Aias00 opened a new issue, #6477:
URL: https://github.com/apache/shenyu/issues/6477

   ### Current Behavior
   
   WAF reject rules expose a configurable `statusCode`, but the HTTP transport 
status is always set to `403 Forbidden`.
   
   `WafHandle` includes `statusCode` and defaults it to `403`, but `WafPlugin` 
hardcodes the response status:
   
   ```java
   exchange.getResponse().setStatusCode(HttpStatus.FORBIDDEN);
   Object error = ShenyuResultWrap.error(exchange, 
Integer.parseInt(wafHandle.getStatusCode()), Constants.REJECT_MSG, null);
   ```
   
   So a rule configured with another status code only changes the body code, 
while the actual HTTP status remains 403.
   
   ### Expected Behavior
   
   The configured WAF `statusCode` should either be applied to the HTTP 
response status as well, or the configuration should be removed/renamed so 
operators do not expect it to control the transport status.
   
   ### Impact
   
   Operators cannot return custom reject statuses from WAF rules, and clients 
can observe inconsistent HTTP status and response body code.
   
   ### Code Location
   
   - 
`shenyu-common/src/main/java/org/apache/shenyu/common/dto/convert/rule/WafHandle.java`
   - 
`shenyu-plugin/shenyu-plugin-waf/src/main/java/org/apache/shenyu/plugin/waf/WafPlugin.java`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to