Aias00 opened a new issue, #6827:
URL: https://github.com/apache/shenyu/issues/6827

   ## Description
   The `discovery` table has a `namespace_id` column (projected by the join 
select at `discovery-sqlmap.xml:111`, written by `insert`), but `update`, 
`updateSelective`, and `delete` all end `WHERE id = #{id}` with no 
`namespace_id` predicate. `DiscoveryServiceImpl.delete(String discoveryId)` 
takes only `discoveryId` (no namespace param at all); `update` builds a DO with 
`.namespaceId(...)` but `updateSelective` WHERE is id-only, so the supplied 
namespace is silently ignored. `DiscoveryController` (`@RestApi`) exposes `POST 
/discovery/insertOrUpdate` and `DELETE /discovery/{discoveryId}` with no 
per-method permission annotation.
   
   ## Location
   - `shenyu-admin/src/main/resources/mappers/discovery-sqlmap.xml:207-218` 
(update), `220-249` (updateSelective), `251-255` (delete)
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/DiscoveryServiceImpl.java:191-203,231-246`
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/DiscoveryController.java:36-88`
   
   ## Impact
   A user who knows/guesses a discovery `id` can update or delete a discovery 
config in another namespace, breaking namespace isolation for the discovery 
topology.
   
   ## Suggested fix
   Add `AND namespace_id = #{namespaceId, jdbcType=VARCHAR}` to the WHERE 
clauses of `update`, `updateSelective`, and `delete`; pass the DO's 
namespaceId; add a namespace parameter to the delete controller; add a 
permission annotation.
   
   ## Related existing
   Distinct from N8 (#6615, `DiscoveryController` missing 
`@RequiresPermissions`) and N15 (publish-before-commit in 
`registerDiscoveryConfig`) — this is the missing-namespace-in-WHERE defect in 
the update/delete mapper statements.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to