dmsolr opened a new pull request, #7014:
URL: https://github.com/apache/shenyu/pull/7014

   ### What is the purpose of the change
   
   Fixes #6874.
   
   In `AbstractNodeDataChangedListener#onCommonChanged`, the REFRESH/MYSELF 
branch only removed stale plugin/app-auth/metadata config entries when the old 
set strictly outnumbered the new one (`configDataNames.size() > 
changedList.size()`). When a REFRESH replaced the set with equal or larger 
cardinality but different members (e.g. old=[A,B,C,D], new=[C,D,E,F]), the 
guard was false, so stale entries A and B were never removed from 
nacos/apollo/polaris config centers — only orphaned per-entry config nodes 
remained while the LIST node was overwritten.
   
   This path is reached by `syncAllByNamespaceId(REFRESH, ns)` from 
`NamespacePluginController` and `ConfigsExportImportController`, which publish 
PLUGIN/AUTH/META REFRESH events spanning a whole namespace. For app-auth this 
is security-adjacent, since a deleted app key's config node could linger and be 
served to gateways that read it before the list update propagates.
   
   ### Changes
   - Removed the faulty size guard so the stale-entry diff (`removeAll`) always 
runs.
   - Fixed the stale-entry `delConfig` call to use the correctly namespaced key 
(`configKeyPrefix + name`) instead of the bare entry name, which was also 
silently preventing cleanup even when the guard passed.
   - Added a regression test reproducing the exact scenario from the issue 
(old=[A,B,C,D] -> new=[C,D,E,F], equal cardinality) verifying stale entries are 
removed.
   
   ### Does this PR introduce a user-facing change?
   
   No.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to