[ 
https://issues.apache.org/jira/browse/CAMEL-25404?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino resolved CAMEL-25404.
--------------------------------------
    Resolution: Fixed

> camel-ai-tool - make an authorizationPolicy denial visible to onException, 
> tracing and metrics
> ----------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25404
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25404
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-ai
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> Follow-up to CAMEL-24831 (the camel-ai-tool authorizationPolicy, shipped in 
> 4.23.0).
> The policy wraps the ai-tool route's outer processor (AiToolConsumer applies 
> Policy.beforeWrap/wrap before register), so a denial throws 
> CamelAuthorizationException in *front* of the route: AiToolExecutor maps it 
> to AiToolResult.AuthorizationDenied and relays a clean refusal to the model, 
> but the deny is only logged at WARN. It does not fire the route's 
> onException, produce a tracing span, or increment any metric. This outer 
> placement was deliberate (agreed with davsclaus on #27332), with the 
> observability gap explicitly deferred to this follow-up.
> Make a denial observable without changing the model-facing behaviour (still a 
> clean AuthorizationDenied refusal): either run the guard inside the route so 
> a deny propagates through the route's UnitOfWork/error handler and tracing, 
> or emit a Camel event plus a management/micrometer counter on deny, so 
> operators can see and alert on authorization denials.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to