Aias00 opened a new issue, #6513:
URL: https://github.com/apache/shenyu/issues/6513

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-plugin
   
   ### What happened
   
   `AiTokenLimiterPluginHandler` parses rule handles directly from JSON and 
caches them without filling defaults:
   
   ```java
   final AiTokenLimiterHandle rateLimiterHandle = 
GsonUtils.getInstance().fromJson(s, AiTokenLimiterHandle.class);
   CACHED_HANDLE.get().cachedHandle(CacheKeyUtils.INST.getKey(ruleData), 
rateLimiterHandle);
   ```
   
   But the runtime assumes `tokenLimit` and `timeWindowSeconds` are always 
non-null:
   
   ```java
   Long tokenLimit = aiTokenLimiterHandle.getTokenLimit();
   Long timeWindowSeconds = aiTokenLimiterHandle.getTimeWindowSeconds();
   ...
   return isAllowed(reactiveRedisTemplate, cacheKey, tokenLimit)
   ```
   
   `isAllowed(...)` unboxes `tokenLimit` during comparison:
   
   ```java
   if (Long.parseLong(currentTokens.toString()) >= tokenLimit) {
       return Mono.just(false);
   }
   ```
   
   and token recording passes `timeWindowSeconds` to `Duration.ofSeconds(...)`:
   
   ```java
   reactiveRedisTemplate.opsForValue()
           .increment(cacheKey, tokens)
           .flatMap(currentValue -> reactiveRedisTemplate.expire(cacheKey, 
Duration.ofSeconds(windowSeconds)))
           .subscribe();
   ```
   
   The admin metadata for these rule fields marks them as not required and does 
not provide default values:
   
   ```sql
   INSERT INTO plugin_handle ... 'timeWindowSeconds' ... 
'{"required":"0","rule":""}'
   INSERT INTO plugin_handle ... 'tokenLimit' ... '{"required":"0","rule":""}'
   ```
   
   So a synced/saved rule handle missing either value can cause runtime 
failures instead of using the documented/default limiter settings.
   
   ### Expected behavior
   
   AI token limiter rule handling should validate required fields or apply 
defaults consistently for rule handles, not only for the selector default-rule 
path. Missing `tokenLimit` or `timeWindowSeconds` should not crash request 
processing.
   
   ### How to reproduce
   
   1. Enable the `ai-token-limiter` plugin with Redis config.
   2. Create or sync a rule handle that omits `tokenLimit`, for example:
   
   ```json
   {"aiTokenLimitType":"uri","timeWindowSeconds":60,"keyName":"default"}
   ```
   
   3. Send a request matching the rule.
   4. `isAllowed(...)` compares the current token count with a null 
`tokenLimit` and the request fails.
   
   A handle that omits `timeWindowSeconds` can also fail when response token 
usage is recorded through `Duration.ofSeconds(windowSeconds)`.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to