Sean-Walker0 opened a new pull request, #7323:
URL: https://github.com/apache/shenyu/pull/7323

   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   Found by code audit (no existing issue — happy to file one if maintainers 
prefer).
   
   `MqttContext#isValid` evaluates `MqttContext.userName.equals(userName)`. The 
statics are initialized from `MqttServerConfiguration`, whose 
`userName`/`password` default to `"shenyu"` — but an explicitly empty YAML 
value (`shenyu.mqtt.userName:`) binds **null**, leaving `MqttContext.userName` 
null. Every CONNECT that carries credentials (Connect handler calls `isValid`, 
`Connect.java:69`) then throws `NullPointerException` instead of rejecting the 
login, failing the connection handler.
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [x] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [x] You submit test cases (unit or integration tests) that back your 
changes.
   - [x] Your local test passed `./mvnw test -pl 
shenyu-protocol/shenyu-protocol-mqtt -am and ./mvnw checkstyle:check -pl 
shenyu-protocol/shenyu-protocol-mqtt` (module-scoped; full build left to CI).
   
   ### Modifications
   
   - Replace the two `.equals(...)` comparisons with `Objects.equals(...)` 
(`Objects` was already imported) — null-safety only, matching semantics 
unchanged for configured credentials.
   
   ### Verifying this change
   
   - New `isValidShouldRejectRatherThanThrowWhenServerCredentialsAreUnset` sets 
both statics to null and asserts credentialed logins are rejected. It fails on 
current master with `NullPointerException: Cannot invoke 
"String.equals(Object)" because "MqttContext.userName" is null` and passes with 
this change.
   - All 12 pre-existing credential matrix cases still pass; full 
`shenyu-protocol-mqtt` module suite green; checkstyle green.
   
   ### Notes
   
   - Behavior change: an MQTT server configured with empty credentials now 
rejects credentialed CONNECTs cleanly instead of erroring the handler.
   - Orthogonal to open PRs: no open PR touches `MqttContext` (checked against 
the file lists of all open PRs).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to