Aias00 opened a new issue, #6474: URL: https://github.com/apache/shenyu/issues/6474
### Current Behavior The Basic Auth plugin can throw `NullPointerException` when a protected request does not provide credentials. `BasicAuthPlugin.doExecute()` reads the credential from the `Authorization` header or URI user info. If neither exists, `authorization` can be `null`, but it is still passed to the configured authentication strategy: ```java authenticationStrategy.authenticate(basicAuthRuleHandle, authorization) ``` The default strategy then dereferences the value directly: ```java return authentication.equals(((DefaultBasicAuthRuleHandle) basicAuthRuleHandle).getAuthorization()); ``` ### Expected Behavior Missing Basic Auth credentials should fail authentication and return the normal `ERROR_TOKEN` response instead of throwing an internal exception. ### Steps to Reproduce 1. Enable the Basic Auth plugin on a route with the default strategy. 2. Send a request to that route without an `Authorization` header and without URI user info. 3. The default strategy dereferences `authentication` and can throw `NullPointerException`. ### Code Location - `shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java` - `shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
