Aias00 commented on issue #6607:
URL: https://github.com/apache/shenyu/issues/6607#issuecomment-5844408126

   Current repository inspection confirms the deprecated raw-password query 
path has no production caller; only its dedicated tests still call it. Both 
POST and compatibility GET `/platform/login` delegate to 
`DashboardUserService.login(...)`, which uses the current password-hash flow.
   
   Suggested implementation scope:
   
   - remove `DashboardUserService.findByQuery(userName, password)`;
   - remove the corresponding `DashboardUserServiceImpl` method;
   - remove `DashboardUserMapper.findByQuery`;
   - remove the `dashboard-user-sqlmap.xml` statement;
   - remove/update the mapper and service tests that exist only for this path.
   
   The compatibility GET login endpoint is explicitly out of scope for this 
cleanup because it does not call the deprecated raw-password mapper method.
   
   Acceptance criteria:
   
   - [ ] No raw-password `findByQuery(userName, password)` API or SQL remains.
   - [ ] POST login behavior and password-hash verification remain green.
   - [ ] Compatibility GET login behavior is unchanged.
   - [ ] Admin service, mapper, and controller tests pass.
   - [ ] Checkstyle and RAT pass.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to