[ 
https://issues.apache.org/jira/browse/CAMEL-25375?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123810#comment-18123810
 ] 

Andrea Cosentino commented on CAMEL-25375:
------------------------------------------

Merged to main via https://github.com/apache/camel/pull/27435 (squash commit 
3a75bfbf1b20, ships in 4.23.0). The camel-4.22.x and camel-4.18.x backports are 
still to come, so the issue stays open until they are merged.

_Claude Code on behalf of oscerd_

> camel-undertow - Apply securityProvider, allowedRoles and handlers to 
> WebSocket endpoints consistently with HTTP endpoints
> --------------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25375
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25375
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-undertow
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.18.5, 4.22.2, 4.23.0
>
>
> The undertow component applies the {{UndertowSecurityProvider}} (configured 
> with {{securityConfiguration}} or {{securityProvider}}), the {{allowedRoles}} 
> option and the {{handlers}} option in the HTTP request path: 
> {{UndertowConsumer.handleRequest()}} and the handler chain built in 
> {{UndertowConsumer.doStart()}}.
> WebSocket endpoints ({{ws://}}, {{wss://}}) are served by 
> {{CamelWebSocketHandler}} and do not go through that path, so these options 
> are not applied to them. On HTTP endpoints the same configuration is applied, 
> including the 403 returned when {{allowedRoles}} is set without a provider 
> (CAMEL-14987).
> h3. Proposed change
> * Call the configured provider's {{authenticate()}} with the endpoint's 
> allowed roles on the WebSocket upgrade request in {{CamelWebSocketHandler}}, 
> and return the same 403 as the HTTP path when {{allowedRoles}} is set without 
> a provider.
> * Take the settings from the endpoints registered on the WebSocket path, 
> producers included, not only from the consumer.
> * Record the result on the WebSocket channel, as is already done for 
> {{oauthProfile}} (CAMEL-23723), so every channel is handled consistently, 
> including channels opened while the consumer is stopped or restarting, for 
> both inbound events and outbound sends.
> * Apply the {{handlers}} option (and the access log) to WebSocket consumers.
> * Make providers that override {{wrapHttpHandler()}} work with WebSocket 
> endpoints; today the WebSocket route fails to start with a 
> {{ClassCastException}}.
> * Propagate the provider's {{addHeader()}} values to WebSocket exchanges, as 
> for HTTP.
> * Tests, an update to the "Security provider" section of 
> {{undertow-component.adoc}}, and upgrade-guide notes: WebSocket connections 
> that do not satisfy the configured provider are now rejected.
> _Claude Code on behalf of Andrea Cosentino (oscerd)_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to