Aias00 opened a new issue, #6845:
URL: https://github.com/apache/shenyu/issues/6845

   ## Description
   `DataDesensitizeUtils.desensitizeBody` does `Map<String,String> bodyMap = 
JsonUtils.jsonToMap(source, String.class)`. `JsonUtils.jsonToMap` catches 
`IOException` and returns an empty `LinkedHashMap` for any non-JSON input. The 
code then `bodyMap.forEach(...)` (no-op) and returns 
`JsonUtils.toJson(bodyMap)` = `"{}"` for all non-JSON input. `queryParams` is 
`request.getURI().getQuery()` (e.g. `a=1&b=2`) — never JSON. 
`requestBody`/`responseBody` are arbitrary content (XML, form-encoded, plain 
text, HTML).
   
   ## Location
   - 
`shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/utils/DataDesensitizeUtils.java:87-100`
   - 
`shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollector.java:207-211`
   - 
`shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/AbstractLoggingPlugin.java:109`
   
   ## Impact
   Whenever desensitization is enabled, legitimate non-JSON request/response 
bodies and query strings are replaced in the collected log with `"{}"` — 
permanent silent data loss in the audit log plus false appearance of empty 
payloads.
   
   ## Suggested fix
   Only invoke `desensitizeBody` when `source` parses as JSON (pre-check or 
fall back to `desensitizeForSingleWord`); for `queryParams`, apply key/value 
desensitization on the parsed query string rather than treating it as JSON.
   
   ## Related existing
   Distinct from LOG-13 (#6770, `KeyWordMatch` regex) and #6581 
(`LogCollectUtils` JSON-on-request-thread).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to