Aias00 opened a new issue, #7299: URL: https://github.com/apache/shenyu/issues/7299
## Background Casdoor is a vendor-specific IAM integration that is not required by the ShenYu request-processing core. Its implementation and starter are small and independently loadable, but current packaging includes them in the main build and default bootstrap. Depends on #7294. ## Scope ### plugin-store - Add the Casdoor runtime plugin and Spring Boot starter. - Move Casdoor-owned configuration and handler logic while depending only on the supported ShenYu plugin API. - Port existing unit tests and add coverage for plugin-data refresh, missing/invalid token, callback parameters, downstream identity headers, authentication failure, and client/resource cleanup. - Add an E2E environment using a reproducible local Casdoor service or container. Cover login/token validation, unauthorized access, identity propagation, selector/rule matching, and runtime configuration refresh. - Document required Casdoor configuration, certificates/secrets, supported versions, and secure production defaults. ### apache/shenyu - Remove the Casdoor plugin/starter and default-bootstrap dependency after store parity. - Update current admin seed data, plugin menu/permissions, dependency management, docs, LICENSE/NOTICE, and distribution packaging. - Preserve historical upgrade SQL; provide a current-version migration path for existing plugin configuration. - Ensure no Casdoor SDK is pulled into the default bootstrap after cutover. ## Acceptance Criteria - [ ] Plugin and starter compile against the declared ShenYu plugin API. - [ ] Unit tests cover authentication success/failure, config refresh, and trusted identity propagation. - [ ] E2E runs without external shared credentials and validates a real authentication flow. - [ ] Secrets/certificates are never committed or logged. - [ ] Existing admin configuration can be migrated or reused with documented steps. - [ ] The default ShenYu distribution no longer includes the Casdoor SDK. - [ ] Store publication and main-repository removal are coordinated and rollback-safe. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
