This is an automated email from the ASF dual-hosted git repository.
Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git
The following commit(s) were added to refs/heads/master by this push:
new b0a28e03b5 fix: reject empty registry and namespace delete requests
(#7190)
b0a28e03b5 is described below
commit b0a28e03b5b8019432aff638f4b64da52a431c73
Author: Southern <[email protected]>
AuthorDate: Sat Sep 26 15:31:43 2026 +0800
fix: reject empty registry and namespace delete requests (#7190)
Add @NotEmpty validation to registry and namespace batch-delete ID lists,
and add executable validation tests to ensure
empty lists are rejected before reaching the delete SQL.
Co-authored-by: aias00 <[email protected]>
---
.../admin/controller/NamespaceController.java | 3 +-
.../admin/controller/RegistryController.java | 3 +-
.../admin/controller/NamespaceControllerTest.java | 45 ++++++++++++++++++++++
.../admin/controller/RegistryControllerTest.java | 45 ++++++++++++++++++++++
4 files changed, 94 insertions(+), 2 deletions(-)
diff --git
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespaceController.java
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespaceController.java
index e2930d0b7f..8df5c3dc71 100644
---
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespaceController.java
+++
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespaceController.java
@@ -38,6 +38,7 @@ import org.springframework.web.bind.annotation.RequestParam;
import jakarta.validation.Valid;
import jakarta.validation.constraints.NotBlank;
+import jakarta.validation.constraints.NotEmpty;
import jakarta.validation.constraints.NotNull;
import java.util.List;
@@ -103,7 +104,7 @@ public class NamespaceController {
* @return {@linkplain ShenyuAdminResult}
*/
@DeleteMapping("/batch")
- public ShenyuAdminResult delete(@RequestBody final List<@NotBlank String>
ids) {
+ public ShenyuAdminResult delete(@RequestBody @NotEmpty final
List<@NotBlank String> ids) {
return ShenyuAdminResult.success(ShenyuResultMessage.SUCCESS,
namespaceService.delete(ids));
}
diff --git
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/RegistryController.java
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/RegistryController.java
index 74e9340c1d..6713f8d525 100644
---
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/RegistryController.java
+++
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/RegistryController.java
@@ -19,6 +19,7 @@ package org.apache.shenyu.admin.controller;
import jakarta.validation.Valid;
import jakarta.validation.constraints.NotBlank;
+import jakarta.validation.constraints.NotEmpty;
import jakarta.validation.constraints.NotNull;
import org.apache.shenyu.admin.aspect.annotation.RestApi;
import org.apache.shenyu.admin.mapper.RegistryMapper;
@@ -107,7 +108,7 @@ public class RegistryController {
*/
@DeleteMapping("/batch")
@RequiresPermissions("system:registry:delete")
- public ShenyuAdminResult delete(@RequestBody final List<@NotBlank String>
ids) {
+ public ShenyuAdminResult delete(@RequestBody @NotEmpty final
List<@NotBlank String> ids) {
return ShenyuAdminResult.success(ShenyuResultMessage.SUCCESS,
registryService.delete(ids));
}
diff --git
a/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/NamespaceControllerTest.java
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/NamespaceControllerTest.java
new file mode 100644
index 0000000000..3092837b1f
--- /dev/null
+++
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/NamespaceControllerTest.java
@@ -0,0 +1,45 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.shenyu.admin.controller;
+
+import jakarta.validation.Validation;
+import jakarta.validation.Validator;
+import jakarta.validation.executable.ExecutableValidator;
+import org.junit.jupiter.api.Test;
+
+import java.lang.reflect.Method;
+import java.util.Collections;
+
+import static org.junit.jupiter.api.Assertions.assertFalse;
+
+/**
+ * Test cases for NamespaceController.
+ */
+public final class NamespaceControllerTest {
+
+ @Test
+ public void testDeleteRejectsEmptyIds() throws NoSuchMethodException {
+ final Validator validator =
Validation.buildDefaultValidatorFactory().getValidator();
+ final ExecutableValidator executableValidator =
validator.forExecutables();
+ final NamespaceController controller = new NamespaceController(null);
+ final Method method = NamespaceController.class.getMethod("delete",
java.util.List.class);
+
+ assertFalse(executableValidator.validateParameters(controller, method,
+ new Object[]{Collections.emptyList()}).isEmpty());
+ }
+}
diff --git
a/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/RegistryControllerTest.java
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/RegistryControllerTest.java
new file mode 100644
index 0000000000..4bcd16f190
--- /dev/null
+++
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/RegistryControllerTest.java
@@ -0,0 +1,45 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.shenyu.admin.controller;
+
+import jakarta.validation.Validation;
+import jakarta.validation.Validator;
+import jakarta.validation.executable.ExecutableValidator;
+import org.junit.jupiter.api.Test;
+
+import java.lang.reflect.Method;
+import java.util.Collections;
+
+import static org.junit.jupiter.api.Assertions.assertFalse;
+
+/**
+ * Test cases for RegistryController.
+ */
+public final class RegistryControllerTest {
+
+ @Test
+ public void testDeleteRejectsEmptyIds() throws NoSuchMethodException {
+ final Validator validator =
Validation.buildDefaultValidatorFactory().getValidator();
+ final ExecutableValidator executableValidator =
validator.forExecutables();
+ final RegistryController controller = new RegistryController(null);
+ final Method method = RegistryController.class.getMethod("delete",
java.util.List.class);
+
+ assertFalse(executableValidator.validateParameters(controller, method,
+ new Object[]{Collections.emptyList()}).isEmpty());
+ }
+}