Aias00 opened a new issue, #6731:
URL: https://github.com/apache/shenyu/issues/6731

   - Severity: Medium-High
   - Location:
   
`shenyu-sync-data-center/shenyu-sync-data-websocket/src/main/java/org/apache/shenyu/plugin/sync/data/websocket/handler/AbstractDataHandler.java:71-73`
 (`MYSELF`/`REFRESH` → `doRefresh`); `PluginDataHandler.java:43-46`, 
`SelectorDataHandler.java:43-46`, `RuleDataHandler.java:42-45` (`doRefresh` → 
`refreshXxxDataSelf`); 
`shenyu-plugin/shenyu-plugin-base/src/main/java/org/apache/shenyu/plugin/base/cache/CommonPluginDataSubscriber.java:127-133`
 (`refreshPluginDataSelf`), `:155-160` (`refreshSelectorDataSelf` — does NOT 
clean MatchDataCache), `:182-187` (`refreshRuleDataSelf` — does NOT clean 
MatchDataCache); 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-sign/src/main/java/org/apache/shenyu/plugin/sign/subscriber/SignAuthDataSubscriber.java`
 (no `refresh()` override → default no-op → `SignAuthDataCache` never cleared)
   - 
   Description:
   On reconnect, the gateway sends `MYSELF`; admin replies with the full 
current snapshot. `AbstractDataHandler.handle` routes `MYSELF` to `doRefresh`, 
which calls `refreshXxxDataSelf(dataList)`. `refreshPluginDataSelf` only calls 
`cleanPluginDataSelf` (removes only items *present in the payload*), not 
`refreshPluginDataAll()` (full clear). 
`refreshSelectorDataSelf`/`refreshRuleDataSelf` likewise only do partial 
BaseDataCache cleaning and do **not** clean `MatchDataCache` (compare 
`refreshSelectorDataAll`/`refreshRuleDataAll` at lines 148-152/175-179 which 
clean both). For auth, `SignAuthDataSubscriber` has no `refresh()` override 
(the interface default is a no-op), so `SignAuthDataCache` is never cleared. 
Contrast: HTTP long-polling transport (`SelectorDataRefresh.java`) correctly 
calls `refreshSelectorDataAll()` (full clear) — an inconsistency between sync 
transports.
   - 
   Impact:
   After any gateway reconnect following an admin-side delete, deleted 
selectors/rules/auth keys persist in gateway caches until process restart → 
traffic routed to deleted selectors/rules, stale match-cache entries, stale 
auth keys retained.
   - 
   Suggested fix:
   Route `MYSELF` to a full-replace path that calls `refreshXxxDataAll()` 
(clear BaseDataCache + MatchDataCache) before re-subscribing. Add `refresh()` 
overrides to `SignAuthDataSubscriber` that clear `SignAuthDataCache`.
   - 
   Confidence: High (verified: `refreshSelectorDataSelf` does not clean 
MatchDataCache; `SignAuthDataSubscriber` has no refresh override)
   - Related existing: #6569 is the HTTP long-polling path; #6479 is 
discovery-upstream specific; PERF-14 is a different class.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to