[ 
https://issues.apache.org/jira/browse/CAMEL-8625?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Tomasz Ptak updated CAMEL-8625:
-------------------------------
    Description: 
DefaultRestletBinding adds values from submitted form as headers in the 
inMessage of the exchange. As a result it is close to impossible to rely on any 
of the values provided.
Suggested solution:
a) form values should be stored separately, or
b) populating headers from the form should fail if a header with this key 
already exists
c) prefixing keys coming from the form with something, for instance "form."

Solution a is a safer solution which will break compatibility with previous 
versions of Apache Camel (it can also be spread over a number of releases, 
first introducing new field for form values and logging a warning if form data 
is being extracted, next making it configurable and disabled by default, then 
removing this functionality).
Solution b is backwards compatible if this behaviour is not used as a feature  
(if it is, it should not). That said someone could still use it to populate 
RestletRequest-like headers in the Message.
Solution c would be rather ok as well, but I like a more, personally.

I can provide a patch if any solution is accepted.

  was:
DefaultRestletBinding adds values from submitted form as headers in the 
inMessage of the exchange. As a result it is close to impossible to rely on any 
of the values provided.
Suggested solution:
a) form values should be stored separately, or
b) populating headers from the form should fail if a header with this key 
already exists

Solution a is a safer solution which will break compatibility with previous 
versions of Apache Camel (it can also be spread over a number of releases, 
first introducing new field for form values and logging a warning if form data 
is being extracted, next making it configurable and disabled by default, then 
removing this functionality).
Solution b is backwards compatible if this behaviour is not used as a feature  
(if it is, it should not). That said someone could still use it to populate 
RestletRequest-like headers in the Message.

I can provide a patch if any solution is accepted.


> Form fields overwrite headers in InMessage
> ------------------------------------------
>
>                 Key: CAMEL-8625
>                 URL: https://issues.apache.org/jira/browse/CAMEL-8625
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-restlet
>    Affects Versions: 2.13.4, 2.14.2, 2.15.1
>         Environment: Linux
>            Reporter: Tomasz Ptak
>
> DefaultRestletBinding adds values from submitted form as headers in the 
> inMessage of the exchange. As a result it is close to impossible to rely on 
> any of the values provided.
> Suggested solution:
> a) form values should be stored separately, or
> b) populating headers from the form should fail if a header with this key 
> already exists
> c) prefixing keys coming from the form with something, for instance "form."
> Solution a is a safer solution which will break compatibility with previous 
> versions of Apache Camel (it can also be spread over a number of releases, 
> first introducing new field for form values and logging a warning if form 
> data is being extracted, next making it configurable and disabled by default, 
> then removing this functionality).
> Solution b is backwards compatible if this behaviour is not used as a feature 
>  (if it is, it should not). That said someone could still use it to populate 
> RestletRequest-like headers in the Message.
> Solution c would be rather ok as well, but I like a more, personally.
> I can provide a patch if any solution is accepted.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to