Aias00 opened a new issue, #6620:
URL: https://github.com/apache/shenyu/issues/6620

   - severity: High
   - files: 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/DiscoveryUpstreamServiceImpl.java:292-331`
   - description: The single-arg `importData(List)` at line 255 is annotated 
`@Transactional(rollbackFor = Exception.class)`, but the namespace-scoped 
overload at line 293 is **not** (verified: grep shows no `@Transactional` 
between line 255 and 293). The method loops, inserts rows one-by-one, and 
remaps `discoveryHandlerId` via `context.getDiscoveryHandlerIdMapping()`. If a 
mid-loop insert fails, earlier inserts are already committed with no rollback. 
`ConfigsServiceImpl.configsImport` wraps the call with no outer transaction.
   - impact: Partial import leaves orphaned discovery-upstream rows pointing at 
non-existent handlers; retrying the import then double-counts or fails 
differently.
   - suggested_fix: Add `@Transactional(rollbackFor = Exception.class)` to the 
namespace overload, consistent with the single-arg version.
   - confidence: High
   - related_existing: none. The reported upstream items are N+1/listAll 
concerns, not this transaction gap.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to