Sean-Walker0 opened a new pull request, #7320:
URL: https://github.com/apache/shenyu/pull/7320

   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   Fixes #5274
   
   A `WafHandle` deserialized from a rule handle such as 
`{"permission":"reject"}` carries a `null` `statusCode`, and 
`WafPlugin#doExecute` passed it straight into `Integer.parseInt` — so a request 
matching a reject rule whose optional status code was omitted failed with 
`NumberFormatException` and the gateway answered 500 instead of rejecting. The 
sibling branch right above (no selector/rule in the default model) already 
rejects with `HttpStatus.FORBIDDEN`, and `WafHandle.newDefaultInstance()` also 
uses `"403"`, so blank status codes now fall back to 403 the same way.
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [x] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [x] You submit test cases (unit or integration tests) that back your 
changes.
   - [x] Your local test passed `./mvnw test -pl 
shenyu-plugin/shenyu-plugin-waf -am and ./mvnw checkstyle:check -pl 
shenyu-plugin/shenyu-plugin-waf` (module-scoped; full build left to CI).
   
   ### Modifications
   
   - `WafPlugin#doExecute`: when the reject handle's `statusCode` is blank, 
fall back to `HttpStatus.FORBIDDEN.value()` instead of calling 
`Integer.parseInt` on it. Non-blank status codes behave exactly as before.
   
   ### Verifying this change
   
   - New `testWafPluginRejectWithoutStatusCodeFallsBackToForbidden` caches a 
`{"permission":"reject"}` handle and asserts the response status is 403. It 
fails on current master with `NumberFormatException: Cannot parse null string` 
and passes with this change.
   - Full `shenyu-plugin-waf` module suite green; checkstyle green. (The new 
test stubs distinct rule ids on the mock — `setId` on a Mockito mock is a 
no-op, and the shared `null_null` cache key would otherwise leak the handle 
into `testWafPluginNotConfiguration`.)
   
   ### Notes
   
   - Behavior change: reject rules with a blank status code now return 403 
instead of a 500 caused by the NumberFormatException.
   - Out of scope: a non-numeric status code (e.g. `"abc"`) still throws — that 
is invalid admin-side configuration, surfacing loudly rather than silently 
defaulting.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to