This is an automated email from the ASF dual-hosted git repository.
dengliming pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git
The following commit(s) were added to refs/heads/master by this push:
new f2b6d0ea69 fix: apply configured WAF statusCode to HTTP response
instead of hardcoded 403 (#6821)
f2b6d0ea69 is described below
commit f2b6d0ea69feefbd3e11be6ef3e89d89284bec22
Author: wy471x <[email protected]>
AuthorDate: Tue Sep 15 20:53:27 2026 +0800
fix: apply configured WAF statusCode to HTTP response instead of hardcoded
403 (#6821)
Co-authored-by: Claude Opus 4.7 <[email protected]>
Co-authored-by: Liming Deng <[email protected]>
---
.../main/java/org/apache/shenyu/plugin/waf/WafPlugin.java | 5 +++--
.../java/org/apache/shenyu/plugin/waf/WafPluginTest.java | 14 +++++++++++++-
2 files changed, 16 insertions(+), 3 deletions(-)
diff --git
a/shenyu-plugin/shenyu-plugin-waf/src/main/java/org/apache/shenyu/plugin/waf/WafPlugin.java
b/shenyu-plugin/shenyu-plugin-waf/src/main/java/org/apache/shenyu/plugin/waf/WafPlugin.java
index ec84dc9a8b..e08563e579 100644
---
a/shenyu-plugin/shenyu-plugin-waf/src/main/java/org/apache/shenyu/plugin/waf/WafPlugin.java
+++
b/shenyu-plugin/shenyu-plugin-waf/src/main/java/org/apache/shenyu/plugin/waf/WafPlugin.java
@@ -65,8 +65,9 @@ public class WafPlugin extends AbstractShenyuPlugin {
return chain.execute(exchange);
}
if (WafEnum.REJECT.getName().equals(wafHandle.getPermission())) {
- exchange.getResponse().setStatusCode(HttpStatus.FORBIDDEN);
- Object error = ShenyuResultWrap.error(exchange,
Integer.parseInt(wafHandle.getStatusCode()), Constants.REJECT_MSG, null);
+ int statusCode = Integer.parseInt(wafHandle.getStatusCode());
+ exchange.getResponse().setRawStatusCode(statusCode);
+ Object error = ShenyuResultWrap.error(exchange, statusCode,
Constants.REJECT_MSG, null);
return WebFluxResultUtils.result(exchange, error);
}
return chain.execute(exchange);
diff --git
a/shenyu-plugin/shenyu-plugin-waf/src/test/java/org/apache/shenyu/plugin/waf/WafPluginTest.java
b/shenyu-plugin/shenyu-plugin-waf/src/test/java/org/apache/shenyu/plugin/waf/WafPluginTest.java
index 3bb68dbc75..c83ae71378 100644
---
a/shenyu-plugin/shenyu-plugin-waf/src/test/java/org/apache/shenyu/plugin/waf/WafPluginTest.java
+++
b/shenyu-plugin/shenyu-plugin-waf/src/test/java/org/apache/shenyu/plugin/waf/WafPluginTest.java
@@ -115,10 +115,22 @@ public final class WafPluginTest {
public void testWafPluginReject() {
ruleData.setId("waf");
ruleData.setSelectorId("waf");
- WafHandle handle =
GsonUtils.getGson().fromJson("{\"permission\":\"reject\",\"statusCode\":\"0\"}",
WafHandle.class);
+ WafHandle handle =
GsonUtils.getGson().fromJson("{\"permission\":\"reject\",\"statusCode\":\"403\"}",
WafHandle.class);
WafPluginDataHandler.CACHED_HANDLE.get().cachedHandle(CacheKeyUtils.INST.getKey(ruleData),
handle);
Mono<Void> execute = wafPluginUnderTest.doExecute(exchange, chain,
selectorData, ruleData);
StepVerifier.create(execute).expectSubscription().verifyComplete();
+ assertEquals(403, exchange.getResponse().getRawStatusCode());
+ }
+
+ @Test
+ public void testWafPluginRejectWithCustomStatusCode() {
+ ruleData.setId("waf");
+ ruleData.setSelectorId("waf");
+ WafHandle handle =
GsonUtils.getGson().fromJson("{\"permission\":\"reject\",\"statusCode\":\"404\"}",
WafHandle.class);
+
WafPluginDataHandler.CACHED_HANDLE.get().cachedHandle(CacheKeyUtils.INST.getKey(ruleData),
handle);
+ Mono<Void> execute = wafPluginUnderTest.doExecute(exchange, chain,
selectorData, ruleData);
+ StepVerifier.create(execute).expectSubscription().verifyComplete();
+ assertEquals(404, exchange.getResponse().getRawStatusCode());
}
@Test