HY-love-sleep opened a new issue, #7154:
URL: https://github.com/apache/shenyu/issues/7154
### Description
The sensitive word plugin is proposed in #7153: the plugin module, the
starter, the rule handle
(`SensitiveWordHandle`) and `PluginEnum.SENSITIVE_WORD` are all in that PR,
and the dictionary is read
from a redis set (default key `shenyu:sensitive:words`).
What #7153 deliberately does **not** contain is the registration data, so as
of now the plugin cannot be
reached from the admin: there is no `plugin` row, no `plugin_handle` rows
(neither the redis connection
nor the rule level settings), and no `resource` rows, which means no menu
entry and no rule form.
This issue tracks that work. It will be done in a follow-up PR once #7153 is
merged, so that the review
of the plugin itself stays focused on the plugin implementation.
### TODO
**db/init + db/upgrade**
- [ ] `db/init/mysql/schema.sql`
- [ ] `db/init/pg/create-table.sql`
- [ ] `db/init/oracle/schema.sql`
- [ ] `db/init/ob/schema.sql`
- [ ] `db/init/og/create-table.sql`
- [ ] `shenyu-admin/src/main/resources/sql-script/h2/schema.sql`
- [ ] `db/upgrade/2.7.1-upgrade-2.7.2-{mysql,pg,oracle,ob,og}.sql` and the
upgrade guide entry
for every dialect, the same set of rows:
- [ ] the `plugin` row: name `sensitiveWord`, role `Ai`, sort `197`
- [ ] the `plugin_handle` rows: the redis connection (`url` / `password` /
`database`) and the rule level
settings (`redisKey`, `refreshIntervalSeconds`, `failClosed`)
- [ ] the `resource` rows: the menu entry and its children
- [ ] `namespace_plugin_rel` if the plugin has to be enabled for the default
namespace
**Console**
- [ ] the rule form for the handle above, so that the dictionary key, the
refresh interval and the fail
strategy can be configured without editing sql
**Body size**
- [ ] a bound on the inspected body (`maxBodySize`), raised in the review of
#7153: decide what happens
when the body exceeds it (skip the scan and warn, or reject) and how
that interacts with
`failClosed`
### Related
- #7153 - the plugin itself
- When the plugin config changes the redis connection is rebuilt and the
previous lettuce connection is
not released, because `RedisConnectionFactory` exposes no `destroy()` yet.
This is pre-existing
(`AiTokenLimiterPluginHandler` has the same shape) and will be a separate
small PR against
`shenyu-infra/shenyu-infra-redis`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]