime, and a route that
> works at runtime (the URIs, as in the Spring XML tests of camel-xmlsecurity
> and in the examples of the xmlSecurity page) fails the YAML validator.
> CAMEL-24710 skips the xmlSecurity page in the documentation examples test for
> this reason.
> Proposed fix: let the data format accept the constant names as well as the
> URIs (map {{AES_128}} to {{XMLCipher.AES_128}} and so on, and pass a URI
> through unchanged, so existing routes keep working), set the metadata
> defaults to {{AES_256_GCM}} and {{RSA_OAEP}}, write the documentation
> examples with the names, and drop the xmlSecurity skip from the test. The
> alternative, listing the URIs as the enum values, keeps the runtime as it is
> but makes the options hard to read in the forms and the option tables.
> _Reported by Claude Code on behalf of Karol Krawczyk_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)