Aias00 opened a new issue, #6825:
URL: https://github.com/apache/shenyu/issues/6825

   ## Description
   `RuleServiceImpl.deleteByIdsAndNamespaceId(List<String> ids, String 
namespaceId)` accepts `namespaceId` but the underlying 
`ruleMapper.selectByIds(ids)` is `SELECT * FROM rule WHERE id IN (...)` (no 
`namespace_id`) and `ruleMapper.deleteByIds(ids)` is `DELETE FROM rule WHERE id 
IN (...)` (no `namespace_id`). The `namespaceId` parameter is **never 
referenced** in the method body and never enforced in any SQL. The sibling 
`selectByQuery` and `updateSelective` *do* filter by `namespace_id`, confirming 
the omission is a bug, not design.
   
   Controller-exposed at `RuleController:153` (`@DeleteMapping("/batch")` → 
`batchNamespaceCommonDTO.getIds()` + `getNamespaceId()`, both user-supplied).
   
   ## Location
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/RuleServiceImpl.java:425-435`
   - `shenyu-admin/src/main/resources/mappers/rule-sqlmap.xml:203-209` 
(`selectByIds`), `377-383` (`deleteByIds`)
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/RuleController.java:150-155`
   
   ## Impact
   A user scoped to namespace A can delete rules in namespace B by supplying 
B's rule ids with A's namespaceId; the namespace guard is a no-op (IDOR-style 
cross-namespace destroy). Multi-namespace isolation — a documented Shenyu 
feature — is broken for this destructive operation. Requires an authenticated 
admin session with `system:plugin:delete`.
   
   ## Suggested fix
   Add `AND namespace_id = #{namespaceId, jdbcType=VARCHAR}` to both 
`selectByIds` and `deleteByIds` in `rule-sqlmap.xml`, or pre-filter `ids` 
against a namespace-scoped select before deleting.
   
   ## Related existing
   Distinct from N2 (#6615, `MetaDataServiceImpl.enabledByIdsAndNamespaceId` 
cross-namespace) — different service/mapper/operation (delete vs enable).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to