wy471x opened a new pull request, #6821: URL: https://github.com/apache/shenyu/pull/6821
apply configured WAF statusCode to HTTP response instead of hardcoded 403 <!-- Describe your PR here; e.g. Fixes #issueNo --> <!-- Thank you for proposing a pull request. This template will guide you through the essential steps necessary for a pull request. --> Make sure that: - [X] You have read the [contribution guidelines](https://shenyu.apache.org/community/contributor-guide). - [X] You submit test cases (unit or integration tests) that back your changes. - [X] Your local test passed `./mvnw clean install -Dmaven.javadoc.skip=true`. ## Summary ### Problem: WafPlugin hardcoded exchange.getResponse().setStatusCode(HttpStatus.FORBIDDEN), ignoring the configurable statusCode from WafHandle. This meant setting a custom statusCode (e.g., 404) only changed the response body code, while the actual HTTP transport status remained 403. ### Changes: - WafPlugin.java:67-71 — Parse wafHandle.getStatusCode() once, apply it via setRawStatusCode(statusCode) instead of setStatusCode(HttpStatus.FORBIDDEN), and reuse the same int value in ShenyuResultWrap.error(), keeping HTTP status and body code consistent. - WafPluginTest.java — Updated testWafPluginReject to use a valid statusCode: "403" and added assertEquals(403, exchange.getResponse().getRawStatusCode()). Added testWafPluginRejectWithCustomStatusCode that configures statusCode: "404" and asserts the HTTP response status is actually 404. close [#6477](https://github.com/apache/shenyu/issues/6477) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
