Aias00 commented on code in PR #7263:
URL: https://github.com/apache/shenyu/pull/7263#discussion_r4110269142
##########
shenyu-web/src/main/java/org/apache/shenyu/web/filter/CrossFilter.java:
##########
@@ -50,8 +50,13 @@ public class CrossFilter implements WebFilter {
private final CrossFilterConfig filterConfig;
+ private volatile Pattern originPattern;
+
public CrossFilter(final CrossFilterConfig filterConfig) {
this.filterConfig = filterConfig;
+ if (Objects.nonNull(filterConfig.getAllowedOrigin()) &&
StringUtils.isNotBlank(filterConfig.getAllowedOrigin().getOriginRegex())) {
+ originPattern =
Pattern.compile(filterConfig.getAllowedOrigin().getOriginRegex().trim());
Review Comment:
This change turns a malformed regex from a request-time degradation into a
startup failure, so I would like it recorded somewhere operators will look.
`crossFilter` is a bean (`ShenyuConfiguration.java:200-204`), and this
constructor now compiles the regex eagerly - so a typo in
`shenyu.cross.allowed-origin.origin-regex` throws `PatternSyntaxException`
during context refresh and the gateway does not come up, whereas before it
started fine and only CORS evaluation failed.
Fail-fast is defensible (you disclose it in the description, and catching it
at startup is arguably better than discovering it on the first cross-origin
request), I just want the failure mode written down: someone whose gateway
refuses to boot after a config edit needs to know this line is the reason.
Nit on the same method: `originPattern = pattern` is a plain check-then-act,
so two threads can both compile here, or one can publish an older pattern over
a newer one. Both are harmless - `Pattern` is immutable, the next request
detects the mismatch and recompiles, and it converges. I would deliberately not
synchronise it (that puts contention on every CORS request to save one rare
compile), only noting that it is intentional.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]