Sean-Walker0 opened a new pull request, #7320:
URL: https://github.com/apache/shenyu/pull/7320
<!-- Describe your PR here; e.g. Fixes #issueNo -->
Fixes #5274
A `WafHandle` deserialized from a rule handle such as
`{"permission":"reject"}` carries a `null` `statusCode`, and
`WafPlugin#doExecute` passed it straight into `Integer.parseInt` — so a request
matching a reject rule whose optional status code was omitted failed with
`NumberFormatException` and the gateway answered 500 instead of rejecting. The
sibling branch right above (no selector/rule in the default model) already
rejects with `HttpStatus.FORBIDDEN`, and `WafHandle.newDefaultInstance()` also
uses `"403"`, so blank status codes now fall back to 403 the same way.
<!--
Thank you for proposing a pull request. This template will guide you through
the essential steps necessary for a pull request.
-->
Make sure that:
- [x] You have read the [contribution
guidelines](https://shenyu.apache.org/community/contributor-guide).
- [x] You submit test cases (unit or integration tests) that back your
changes.
- [x] Your local test passed `./mvnw test -pl
shenyu-plugin/shenyu-plugin-waf -am and ./mvnw checkstyle:check -pl
shenyu-plugin/shenyu-plugin-waf` (module-scoped; full build left to CI).
### Modifications
- `WafPlugin#doExecute`: when the reject handle's `statusCode` is blank,
fall back to `HttpStatus.FORBIDDEN.value()` instead of calling
`Integer.parseInt` on it. Non-blank status codes behave exactly as before.
### Verifying this change
- New `testWafPluginRejectWithoutStatusCodeFallsBackToForbidden` caches a
`{"permission":"reject"}` handle and asserts the response status is 403. It
fails on current master with `NumberFormatException: Cannot parse null string`
and passes with this change.
- Full `shenyu-plugin-waf` module suite green; checkstyle green. (The new
test stubs distinct rule ids on the mock — `setId` on a Mockito mock is a
no-op, and the shared `null_null` cache key would otherwise leak the handle
into `testWafPluginNotConfiguration`.)
### Notes
- Behavior change: reject rules with a blank status code now return 403
instead of a 500 caused by the NumberFormatException.
- Out of scope: a non-numeric status code (e.g. `"abc"`) still throws — that
is invalid admin-side configuration, surfacing loudly rather than silently
defaulting.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]