Andrea Cosentino created CAMEL-25414:
----------------------------------------

             Summary: camel-debezium-mongodb - mongodbSslInvalidHostnameAllowed 
is not marked insecure:ssl
                 Key: CAMEL-25414
                 URL: https://issues.apache.org/jira/browse/CAMEL-25414
             Project: Camel
          Issue Type: Bug
            Reporter: Andrea Cosentino


Follow-up to CAMEL-25409.

The Debezium MongoDB connector option mongodbSslInvalidHostnameAllowed turns 
off TLS hostname verification, but the generated 
MongoDbConnectorEmbeddedDebeziumConfiguration declares it as a plain @UriParam, 
without security = "insecure:ssl". The security option map in SecurityUtils is 
populated from the catalog, so nothing named mongodbSslInvalidHostnameAllowed 
is known to it and camel.main.profile=prod does not refuse it. camel-mongodb's 
equivalent option (tlsAllowInvalidHostnames) was fixed in CAMEL-25409; this one 
was left out because it cannot be fixed by editing the source.

The configuration classes under camel-debezium-*/src/generated are produced by 
camel-debezium-maven-plugin (ConnectorConfigGenerator), which currently emits 
only two security-related attributes: secret = true when the Debezium connector 
declares the field as a password, and nothing at all for insecure flags. Fixing 
this means teaching the generator which option names are security sensitive - 
the natural place is next to the existing isSecret() branch in 
ConnectorConfigGenerator - and then regenerating the connector configurations.

Worth doing in the same change:

* the generator still emits the legacy secret = true form; the rest of the 
codebase moved to security = "secret" in CAMEL-23250, so the generated classes 
are the last users of the old attribute
* the mapping should be driven by a small explicit list of Debezium option 
names rather than a name heuristic, so that a new connector option cannot 
silently inherit a security category it does not deserve

Scope check before starting: regenerating touches every connector (db2, 
mongodb, mysql, oracle, postgres, sqlserver), so the diff should be inspected 
to confirm that only the intended attributes change.

_Reported by Claude Code on behalf of @oscerd_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to