This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 2359fdcede fix(basic-auth): fall back to the default handle for blank 
rule handles (#7374)
2359fdcede is described below

commit 2359fdcede76f49a0c80d95fcc47e0dd485ebdb2
Author: Sean-Walker0 <[email protected]>
AuthorDate: Wed Sep 30 10:45:00 2026 +0800

    fix(basic-auth): fall back to the default handle for blank rule handles 
(#7374)
    
    handlerRule wrapped its parse in
    Optional.ofNullable(ruleData.getHandle()) and then used
    StringUtils.defaultString(ruleHandle, default), whose fallback only
    fires for null - inside ifPresent the handle is provably non-null, so
    the configured defaultHandleJson was unreachable dead code. A rule
    saved with an empty handle (the exact case the fallback exists for)
    reached BasicAuthRuleHandle.newInstance("") , whose Gson parse of the
    empty string yields null, and the following
    setBasicAuthAuthenticationStrategy call threw NullPointerException
    inside the data-sync callback, failing the whole rule refresh.
    defaultIfBlank restores the intended blank-string fallback.
    
    The new test fails on current master with the exact NPE and passes
    with this change; blank handles now parse the plugin-level default
    handle instead of crashing.
    
    Co-authored-by: Sean-Walker0 
<[email protected]>
---
 .../plugin/basic/auth/handle/BasicAuthPluginDataHandler.java |  2 +-
 .../basic/auth/handle/BasicAuthPluginDataHandlerTest.java    | 12 ++++++++++++
 2 files changed, 13 insertions(+), 1 deletion(-)

diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandler.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandler.java
index 280876e936..5d942d470c 100755
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandler.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandler.java
@@ -60,7 +60,7 @@ public class BasicAuthPluginDataHandler implements 
PluginDataHandler {
     public void handlerRule(final RuleData ruleData) {
         BasicAuthConfig basicAuthConfig = 
Singleton.INST.get(BasicAuthConfig.class);
         Optional.ofNullable(ruleData.getHandle()).ifPresent(ruleHandle -> {
-            BasicAuthRuleHandle basicAuthRuleHandle = 
BasicAuthRuleHandle.newInstance(StringUtils.defaultString(ruleHandle, 
basicAuthConfig.getDefaultHandleJson()));
+            BasicAuthRuleHandle basicAuthRuleHandle = 
BasicAuthRuleHandle.newInstance(StringUtils.defaultIfBlank(ruleHandle, 
basicAuthConfig.getDefaultHandleJson()));
             
CACHED_HANDLE.get().cachedHandle(CacheKeyUtils.INST.getKey(ruleData), 
basicAuthRuleHandle);
         });
     }
diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandlerTest.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandlerTest.java
index a5da2af7c5..b29897d5d8 100755
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandlerTest.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/handle/BasicAuthPluginDataHandlerTest.java
@@ -66,6 +66,18 @@ public final class BasicAuthPluginDataHandlerTest {
         assertEquals(map.get("authorization"), ((DefaultBasicAuthRuleHandle) 
BasicAuthPluginDataHandler.CACHED_HANDLE.get().obtainHandle(CacheKeyUtils.INST.getKey(ruleData))).getAuthorization());
     }
 
+    @Test
+    public void 
testHandlerRuleFallsBackToDefaultHandleJsonWhenRuleHandleIsBlank() {
+        RuleData ruleData = new RuleData();
+        ruleData.setId("basicAuthRuleBlank");
+        ruleData.setSelectorId("basicAuth");
+        ruleData.setHandle("");
+        basicAuthPluginDataHandler.handlerPlugin(new PluginData("pluginId", 
"pluginName", 
"{\"defaultHandleJson\":\"{\\\"authorization\\\":\\\"test:test123\\\"}\"}", 
"0", false, null));
+        basicAuthPluginDataHandler.handlerRule(ruleData);
+        DefaultBasicAuthRuleHandle cached = (DefaultBasicAuthRuleHandle) 
BasicAuthPluginDataHandler.CACHED_HANDLE.get().obtainHandle(CacheKeyUtils.INST.getKey(ruleData));
+        assertEquals("test:test123", cached.getAuthorization());
+    }
+
     @Test
     public void testPluginNamed() {
         final String result = basicAuthPluginDataHandler.pluginNamed();

Reply via email to