[ 
https://issues.apache.org/jira/browse/CAMEL-25376?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on CAMEL-25376 started by Andrea Cosentino.
------------------------------------------------
> camel-netty-http - match security constraint roles by exact role name
> ---------------------------------------------------------------------
>
>                 Key: CAMEL-25376
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25376
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-netty-http
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.18.5, 4.22.2, 4.23.0
>
>
> Make {{HttpServerChannelHandler.matchesRoles}} treat the roles configured for 
> a {{SecurityConstraintMapping}} inclusion as the comma-separated list of role 
> names described by the {{SecurityConstraint}} contract ("a comma separated 
> String with roles") and by the component documentation ("access to /admin/* 
> requires the admin role"), and decide whether the user is in role by exact 
> role name.
> This aligns the role check with how other components handle role lists, for 
> example {{allowedRoles}} in camel-undertow and {{requiredRoles}} in 
> camel-keycloak:
> * split the configured roles on comma, trim each name and ignore blank entries
> * treat the user's roles returned by {{SecurityAuthenticator.getUserRoles}} 
> the same way
> * the user is in role only when one of their roles equals one of the 
> configured role names (case-sensitive)
> * keep {{*}} as the only wildcard value
> The {{SecurityConstraint}} SPI and the protected {{matchesRoles(String, 
> String)}} signature stay unchanged.
> Code: 
> {{components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/handlers/HttpServerChannelHandler.java}}
> Also:
> * add tests for the role matching
> * document the matching rules in the "Specifying ACL on web resources" 
> section of the netty-http documentation
> * add an upgrade-guide note for roles values that are not comma-separated
> _Claude Code on behalf of Andrea Cosentino_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to