Aias00 opened a new issue, #6845:
URL: https://github.com/apache/shenyu/issues/6845
## Description
`DataDesensitizeUtils.desensitizeBody` does `Map<String,String> bodyMap =
JsonUtils.jsonToMap(source, String.class)`. `JsonUtils.jsonToMap` catches
`IOException` and returns an empty `LinkedHashMap` for any non-JSON input. The
code then `bodyMap.forEach(...)` (no-op) and returns
`JsonUtils.toJson(bodyMap)` = `"{}"` for all non-JSON input. `queryParams` is
`request.getURI().getQuery()` (e.g. `a=1&b=2`) — never JSON.
`requestBody`/`responseBody` are arbitrary content (XML, form-encoded, plain
text, HTML).
## Location
-
`shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/utils/DataDesensitizeUtils.java:87-100`
-
`shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollector.java:207-211`
-
`shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/AbstractLoggingPlugin.java:109`
## Impact
Whenever desensitization is enabled, legitimate non-JSON request/response
bodies and query strings are replaced in the collected log with `"{}"` —
permanent silent data loss in the audit log plus false appearance of empty
payloads.
## Suggested fix
Only invoke `desensitizeBody` when `source` parses as JSON (pre-check or
fall back to `desensitizeForSingleWord`); for `queryParams`, apply key/value
desensitization on the parsed query string rather than treating it as JSON.
## Related existing
Distinct from LOG-13 (#6770, `KeyWordMatch` regex) and #6581
(`LogCollectUtils` JSON-on-request-thread).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]