[ 
https://issues.apache.org/jira/browse/CAMEL-25026?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18119145#comment-18119145
 ] 

Andrea Cosentino commented on CAMEL-25026:
------------------------------------------

PR opened: https://github.com/apache/camel/pull/26900

Root cause: {{SchemaGeneratorMojo.createOption}} never copied the {{security}}, 
{{secret}} and {{insecureValue}} attributes off {{@Metadata}}, so they were 
dropped for every model, dataformat and language option. Component options were 
unaffected because {{EndpointSchemaGeneratorMojo}} resolves them on its own 
code path. {{PackageDataFormatMojo}} had a second, narrower instance of the 
same bug: it copied {{isSecret()}} but not the other two when folding a model 
option into the dataformat JSON.

The failure is silent, which is the real problem - an option declaring 
{{security = "insecure:ssl"}} simply never reaches the generated 
{{SecurityUtils}}/{{SensitiveUtils}} tables, so it gets no prod-profile 
enforcement, no security-scan coverage and no value masking, with nothing in 
the build to signal it.

Only two data formats are affected in practice: {{xmlSecurity}} 
({{passPhrase}}, {{passPhraseByte}}, {{keyPassword}} are now secret) and 
{{avro}} ({{serializablePackages}} is now {{insecure:serialization}}). No 
option changed its default or meaning. Runtime behaviour is almost unchanged 
because those bare names already reached the tables via components declaring 
options with the same name; the two genuinely new effects are that 
{{passPhraseByte}} is now masked when Camel sanitizes values, and that the YAML 
DSL schema marks {{passPhrase}}/{{keyPassword}} with {{"format": "password"}}. 
Both are noted in the 4.23.0 upgrade guide.

_Comment by Claude Code on behalf of Andrea Cosentino._

> camel-package-maven-plugin - @Metadata(security/secret) is dropped for model, 
> dataformat and language options
> -------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25026
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25026
>             Project: Camel
>          Issue Type: Bug
>          Components: tooling
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>
> CAMEL-23250 introduced the {{security}} attribute on {{@Metadata}} and wired 
> it through the *component* JSON pipeline. The model/dataformat/language 
> pipeline was never wired up, so {{@Metadata(security = ...)}} and 
> {{@Metadata(secret = true)}} are silently dropped for every option that is 
> not a component option.
> h3. Root cause
> {{SchemaGeneratorMojo.createOption(...)}} is the single factory for every 
> model, dataformat and language option. It sets name, type, label, default 
> value, deprecation and enums, but never calls {{setSecurity}}, {{setSecret}} 
> or {{setInsecureValue}}. The only {{setSecurity}} call in that class is on 
> the separate {{exchangeProperty}} branch.
> h3. Evidence
> || source annotation || generated catalog ||
> | {{AvroDataFormat.serializablePackages}} -> {{security = 
> "insecure:serialization"}} | {{dataformats/avro.json}}: no {{security}} |
> | {{XMLSecurityDataFormat.passPhrase}} -> {{security = "secret"}} | 
> {{dataformats/xmlSecurity.json}}: {{secret: false}}, no {{security}} |
> | {{XMLSecurityDataFormat.passPhraseByte}}, {{.keyPassword}} -> {{security = 
> "secret"}} | same |
> Catalog-wide: 1370 component options carry {{security}} and *0* of the 2562 
> options under {{dataformats/}}, {{languages/}}, {{models/}} and 
> {{models-app/}} do. Same for {{secret: true}} - 1165 in components, 0 
> elsewhere.
> h3. Consequences
> * The dataformat and language branches of the {{SECURITY_OPTIONS}} generator 
> ({{UpdateSensitizeHelper}}) are dead code: they iterate those models and call 
> {{collectSecurityOption}}, but the input can never carry a marker.
> * {{PackageLanguageMojo}} already copies {{secret}}, {{security}} and 
> {{insecureValue}} from the model option, which shows the propagation is 
> intended - it is simply inert because the upstream value is never set. 
> {{PackageDataFormatMojo}} copies {{secret}} but not 
> {{security}}/{{insecureValue}}, a second and narrower gap.
> * The generated docs are wrong: {{xmlSecurity}}'s {{passPhrase}} renders in 
> the dataformat options table as an ordinary non-secret string option.
> h3. Impact
> No known runtime impact today. All four affected option names are covered by 
> coincidence, because the {{SecurityUtils}}/{{SensitiveUtils}} maps are keyed 
> by bare option name: {{serializablepackages}} reaches {{SECURITY_OPTIONS}} 
> via the avro *component*, and {{passphrase}}/{{keypassword}} are already in 
> the sensitive-keys list via other components.
> The defect is that the failure is silent. The next {{@Metadata(security = 
> ...)}} added to a dataformat or language model whose name is not already 
> covered elsewhere gets no prod-profile enforcement, no camel-jbang scanner 
> coverage and no value masking, with no build error and no visible signal.
> This was found while auditing security-marker consistency across the catalog, 
> not from a user report.
> _Filed by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to