im47cn commented on PR #6531:
URL: https://github.com/apache/shenyu/pull/6531#issuecomment-5182348161
Thanks @Aias00 for the thorough review. All items addressed in the latest
push:
**Should-fix #1 (IV reuse Javadoc):** Added security warning to
`AbstractCbcCryptorStrategy` class-level Javadoc documenting that the IV is
fixed per rule, the CBC reuse risk, and operator guidance to regenerate IVs per
deployment/rule.
**Should-fix #2 (SPI-wiring regression test):** Added
`CryptorStrategyFactorySpiTest` that loads strategies via
`CryptorStrategyFactory.newInstance("aes")` / `newInstance("sm4")` — exercising
the real `ExtensionLoader.getJoin` + META-INF SPI path, not direct
instantiation. If the SPI file or `@Join` annotation is dropped, these tests
fail.
**Nit #3 (key format divergence):** Added cross-reference in the same
Javadoc pointing to `AesUtils` and warning against interchanging secrets.
**Nit #4 (negative test coverage):** Added 3 new negative tests: AES 15-byte
key (wrong length), SM4 18-byte key (wrong length), and non-base64 key content.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]