Aias00 opened a new issue, #6538:
URL: https://github.com/apache/shenyu/issues/6538

   ## Description
   `updateDetail` calls `appAuthMapper.update(appAuthDO)` where the DO is 
mapped straight from the DTO. The `update` SQL is a *full* update: `SET 
app_key=?, app_secret=?, phone=?, user_id=?, ext_info=?, open=?, enabled=?`. In 
`AppAuthDTO`, `phone`/`userId`/`extInfo` have no `@NotNull`, so any field the 
client omits becomes null on the DO and is written as `NULL`. Every other 
update path (`createOrUpdate`, `modifyPassword`) correctly uses 
`updateSelective`.
   
   ## Location
   ```
   shenyu-admin/.../service/impl/AppAuthServiceImpl.java:184
   SQL at shenyu-admin/src/main/resources/mappers/app-auth-sqlmap.xml:251-262
   ```
   
   ## Impact
   `phone`, `user_id`, `ext_info` are silently wiped. The published 
`DataChangedEvent(UPDATE)` carries the already-nullified entity, so the gateway 
also receives the wrong data.
   
   ## Suggested fix
   Use `appAuthMapper.updateSelective(appAuthDO)`, or merge the existing 
record's `phone/userId/extInfo` before the full `update`.
   
   ## Related existing issue(s)
   None
   
   _Identified during the 2026-08-02 audit; full list in 
[`docs/issue-candidates-2026-08-02.md`](docs/issue-candidates-2026-08-02.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to