Aias00 opened a new issue, #6520:
URL: https://github.com/apache/shenyu/issues/6520

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-admin
   
   ### What happened
   
   `TagServiceImpl.createInner(...)` loads the parent tag when `parentTagId` is 
not the root id:
   
   ```java
   if (!tagDTO.getParentTagId().equals(AdminConstants.TAG_ROOT_PARENT_ID)) {
       TagDO tagDO = tagMapper.selectByPrimaryKey(tagDTO.getParentTagId());
       ext = buildExtParamByParentTag(tagDO);
   } else {
       ext = 
GsonUtils.getInstance().toJson(Optional.ofNullable(tagExt).orElse(new 
TagDO.TagExt()));
   }
   ```
   
   `buildExtParamByParentTag(...)` then dereferences the parent tag immediately:
   
   ```java
   private String buildExtParamByParentTag(final TagDO parentTagDO) {
       String ext = "";
       if (parentTagDO.getId().equals(AdminConstants.TAG_ROOT_PARENT_ID)) {
           ...
       }
   ```
   
   If the request supplies a non-root `parentTagId` that does not exist, 
`tagMapper.selectByPrimaryKey(...)` returns `null`, and the admin API fails 
with `NullPointerException` instead of a validation error.
   
   ### Expected behavior
   
   Creating or updating a child tag should validate that `parentTagId` exists 
before building inherited tag metadata. A missing parent tag should return a 
clear parameter/validation error rather than an internal 500.
   
   ### How to reproduce
   
   1. Call the tag create API with a non-root `parentTagId` that is not present 
in the tag table.
   2. `TagServiceImpl.createInner(...)` calls 
`tagMapper.selectByPrimaryKey(parentTagId)` and receives `null`.
   3. `buildExtParamByParentTag(null)` calls `parentTagDO.getId()` and throws 
`NullPointerException`.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to