Aias00 opened a new issue, #6828:
URL: https://github.com/apache/shenyu/issues/6828
## Description
`app_auth selectByCondition` filters only on `appKey` and `phone` in a
`<where>` block; there is no `namespace_id` predicate, unlike `selectByQuery`
(which filters `namespace_id = #{namespaceId}`). `AppAuthQuery` carries
`namespaceId`. `AppAuthServiceImpl.searchByCondition(condition)` calls this
mapper directly.
## Location
- `shenyu-admin/src/main/resources/mappers/app-auth-sqlmap.xml:48-60`
-
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/AppAuthServiceImpl.java:98-99`
## Impact
`searchByCondition` returns app-auth rows across all namespaces, leaking
app-key/phone entries belonging to other namespaces to any caller of this
service method.
## Suggested fix
Add `<if test="condition.namespaceId != null and condition.namespaceId !=
''"> AND namespace_id = #{condition.namespaceId, jdbcType=VARCHAR} </if>` to
`selectByCondition`.
## Related existing
Distinct from N21 (#6700, `app_auth.updateSelective` WHERE omits
namespace_id — write path). This is the read path `selectByCondition`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]