Aias00 opened a new issue, #6713:
URL: https://github.com/apache/shenyu/issues/6713

   - severity: Medium
   - files: 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/ShenyuClientHttpRegistryController.java:61,77,93,106,122,138`
   - description: All six mutating endpoints (`registerMetadata`, 
`registerURI`, `registerApiDoc`, `registerDiscoveryConfig`, `registerMcpTools`, 
`offline`) take `@RequestBody` without `@Valid`, and the register DTOs carry no 
bean-validation annotations. Required fields like `appName`, `rpcType`, `host`, 
`contextPath` are never validated and are forwarded into the gateway 
registration pipeline as null. `registerApiDoc` (line 93) does not even default 
`namespaceId`.
   - impact: A malformed or empty JSON body is accepted and published to the 
gateway, potentially creating metadata/URI/MCP records with null required 
fields that downstream services consume without null-checks, leading to NPEs or 
corrupt gateway config.
   - suggested_fix: Add `@Valid` to each `@RequestBody` and add 
`@NotBlank`/`@NotNull` on required fields of the register DTOs.
   - confidence: High
   - related_existing: none — distinct from GOV-T1 (test coverage); this is a 
per-controller validation gap on externally-facing register endpoints.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to