[
https://issues.apache.org/jira/browse/CAMEL-25376?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123827#comment-18123827
]
Andrea Cosentino commented on CAMEL-25376:
------------------------------------------
Backported to camel-4.22.x via https://github.com/apache/camel/pull/27441
(squash commit 169ea05346cf, ships in 4.22.2). The camel-4.18.x backport is
still pending, so this issue stays open until it merges.
_Claude Code on behalf of oscerd_
> camel-netty-http - match security constraint roles by exact role name
> ---------------------------------------------------------------------
>
> Key: CAMEL-25376
> URL: https://issues.apache.org/jira/browse/CAMEL-25376
> Project: Camel
> Issue Type: Bug
> Components: camel-netty-http
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.18.5, 4.22.2, 4.23.0
>
>
> Make {{HttpServerChannelHandler.matchesRoles}} treat the roles configured for
> a {{SecurityConstraintMapping}} inclusion as the comma-separated list of role
> names described by the {{SecurityConstraint}} contract ("a comma separated
> String with roles") and by the component documentation ("access to /admin/*
> requires the admin role"), and decide whether the user is in role by exact
> role name.
> This aligns the role check with how other components handle role lists, for
> example {{allowedRoles}} in camel-undertow and {{requiredRoles}} in
> camel-keycloak:
> * split the configured roles on comma, trim each name and ignore blank entries
> * treat the user's roles returned by {{SecurityAuthenticator.getUserRoles}}
> the same way
> * the user is in role only when one of their roles equals one of the
> configured role names (case-sensitive)
> * keep {{*}} as the only wildcard value
> The {{SecurityConstraint}} SPI and the protected {{matchesRoles(String,
> String)}} signature stay unchanged.
> Code:
> {{components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java}}
> Also:
> * add tests for the role matching
> * document the matching rules in the "Specifying ACL on web resources"
> section of the netty-http documentation
> * add an upgrade-guide note for roles values that are not comma-separated
> _Claude Code on behalf of Andrea Cosentino_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)