Sean-Walker0 opened a new pull request, #7322:
URL: https://github.com/apache/shenyu/pull/7322

   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   Found by code audit (no existing issue — happy to file one if maintainers 
prefer).
   
   `ZombieUpstream`'s setter is named `setSelectorName` but its javadoc says 
*"set selectorId"*, it assigns the `selectorId` field, the class declares 
**no** `selectorName` field, and the matching getter is `getSelectorId()`. 
Every sibling accessor in the class maps to its own field, so this is a naming 
slip. The consequence is a broken JavaBeans contract: the `selectorId` property 
has no write method, and a phantom write-only `selectorName` property is 
exposed — any `java.beans`-based binding (Spring `BeanUtils.copyProperties`, 
EL, JMX, and any JSON library that binds through setters rather than fields) 
cannot populate `selectorId` and sees a writable `selectorName` that targets 
the wrong name. No in-repo caller uses the misnamed setter (construction goes 
through the builder/`transform()`), so nothing in the repo changes behavior.
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [x] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [x] You submit test cases (unit or integration tests) that back your 
changes.
   - [x] Your local test passed `./mvnw test -pl shenyu-common -am and ./mvnw 
checkstyle:check -pl shenyu-common` (module-scoped; full build left to CI).
   
   ### Modifications
   
   - Rename `setSelectorName` to `setSelectorId` in `ZombieUpstream` (one-line 
change).
   - Update the existing test that had codified the misnamed setter.
   
   ### Verifying this change
   
   - New `testSelectorIdFollowsJavaBeanContract` uses `java.beans.Introspector` 
to assert the `selectorId` property has a write method and no phantom 
`selectorName` property exists. It fails on current master with `selectorId 
must have a setter per the JavaBeans contract` and passes with this change.
   - Full `shenyu-common` module suite green (122 test classes); checkstyle 
green. Repo-wide grep confirms no other caller of the old method name.
   
   ### Notes
   
   - Source-compatibility note: the public method is renamed. It had zero 
in-repo callers and its old name was objectively wrong (assigned a different 
field than the name claims), so external code calling it was already writing 
through a misleading name; if maintainers prefer, a deprecated 
`setSelectorName` alias can be kept instead.
   - Jackson-based JSON paths are unaffected either way (Gson and Jackson both 
effectively work off fields/getters here — verified empirically); the contract 
being repaired is the java.beans one.
   - Orthogonal to open PRs: no open PR touches `ZombieUpstream` (checked 
against the file lists of all open PRs).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to