This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 2cd57998c2 fix: handle invalid JSON fields in cryptor plugin (#6960)
2cd57998c2 is described below

commit 2cd57998c2a472f3d3592b44e45523d38775ebcf
Author: SouthwestAsiaFloat <[email protected]>
AuthorDate: Sun Aug 23 12:56:08 2026 +0800

    fix: handle invalid JSON fields in cryptor plugin (#6960)
    
    Co-authored-by: aias00 <[email protected]>
---
 .../shenyu/plugin/cryptor/utils/JsonUtil.java      | 23 ++++++++--
 .../shenyu/plugin/cryptor/utils/JsonUtilTest.java  | 49 ++++++++++++++++++++++
 2 files changed, 69 insertions(+), 3 deletions(-)

diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
index ad703fb462..6325d5cf9f 100644
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
@@ -49,15 +49,32 @@ public final class JsonUtil {
      */
     public static String parser(final String json, final String fieldName) {
         Map<String, Object> map = GsonUtils.getInstance().toObjectMap(json);
+        if (Objects.isNull(map)) {
+            return null;
+        }
         String str = null;
         if (fieldName.contains(".")) {
             String[] split = fieldName.split("\\.");
-            JsonObject jsonObject = (JsonObject) map.get(split[0]);
+            Object firstElement = map.get(split[0]);
+            if (!(firstElement instanceof JsonObject)) {
+                return null;
+            }
+            JsonObject jsonObject = (JsonObject) firstElement;
             for (int i = 1; i < split.length; i++) {
+                JsonElement jsonElement = jsonObject.get(split[i]);
+                if (Objects.isNull(jsonElement)) {
+                    return null;
+                }
                 if (i == split.length - 1) {
-                    str = 
jsonObject.getAsJsonPrimitive(split[i]).getAsString();
+                    if (!jsonElement.isJsonPrimitive()) {
+                        return null;
+                    }
+                    str = jsonElement.getAsString();
                 } else {
-                    jsonObject = jsonObject.getAsJsonObject(split[i]);
+                    if (!jsonElement.isJsonObject()) {
+                        return null;
+                    }
+                    jsonObject = jsonElement.getAsJsonObject();
                 }
             }
         } else {
diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/test/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtilTest.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/test/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtilTest.java
new file mode 100644
index 0000000000..89577affb1
--- /dev/null
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/test/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtilTest.java
@@ -0,0 +1,49 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.shenyu.plugin.cryptor.utils;
+
+import org.junit.jupiter.api.Test;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertNull;
+
+public class JsonUtilTest {
+
+    @Test
+    public void testParser() {
+        assertEquals("shenyu", JsonUtil.parser("{\"name\":\"shenyu\"}", 
"name"));
+        assertEquals("shenyu", 
JsonUtil.parser("{\"data\":{\"nested\":{\"name\":\"shenyu\"}}}", 
"data.nested.name"));
+    }
+
+    @Test
+    public void testParserReturnsNullForNonObjectBody() {
+        assertNull(JsonUtil.parser("[{\"name\":\"shenyu\"}]", "name"));
+        assertNull(JsonUtil.parser("\"shenyu\"", "name"));
+        assertNull(JsonUtil.parser("invalid", "name"));
+    }
+
+    @Test
+    public void testParserReturnsNullForInvalidNestedPath() {
+        assertNull(JsonUtil.parser("{}", "data.nested.name"));
+        assertNull(JsonUtil.parser("{\"data\":\"shenyu\"}", 
"data.nested.name"));
+        assertNull(JsonUtil.parser("{\"data\":{}}", "data.nested.name"));
+        assertNull(JsonUtil.parser("{\"data\":{\"nested\":[]}}", 
"data.nested.name"));
+        assertNull(JsonUtil.parser("{\"data\":{\"nested\":{}}}", 
"data.nested.name"));
+        assertNull(JsonUtil.parser("{\"data\":{\"nested\":{\"name\":{}}}}", 
"data.nested.name"));
+    }
+}

Reply via email to