Aias00 opened a new issue, #6521:
URL: https://github.com/apache/shenyu/issues/6521

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-admin
   
   ### What happened
   
   `MockRequestRecordServiceImpl.queryByApiId(...)` returns the first row from 
`selectByQuery(...)`:
   
   ```java
   MockRequestRecordQuery mockRequestRecordQuery = new MockRequestRecordQuery();
   mockRequestRecordQuery.setApiId(apiId);
   List<MockRequestRecordDO> mockRequestRecordDOList = 
mockRequestRecordMapper.selectByQuery(mockRequestRecordQuery);
   return mockRequestRecordDOList.isEmpty()
           ? new MockRequestRecordVO()
           : 
MockRequestRecordVO.buildMockRequestRecordVO(mockRequestRecordDOList.get(0));
   ```
   
   But the mapper query has no `ORDER BY`:
   
   ```xml
   <select id="selectByQuery" ...>
       SELECT ...
       FROM mock_request_record
       <where>
           <if test="apiId != null">
              and api_id = #{apiId, jdbcType=VARCHAR}
           </if>
           ...
       </where>
   </select>
   ```
   
   and the table schema only defines `id` as the primary key. There is no 
uniqueness constraint on `api_id`:
   
   ```sql
   CREATE TABLE `mock_request_record` (
       `id` varchar(128) NOT NULL,
       `api_id` varchar(128) NOT NULL,
       ...
       PRIMARY KEY (`id`)
   )
   ```
   
   If multiple mock request records exist for the same `apiId`, the returned 
record depends on the database execution plan and can change unpredictably.
   
   ### Expected behavior
   
   `queryByApiId(...)` should be deterministic. It should either enforce a 
unique mock request record per `apiId`, add a deterministic ordering and 
selection rule, or return all matching records instead of silently picking the 
first unordered row.
   
   ### How to reproduce
   
   1. Insert or create two `mock_request_record` rows with the same `api_id` 
and different request data.
   2. Call the admin API path that uses 
`MockRequestRecordServiceImpl.queryByApiId(apiId)`.
   3. The service returns `selectByQuery(...).get(0)` without any SQL ordering 
or uniqueness guarantee.
   4. Which mock record is returned is not stable across database plans/storage 
state.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to