Thomas Raddatz created CAMEL-25168:
--------------------------------------

             Summary: camel-openapi-validator: a repeated request header is 
validated as the text of a Java collection
                 Key: CAMEL-25168
                 URL: https://issues.apache.org/jira/browse/CAMEL-25168
             Project: Camel
          Issue Type: Bug
          Components: camel-core
    Affects Versions: 4.22.1
            Reporter: Thomas Raddatz


The rest client request validator ({{OpenApiRestClientRequestValidator}}) 
builds the {{SimpleRequest}} for swagger-request-validator with

{code:java}
builder.withHeader(key, exchange.getMessage().getHeader(key, String.class));
{code}

A header that occurs more than once arrives on the message as a {{Collection}} 
({{CollectionHelper.appendEntry}}). Converting it to {{String}} falls back to 
{{ToStringTypeConverter}}, so the validator checks the value {{[a, b]}}, which 
the client never sent.

h3. Consequences

* A header declared as a single value (e.g. {{"type": "string"}}) that is 
repeated is never reported, because {{[a, b]}} is still a string.
* {{pattern}}, {{enum}}, {{format}} and {{maxLength}}, and the item type of an 
array header, are checked against the wrong value, so a valid request can be 
rejected or an invalid one accepted.
* A repeated array header is rejected, although per [RFC 9110 section 
5.3|https://www.rfc-editor.org/rfc/rfc9110#section-5.3] it is equivalent to one 
header with the values joined by commas.

Query parameters in the same method are already passed once per occurrence, so 
the equivalent repeated query parameter is validated correctly.

h3. Reproduce

With the petstore contract of the module ({{DELETE /pet/\{petId\}}}, header 
{{api_key}} {{"type": "string"}}):

{code:java}
exchange.getMessage().setHeader(Exchange.HTTP_METHOD, "DELETE");
exchange.getMessage().setHeader(Exchange.HTTP_PATH, "pet/123");
exchange.getMessage().setHeader("api_key", List.of("key-one", "key-two"));
{code}

*Expected:* a validation error.
*Actual:* no error.

h3. Known limitation (outside the scope of this issue)

For OpenAPI 3.1 contracts swagger-request-validator 2.46.1 does not recognise 
header parameters as arrays (the parser produces {{JsonSchema}}, the validator 
checks for {{ArraySchema}}), so header arrays of a 3.1 contract do not validate 
at all.

h3. Pull request

https://github.com/apache/camel/pull/27099



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to