lll-peanut opened a new pull request, #6533:
URL: https://github.com/apache/shenyu/pull/6533
Fixes #6474
## What's changed
- BasicAuthPlugin.doExecute now short-circuits with ERROR_TOKEN when the
Authorization header and URI user info are both missing, instead of
passing
null to the authentication strategy.
- DefaultBasicAuthAuthenticationStrategy.authenticate now uses
Objects.equals
so a null credential fails authentication instead of throwing NPE.
## Why
A request without credentials produced `authorization == null`, and the
default strategy dereferenced it (`authentication.equals(...)`), causing a
NullPointerException (HTTP 500) instead of the expected 401 ERROR_TOKEN.
## Tests
- BasicAuthPluginTest.testDoExecuteWithoutAuthorization: request without
Authorization header / user info must return Illegal authorization and
not
invoke the chain (failed with NPE before the fix).
-
DefaultBasicAuthAuthenticationStrategyTest.testAuthenticateWithNullAuthentication:
authenticate(null) must return false, not throw.
- `mvn -pl shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth
test`
→ 15 tests passed.
## Manual verification
- no credentials → {"code":401,"message":"Illegal authorization"}
- Authorization: test:test123 → request forwarded to upstream (200)
- wrong credentials → 401 Illegal authorization
Make sure that:
- [X ] You have read the [contribution
guidelines](https://shenyu.apache.org/community/contributor-guide).
- [X] You submit test cases (unit or integration tests) that back your
changes.
- [X] Your local test passed `./mvnw clean install
-Dmaven.javadoc.skip=true`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]