Aias00 opened a new issue, #6690:
URL: https://github.com/apache/shenyu/issues/6690
- severity: Medium
- files:
`shenyu-admin/src/main/resources/mappers/app-auth-sqlmap.xml:265-291`
(updateSelective `WHERE id=#{id}`) vs `:251-263` (full `update` `WHERE id=#{id}
AND namespace_id=#{namespaceId}`)
- description: The full `update` scopes by `id AND namespace_id`, but
`updateSelective` (the path used by `AppAuthServiceImpl.createOrUpdate`) scopes
only by `id` (verified). A caller that supplies an `id` belonging to namespace
A can mutate an app_auth row from namespace B without a namespace match.
- impact: Potential cross-namespace tampering of app_auth when only an id is
supplied and the namespace is not re-verified.
- suggested_fix: Add `AND namespace_id = #{namespaceId, jdbcType=VARCHAR}`
to `updateSelective`'s WHERE.
- confidence: Medium
- related_existing: none. The baseline AppAuth issues (#6538-6540) are about
updateDetail full-update nulling and path appName; this is the updateSelective
WHERE clause.
---
_Identified during the 2026-08-02 deep re-scan; full list in
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]