wy471x opened a new pull request, #6924: URL: https://github.com/apache/shenyu/pull/6924
CONNECT with password flag 0 yields a null passwordInBytes, which caused new String((byte[]) null) to throw and hang the connection without a CONNACK. Treat null as empty so the client receives CONNECTION_REFUSED_BAD_USER_NAME_OR_PASSWORD, and add unit tests. <!-- Describe your PR here; e.g. Fixes #issueNo --> <!-- Thank you for proposing a pull request. This template will guide you through the essential steps necessary for a pull request. --> Make sure that: - [X] You have read the [contribution guidelines](https://shenyu.apache.org/community/contributor-guide). - [X] You submit test cases (unit or integration tests) that back your changes. - [X] Your local test passed `./mvnw clean install -Dmaven.javadoc.skip=true`. ## Summary ### Changes: - Fix NPE in MqttContext.isValid: new String(passwordInBytes) throws when msg.payload().passwordInBytes() is null — any CONNECT with the password flag bit set to 0 (anonymous or username-only clients). The handler thread dies and the client never receives a CONNACK, leaving the connection hanging. - Null passwordInBytes is now treated as empty, so validation fails gracefully and the client receives CONNECTION_REFUSED_BAD_USER_NAME_OR_PASSWORD instead of a hang. ### Test Cases: - Added junit-jupiter test dependency and MqttContextTest with 6 cases covering null/empty/wrong password, null/empty username, and valid credentials. close [#6847](https://github.com/apache/shenyu/issues/6847) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
