[ 
https://issues.apache.org/jira/browse/CAMEL-25414?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino reassigned CAMEL-25414:
----------------------------------------

    Assignee: Andrea Cosentino

> camel-debezium-mongodb - mongodbSslInvalidHostnameAllowed is not marked 
> insecure:ssl
> ------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25414
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25414
>             Project: Camel
>          Issue Type: Bug
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> Follow-up to CAMEL-25409.
> The Debezium MongoDB connector option mongodbSslInvalidHostnameAllowed turns 
> off TLS hostname verification, but the generated 
> MongoDbConnectorEmbeddedDebeziumConfiguration declares it as a plain 
> @UriParam, without security = "insecure:ssl". The security option map in 
> SecurityUtils is populated from the catalog, so nothing named 
> mongodbSslInvalidHostnameAllowed is known to it and camel.main.profile=prod 
> does not refuse it. camel-mongodb's equivalent option 
> (tlsAllowInvalidHostnames) was fixed in CAMEL-25409; this one was left out 
> because it cannot be fixed by editing the source.
> The configuration classes under camel-debezium-*/src/generated are produced 
> by camel-debezium-maven-plugin (ConnectorConfigGenerator), which currently 
> emits only two security-related attributes: secret = true when the Debezium 
> connector declares the field as a password, and nothing at all for insecure 
> flags. Fixing this means teaching the generator which option names are 
> security sensitive - the natural place is next to the existing isSecret() 
> branch in ConnectorConfigGenerator - and then regenerating the connector 
> configurations.
> Worth doing in the same change:
> * the generator still emits the legacy secret = true form; the rest of the 
> codebase moved to security = "secret" in CAMEL-23250, so the generated 
> classes are the last users of the old attribute
> * the mapping should be driven by a small explicit list of Debezium option 
> names rather than a name heuristic, so that a new connector option cannot 
> silently inherit a security category it does not deserve
> Scope check before starting: regenerating touches every connector (db2, 
> mongodb, mysql, oracle, postgres, sqlserver), so the diff should be inspected 
> to confirm that only the intended attributes change.
> _Reported by Claude Code on behalf of @oscerd_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to