Thomas Raddatz created CAMEL-25168:
--------------------------------------
Summary: camel-openapi-validator: a repeated request header is
validated as the text of a Java collection
Key: CAMEL-25168
URL: https://issues.apache.org/jira/browse/CAMEL-25168
Project: Camel
Issue Type: Bug
Components: camel-core
Affects Versions: 4.22.1
Reporter: Thomas Raddatz
The rest client request validator ({{OpenApiRestClientRequestValidator}})
builds the {{SimpleRequest}} for swagger-request-validator with
{code:java}
builder.withHeader(key, exchange.getMessage().getHeader(key, String.class));
{code}
A header that occurs more than once arrives on the message as a {{Collection}}
({{CollectionHelper.appendEntry}}). Converting it to {{String}} falls back to
{{ToStringTypeConverter}}, so the validator checks the value {{[a, b]}}, which
the client never sent.
h3. Consequences
* A header declared as a single value (e.g. {{"type": "string"}}) that is
repeated is never reported, because {{[a, b]}} is still a string.
* {{pattern}}, {{enum}}, {{format}} and {{maxLength}}, and the item type of an
array header, are checked against the wrong value, so a valid request can be
rejected or an invalid one accepted.
* A repeated array header is rejected, although per [RFC 9110 section
5.3|https://www.rfc-editor.org/rfc/rfc9110#section-5.3] it is equivalent to one
header with the values joined by commas.
Query parameters in the same method are already passed once per occurrence, so
the equivalent repeated query parameter is validated correctly.
h3. Reproduce
With the petstore contract of the module ({{DELETE /pet/\{petId\}}}, header
{{api_key}} {{"type": "string"}}):
{code:java}
exchange.getMessage().setHeader(Exchange.HTTP_METHOD, "DELETE");
exchange.getMessage().setHeader(Exchange.HTTP_PATH, "pet/123");
exchange.getMessage().setHeader("api_key", List.of("key-one", "key-two"));
{code}
*Expected:* a validation error.
*Actual:* no error.
h3. Known limitation (outside the scope of this issue)
For OpenAPI 3.1 contracts swagger-request-validator 2.46.1 does not recognise
header parameters as arrays (the parser produces {{JsonSchema}}, the validator
checks for {{ArraySchema}}), so header arrays of a 3.1 contract do not validate
at all.
h3. Pull request
https://github.com/apache/camel/pull/27099
--
This message was sent by Atlassian Jira
(v8.20.10#820010)