This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 1e24ce572b fix(mcp): encode request path values (#7118)
1e24ce572b is described below

commit 1e24ce572bfff67147cc176cb388e0e8b5f2c017
Author: Liming Deng <[email protected]>
AuthorDate: Tue Sep 22 09:27:27 2026 +0800

    fix(mcp): encode request path values (#7118)
---
 .../plugin/mcp/server/request/RequestConfigHelper.java   | 16 ++++++----------
 .../mcp/server/request/RequestConfigHelperTest.java      | 15 +++++++++++++--
 2 files changed, 19 insertions(+), 12 deletions(-)

diff --git 
a/shenyu-plugin/shenyu-plugin-mcp-server/src/main/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelper.java
 
b/shenyu-plugin/shenyu-plugin-mcp-server/src/main/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelper.java
index 6f60d661c8..8e6ca7b807 100644
--- 
a/shenyu-plugin/shenyu-plugin-mcp-server/src/main/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelper.java
+++ 
b/shenyu-plugin/shenyu-plugin-mcp-server/src/main/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelper.java
@@ -19,7 +19,9 @@ package org.apache.shenyu.plugin.mcp.server.request;
 
 import com.google.gson.JsonObject;
 import org.apache.shenyu.common.utils.GsonUtils;
+import org.springframework.web.util.UriUtils;
 
+import java.nio.charset.StandardCharsets;
 import java.util.Objects;
 
 /**
@@ -141,7 +143,7 @@ public class RequestConfigHelper {
             if (inputJson.has(key)) {
                 try {
                     String value = inputJson.get(key).getAsString();
-                    if (value.startsWith("http://";) || 
value.startsWith("https://";) || value.contains("?")) {
+                    if (value.startsWith("http://";) || 
value.startsWith("https://";)) {
                         return true;
                     }
                 } catch (Exception exception) {
@@ -164,7 +166,7 @@ public class RequestConfigHelper {
             if (inputJson.has(key)) {
                 try {
                     String value = inputJson.get(key).getAsString();
-                    if (value.startsWith("http://";) || 
value.startsWith("https://";) || value.contains("?")) {
+                    if (value.startsWith("http://";) || 
value.startsWith("https://";)) {
                         return value;
                     }
                 } catch (Exception exception) {
@@ -192,11 +194,8 @@ public class RequestConfigHelper {
             if ("path".equals(position) && inputJson.has(key)) {
                 // Process path parameters
                 String value = inputJson.get(key).getAsString();
-                if (value.contains("?")) {
-                    value = value.substring(0, value.indexOf("?"));
-                }
                 value = value.replace("\"", "").trim();
-                modifiedBasePath = modifiedBasePath.replace("{{." + key + 
"}}", value);
+                modifiedBasePath = modifiedBasePath.replace("{{." + key + 
"}}", UriUtils.encodePathSegment(value, StandardCharsets.UTF_8));
             } else if ("query".equals(position) && inputJson.has(key)) {
                 // Handle query parameters
                 if (!modifiedBasePath.contains(key + "=")) {
@@ -204,11 +203,8 @@ public class RequestConfigHelper {
                         queryBuilder.append("&");
                     }
                     String value = inputJson.get(key).getAsString();
-                    if (value.contains("?")) {
-                        value = value.substring(0, value.indexOf("?"));
-                    }
                     value = value.replace("\"", "").trim();
-                    queryBuilder.append(key).append("=").append(value);
+                    
queryBuilder.append(key).append("=").append(UriUtils.encodeQueryParam(value, 
StandardCharsets.UTF_8));
                 }
             }
         }
diff --git 
a/shenyu-plugin/shenyu-plugin-mcp-server/src/test/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelperTest.java
 
b/shenyu-plugin/shenyu-plugin-mcp-server/src/test/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelperTest.java
index aa12ad11f3..47b59f04ee 100644
--- 
a/shenyu-plugin/shenyu-plugin-mcp-server/src/test/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelperTest.java
+++ 
b/shenyu-plugin/shenyu-plugin-mcp-server/src/test/java/org/apache/shenyu/plugin/mcp/server/request/RequestConfigHelperTest.java
@@ -203,7 +203,18 @@ class RequestConfigHelperTest {
         inputJson.addProperty("query", "hello world & special chars");
         
         String result = RequestConfigHelper.buildPath("/search", argsPosition, 
inputJson);
-        // The implementation doesn't URL encode, so check for raw string
-        assertTrue(result.contains("query=hello world & special chars"));
+        assertEquals("/search?query=hello%20world%20%26%20special%20chars", 
result);
+    }
+
+    @Test
+    void testReservedCharactersInPathParameter() {
+        JsonObject argsPosition = new JsonObject();
+        argsPosition.addProperty("id", "path");
+        JsonObject inputJson = new JsonObject();
+        inputJson.addProperty("id", "a/b #?+%");
+
+        String result = RequestConfigHelper.buildPath("/items/{{.id}}", 
argsPosition, inputJson);
+
+        assertEquals("/items/a%2Fb%20%23%3F+%25", result);
     }
 }

Reply via email to