Aias00 opened a new issue, #6632:
URL: https://github.com/apache/shenyu/issues/6632

   - Severity: High
   - Location:
   
`shenyu-sync-data-center/shenyu-sync-data-api/src/main/java/org/apache/shenyu/sync/data/core/AbstractNodeDataSyncService.java:261-267`
 (`unCacheAuthData` takes `ruleKeys[1]`), `:275-281` (`unCacheMetaData` takes 
`ruleKeys[1]`), `:289-296` (`unCacheProxySelectorData` takes 
`proxySelectorKeys[2]`/`[3]`)
   - 
   Description:
   The per-item key registered by `watchCommonList` is `namespace + "." + 
dataId + "." + id`, split by `DefaultNodeConstants.JOIN_POINT` = `"."`. The 
delete handlers index the split array with wrong offsets:
     - **auth:** key = `ns.auth.<appKey>` → `[ns, auth, appKey]`. Code takes 
`ruleKeys[1]` = `"auth"` (the data-id literal), not `ruleKeys[2]` = appKey. The 
sibling `unCacheSelectorData` (line 232-234) correctly uses `[2]`/`[3]` for its 
4-segment key.
     - **meta:** key = `ns.meta.<metaId>` → `[ns, meta, metaId]`. Code takes 
`ruleKeys[1]` = `"meta"`, not `[2]` = metaId.
     - **proxy-selector:** `NacosPathConstants.PROXY_SELECTOR_DATA_ID = 
"proxy.selector"` (contains a dot, verified `NacosPathConstants.java:58` / 
`ApolloPathConstants.java:62`). Key = `ns.proxy.selector.<pluginName>.<name>` → 
5 segments. Code reads `[2]`/`[3]` = `"selector"`/`<pluginName>`, instead of 
`[3]`/`[4]`.
     Both Nacos and Polaris transports pass the full key to the delete handler.
   - 
   Impact:
   When admin deletes an app-auth, meta-data, or proxy-selector via 
Nacos/Polaris/Apollo sync, the gateway constructs the eviction DTO with a bogus 
key (`appKey="auth"`, `id="meta"`, `pluginName="selector"`), so cache removal 
matches nothing. The real entry stays in the gateway cache until restart — 
stale auth keys, stale meta path-matching, stale proxy selectors.
   - 
   Suggested fix:
   `unCacheAuthData`: `setAppKey(ruleKeys[2])`. `unCacheMetaData`: 
`setId(ruleKeys[2])`. `unCacheProxySelectorData`: 
`setPluginName(proxySelectorKeys[3]); setName(proxySelectorKeys[4]);`. Add 
length guards.
   - 
   Confidence: High (verified: `AUTH_DATA_ID = "auth"`, `META_DATA_ID = 
"meta"`, `PROXY_SELECTOR_DATA_ID = "proxy.selector"`, `JOIN_POINT = "."`)
   - Related existing: #6479 is discovery-upstream stale cache, a different 
cache and root cause.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to