Sean-Walker0 opened a new pull request, #7375:
URL: https://github.com/apache/shenyu/pull/7375
<!-- Describe your PR here; e.g. Fixes #issueNo -->
Found by code audit (no existing issue — happy to file one if maintainers
prefer).
`KeyWordMatch`'s constructor appends `"||"` after **every** keyword, so the
compiled alternation always contains empty branches — a trailing one at
minimum, plus an inner one between every pair. `matches("")` therefore returns
`true` whenever any keyword is configured. Reachable consequences in
`DataDesensitizeUtils`: `desensitizeQueryParam` decodes an empty `rawKey` from
a query string like `?=secret` and calls `desensitizeSingleKeyword(true, "",
...)` → the innocent value gets replaced with a masked placeholder;
`desensitizeBody` hits the same via empty JSON keys.
<!--
Thank you for proposing a pull request. This template will guide you through
the essential steps necessary for a pull request.
-->
Make sure that:
- [x] You have read the [contribution
guidelines](https://shenyu.apache.org/community/contributor-guide).
- [x] You submit test cases (unit or integration tests) that back your
changes.
- [x] Your local test passed `./mvnw test -pl
shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api -am
and ./mvnw checkstyle:check -pl
shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api`
(module-scoped; full build left to CI).
### Modifications
- Join the alternatives with a single `"|"` and only **between** entries
(leading `if (sb.length() > 0)`), so no empty branch can exist in the pattern.
Keyword, `(?i)` case-insensitivity and the >6-char prefix/suffix shape are
untouched.
### Verifying this change
- New `KeyWordMatchTest`: `matches("")` must be `false` (fails on current
master with `expected: <false> but was: <true>`) and keyword semantics (match,
case-insensitive match, long-keyword shape, non-match) stay intact.
- Full module suite green (183 test classes across the reactor); checkstyle
green.
### Notes
- Behavior change: values under empty keys (query params like `?=secret`,
empty JSON keys) are no longer spuriously desensitized.
- Orthogonal to open PRs: no open PR touches `KeyWordMatch` (checked against
the file lists of all 200 open PRs).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]