Aias00 opened a new issue, #6732:
URL: https://github.com/apache/shenyu/issues/6732

   - Severity: Low-Medium
   - Location:
   
`shenyu-sync-data-center/shenyu-sync-data-websocket/src/main/java/org/apache/shenyu/plugin/sync/data/websocket/handler/WebsocketDataHandler.java:35`
 (`private static final EnumMap<ConfigGroupEnum, DataHandler> ENUM_MAP`), 
populated in constructor `:50-57`, read at `:68`
   - 
   Description:
   `ENUM_MAP` is `static`, shared across all `WebsocketDataHandler` instances. 
`WebsocketSyncDataService` creates one `ShenyuWebsocketClient` (and thus one 
`WebsocketDataHandler`) per URL in `shenyu.sync.websocket.urls` (multiple for 
HA); `masterCheck`/recreate creates more. Each constructor overwrites the 
shared map; the last-constructed instance's handlers win for *all* clients.
   - 
   Impact:
   In standard single-subscriber deployment the injected subscribers are the 
same shared Spring beans, so the clobbering is masked. But it is fundamentally 
wrong (mutable static state initialized in a constructor) and becomes a live 
cross-talk defect for any multi-tenant or test wiring that supplies per-client 
subscriber lists.
   - 
   Suggested fix:
   Make `ENUM_MAP` a non-static instance field.
   - 
   Confidence: High (as a defect), Low (production impact in standard config)
   - Related existing: none
   
   ---
   
   ## F. Header/cookie/body manipulation plugins (4 findings)
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to