Aias00 opened a new issue, #6713: URL: https://github.com/apache/shenyu/issues/6713
- severity: Medium - files: `shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/ShenyuClientHttpRegistryController.java:61,77,93,106,122,138` - description: All six mutating endpoints (`registerMetadata`, `registerURI`, `registerApiDoc`, `registerDiscoveryConfig`, `registerMcpTools`, `offline`) take `@RequestBody` without `@Valid`, and the register DTOs carry no bean-validation annotations. Required fields like `appName`, `rpcType`, `host`, `contextPath` are never validated and are forwarded into the gateway registration pipeline as null. `registerApiDoc` (line 93) does not even default `namespaceId`. - impact: A malformed or empty JSON body is accepted and published to the gateway, potentially creating metadata/URI/MCP records with null required fields that downstream services consume without null-checks, leading to NPEs or corrupt gateway config. - suggested_fix: Add `@Valid` to each `@RequestBody` and add `@NotBlank`/`@NotNull` on required fields of the register DTOs. - confidence: High - related_existing: none — distinct from GOV-T1 (test coverage); this is a per-controller validation gap on externally-facing register endpoints. --- _Identified during the 2026-08-02 deep re-scan; full list in [`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
