wy471x opened a new pull request, #6924:
URL: https://github.com/apache/shenyu/pull/6924

   CONNECT with password flag 0 yields a null passwordInBytes, which caused new 
String((byte[]) null) to throw and hang the connection without a CONNACK. Treat 
null as empty so the client receives 
CONNECTION_REFUSED_BAD_USER_NAME_OR_PASSWORD, and add unit tests.
   
   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [X] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [X] You submit test cases (unit or integration tests) that back your 
changes.
   - [X] Your local test passed `./mvnw clean install 
-Dmaven.javadoc.skip=true`.
   
   ## Summary                                                                   
                                                                                
                         
   
   ### Changes:                                                                 
                                                                                
                              
     - Fix NPE in MqttContext.isValid: new String(passwordInBytes) throws when 
msg.payload().passwordInBytes() is null — any CONNECT with the password flag 
bit set to 0 (anonymous or  
     username-only clients). The handler thread dies and the client never 
receives a CONNACK, leaving the connection hanging.                             
                              
     - Null passwordInBytes is now treated as empty, so validation fails 
gracefully and the client receives CONNECTION_REFUSED_BAD_USER_NAME_OR_PASSWORD 
instead of a hang.             
   
   ### Test Cases:
     - Added junit-jupiter test dependency and MqttContextTest with 6 cases 
covering null/empty/wrong password, null/empty username, and valid credentials.
   
   close [#6847](https://github.com/apache/shenyu/issues/6847)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to