[ 
https://issues.apache.org/jira/browse/CAMEL-25168?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Thomas Raddatz updated CAMEL-25168:
-----------------------------------
    Description: 
The rest client request validator ({{OpenApiRestClientRequestValidator}}) 
builds the {{SimpleRequest}} for swagger-request-validator with

{code:java}
builder.withHeader(key, exchange.getMessage().getHeader(key, String.class));
{code}

A header that occurs more than once arrives on the message as a {{Collection}} 
({{CollectionHelper.appendEntry}}). Converting it to {{String}} falls back to 
{{ToStringTypeConverter}}, so the validator checks the value {{[a, b]}}, which 
the client never sent.

h3. Consequences

* A header declared as a single value (e.g. {{"type": "string"}}) that is 
repeated is never reported, because {{[a, b]}} is still a string.
* {{pattern}}, {{enum}}, {{format}} and {{maxLength}}, and the item type of an 
array header, are checked against the wrong value, so a valid request can be 
rejected or an invalid one accepted.
* A repeated array header is checked as the text {{[a, b]}}, split at the comma 
into {{[a}} and {{ b]}}. With typed items such as {{integer}} it is rejected, 
although per [RFC 9110 section 
5.3|https://www.rfc-editor.org/rfc/rfc9110#section-5.3] it is equivalent to one 
header with the values joined by commas. With string items it passes only by 
accident.

Query parameters in the same method are already passed once per occurrence, so 
the equivalent repeated query parameter is validated correctly.

h3. Reproduce

With the petstore contract of the module ({{DELETE /pet/\{petId\}}}, header 
{{api_key}} {{"type": "string"}}):

{code:java}
exchange.getMessage().setHeader(Exchange.HTTP_METHOD, "DELETE");
exchange.getMessage().setHeader(Exchange.HTTP_PATH, "pet/123");
exchange.getMessage().setHeader("api_key", List.of("key-one", "key-two"));
{code}

*Expected:* a validation error.
*Actual:* no error.

h3. Known limitation (outside the scope of this issue)

For OpenAPI 3.1 contracts swagger-request-validator 2.46.1 does not recognise 
header parameters as arrays (the parser produces {{JsonSchema}}, the validator 
checks for {{ArraySchema}}), so header arrays of a 3.1 contract do not validate 
at all.

h3. Pull request

https://github.com/apache/camel/pull/27099

  was:
The rest client request validator ({{OpenApiRestClientRequestValidator}}) 
builds the {{SimpleRequest}} for swagger-request-validator with

{code:java}
builder.withHeader(key, exchange.getMessage().getHeader(key, String.class));
{code}

A header that occurs more than once arrives on the message as a {{Collection}} 
({{CollectionHelper.appendEntry}}). Converting it to {{String}} falls back to 
{{ToStringTypeConverter}}, so the validator checks the value {{[a, b]}}, which 
the client never sent.

h3. Consequences

* A header declared as a single value (e.g. {{"type": "string"}}) that is 
repeated is never reported, because {{[a, b]}} is still a string.
* {{pattern}}, {{enum}}, {{format}} and {{maxLength}}, and the item type of an 
array header, are checked against the wrong value, so a valid request can be 
rejected or an invalid one accepted.
* A repeated array header is rejected, although per [RFC 9110 section 
5.3|https://www.rfc-editor.org/rfc/rfc9110#section-5.3] it is equivalent to one 
header with the values joined by commas.

Query parameters in the same method are already passed once per occurrence, so 
the equivalent repeated query parameter is validated correctly.

h3. Reproduce

With the petstore contract of the module ({{DELETE /pet/\{petId\}}}, header 
{{api_key}} {{"type": "string"}}):

{code:java}
exchange.getMessage().setHeader(Exchange.HTTP_METHOD, "DELETE");
exchange.getMessage().setHeader(Exchange.HTTP_PATH, "pet/123");
exchange.getMessage().setHeader("api_key", List.of("key-one", "key-two"));
{code}

*Expected:* a validation error.
*Actual:* no error.

h3. Known limitation (outside the scope of this issue)

For OpenAPI 3.1 contracts swagger-request-validator 2.46.1 does not recognise 
header parameters as arrays (the parser produces {{JsonSchema}}, the validator 
checks for {{ArraySchema}}), so header arrays of a 3.1 contract do not validate 
at all.

h3. Pull request

https://github.com/apache/camel/pull/27099


> camel-openapi-validator: a repeated request header is validated as the text 
> of a Java collection
> ------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25168
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25168
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-openapi-validator
>    Affects Versions: 4.22.1
>            Reporter: Thomas Raddatz
>            Priority: Minor
>
> The rest client request validator ({{OpenApiRestClientRequestValidator}}) 
> builds the {{SimpleRequest}} for swagger-request-validator with
> {code:java}
> builder.withHeader(key, exchange.getMessage().getHeader(key, String.class));
> {code}
> A header that occurs more than once arrives on the message as a 
> {{Collection}} ({{CollectionHelper.appendEntry}}). Converting it to 
> {{String}} falls back to {{ToStringTypeConverter}}, so the validator checks 
> the value {{[a, b]}}, which the client never sent.
> h3. Consequences
> * A header declared as a single value (e.g. {{"type": "string"}}) that is 
> repeated is never reported, because {{[a, b]}} is still a string.
> * {{pattern}}, {{enum}}, {{format}} and {{maxLength}}, and the item type of 
> an array header, are checked against the wrong value, so a valid request can 
> be rejected or an invalid one accepted.
> * A repeated array header is checked as the text {{[a, b]}}, split at the 
> comma into {{[a}} and {{ b]}}. With typed items such as {{integer}} it is 
> rejected, although per [RFC 9110 section 
> 5.3|https://www.rfc-editor.org/rfc/rfc9110#section-5.3] it is equivalent to 
> one header with the values joined by commas. With string items it passes only 
> by accident.
> Query parameters in the same method are already passed once per occurrence, 
> so the equivalent repeated query parameter is validated correctly.
> h3. Reproduce
> With the petstore contract of the module ({{DELETE /pet/\{petId\}}}, header 
> {{api_key}} {{"type": "string"}}):
> {code:java}
> exchange.getMessage().setHeader(Exchange.HTTP_METHOD, "DELETE");
> exchange.getMessage().setHeader(Exchange.HTTP_PATH, "pet/123");
> exchange.getMessage().setHeader("api_key", List.of("key-one", "key-two"));
> {code}
> *Expected:* a validation error.
> *Actual:* no error.
> h3. Known limitation (outside the scope of this issue)
> For OpenAPI 3.1 contracts swagger-request-validator 2.46.1 does not recognise 
> header parameters as arrays (the parser produces {{JsonSchema}}, the 
> validator checks for {{ArraySchema}}), so header arrays of a 3.1 contract do 
> not validate at all.
> h3. Pull request
> https://github.com/apache/camel/pull/27099



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to