wy471x opened a new pull request, #7007: URL: https://github.com/apache/shenyu/pull/7007
<!-- Describe your PR here; e.g. Fixes #issueNo --> <!-- Thank you for proposing a pull request. This template will guide you through the essential steps necessary for a pull request. --> Make sure that: - [X] You have read the [contribution guidelines](https://shenyu.apache.org/community/contributor-guide). - [X] You submit test cases (unit or integration tests) that back your changes. - [X] Your local test passed `./mvnw clean install -Dmaven.javadoc.skip=true`. ## Summary ### Changes: 1. `discovery-sqlmap.xml` — added `AND namespace_id = #{namespaceId, jdbcType=VARCHAR}` to the WHERE clauses of `update` (:217), `updateSelective` (:248) and `delete` (:254), so discovery mutations are scoped to the caller's namespace; `delete` now takes `(id, namespaceId)` parameters. 2. `DiscoveryMapper.java:134` — `delete(String id)` changed to `delete(@Param("id") String id, @Param("namespaceId") String namespaceId)`. 3. `DiscoveryServiceImpl.java:192-206` — `delete` accepts `namespaceId` and verifies the selected `DiscoveryDO` belongs to the requested namespace before invoking the discovery processor, so cross-namespace ids produce no registry side effects (also fixes a potential NPE when the id does not exist); the mapper delete is then called with the scoped predicate. 4. `SelectorServiceImpl.java:332` / `ProxySelectorServiceImpl.java:184` — internal cleanup paths pass `discoveryDO.getNamespaceId()` (the DO is freshly loaded from DB, so the value is authoritative). 5. `DiscoveryController.java` — `DELETE /discovery/{discoveryId}` now requires a `namespaceId` request parameter (validated via `@Existed(NamespaceMapper)`); added `@RequiresPermissions("system:plugin:edit")` to `insertOrUpdate` and `@RequiresPermissions("system:plugin:delete")` to `delete`, consistent with the Selector/Rule controllers. ### Test Cases: - `DiscoveryMapperTest` — H2 integration tests: `delete`/`update`/`updateSelective` with a mismatched namespace mutate 0 rows; with a matching namespace they mutate only the target row and leave the other namespace's row intact. - `DiscoveryServiceImplTest` — delete succeeds in the matching namespace; throws `ShenyuException` with no processor/mapper side effects on namespace mismatch or when the discovery does not exist. ## Verification - `./mvnw clean install -Dmaven.javadoc.skip=true` passed locally (JDK 21). - Targeted tests: 23 run, 0 failures (`DiscoveryMapperTest`, `DiscoveryServiceImplTest`, `SelectorServiceTest`, `ProxySelectorServiceTest`). - `checkstyle:check` passed. Note: the dashboard frontend (apache/shenyu-dashboard) currently calls `DELETE /discovery/{id}` without a `namespaceId`; a follow-up in that repository is needed to pass the current namespace. close #6827 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
