Aias00 opened a new issue, #6825:
URL: https://github.com/apache/shenyu/issues/6825
## Description
`RuleServiceImpl.deleteByIdsAndNamespaceId(List<String> ids, String
namespaceId)` accepts `namespaceId` but the underlying
`ruleMapper.selectByIds(ids)` is `SELECT * FROM rule WHERE id IN (...)` (no
`namespace_id`) and `ruleMapper.deleteByIds(ids)` is `DELETE FROM rule WHERE id
IN (...)` (no `namespace_id`). The `namespaceId` parameter is **never
referenced** in the method body and never enforced in any SQL. The sibling
`selectByQuery` and `updateSelective` *do* filter by `namespace_id`, confirming
the omission is a bug, not design.
Controller-exposed at `RuleController:153` (`@DeleteMapping("/batch")` →
`batchNamespaceCommonDTO.getIds()` + `getNamespaceId()`, both user-supplied).
## Location
-
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/RuleServiceImpl.java:425-435`
- `shenyu-admin/src/main/resources/mappers/rule-sqlmap.xml:203-209`
(`selectByIds`), `377-383` (`deleteByIds`)
-
`shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/RuleController.java:150-155`
## Impact
A user scoped to namespace A can delete rules in namespace B by supplying
B's rule ids with A's namespaceId; the namespace guard is a no-op (IDOR-style
cross-namespace destroy). Multi-namespace isolation — a documented Shenyu
feature — is broken for this destructive operation. Requires an authenticated
admin session with `system:plugin:delete`.
## Suggested fix
Add `AND namespace_id = #{namespaceId, jdbcType=VARCHAR}` to both
`selectByIds` and `deleteByIds` in `rule-sqlmap.xml`, or pre-filter `ids`
against a namespace-scoped select before deleting.
## Related existing
Distinct from N2 (#6615, `MetaDataServiceImpl.enabledByIdsAndNamespaceId`
cross-namespace) — different service/mapper/operation (delete vs enable).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]