Andrea Cosentino created CAMEL-25459:
----------------------------------------
Summary: camel-thrift - consumer: fail at startup when
negotiationType cannot be applied
Key: CAMEL-25459
URL: https://issues.apache.org/jira/browse/CAMEL-25459
Project: Camel
Issue Type: Bug
Reporter: Andrea Cosentino
Assignee: Andrea Cosentino
Fix For: 4.24.0, 4.18.6, 4.22.3
{{ThriftProducer}} refuses to start when {{negotiationType=SSL}} is used
without {{synchronous=true}} ("The SSL negotiation type requires to set
syncronous communication mode"). {{ThriftConsumer}} has no equivalent check.
{{initializeServer()}} builds the TLS server only for {{negotiationType == SSL
&& synchronous}}:
{code:java}
if (configuration.getNegotiationType() == ThriftNegotiationType.SSL &&
endpoint.isSynchronous()) {
{code}
With the default {{synchronous=false}} the consumer falls through to the
{{TNonblockingServerSocket}} / {{ThriftHsHaServer}} branch, which does not use
{{sslParameters}}. Nothing is logged about it, and the component page does not
say that SSL requires {{synchronous=true}}. {{ThriftConsumerSecurityTest}} only
covers {{synchronous=true}}.
In the same area, {{negotiationType=SASL}} is marked as not implemented in
{{ThriftNegotiationType}}. Both the producer and the consumer still accept it
and then behave as with {{PLAINTEXT}}.
Proposal:
# Fail consumer startup when {{negotiationType=SSL}} is combined with
{{synchronous=false}}, with a message like the producer's.
# Reject {{negotiationType=SASL}} at startup in the producer and the consumer
until it is implemented.
# State on the component page that {{negotiationType=SSL}} requires
{{synchronous=true}} for both producer and consumer.
# Add an upgrade-guide entry: a consumer configured with
{{negotiationType=SSL}} and the default {{synchronous}} no longer starts.
_Claude Code on behalf of oscerd_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)