This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 563415e5cf [type:fix] scope cryptor JSON replacement to configured 
path (#7200)
563415e5cf is described below

commit 563415e5cf50044e604183339f26b71e6148a2e2
Author: Liming Deng <[email protected]>
AuthorDate: Wed Sep 30 12:02:51 2026 +0800

    [type:fix] scope cryptor JSON replacement to configured path (#7200)
    
    * fix(cryptor): replace only configured json path
    
    * fix(cryptor): guard JSON replacement starting depth
---
 .../shenyu/plugin/cryptor/utils/JsonUtil.java      | 31 +++++++++++---------
 .../shenyu/plugin/cryptor/utils/JsonUtilTest.java  | 33 ++++++++++++++++++++++
 2 files changed, 51 insertions(+), 13 deletions(-)

diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
index 6325d5cf9f..c615f6ec56 100644
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java
@@ -102,26 +102,33 @@ public final class JsonUtil {
     /**
      * operate json.
      * @param jsonElement jsonElement
-     * @param initDeep default 0
+     * @param startDepth starting path index, normally 0; retained as 
AtomicInteger for compatibility and never mutated
      * @param value The value that needs to be modified
      * @param deepKey json link
      * @return JsonElement
      */
     public static JsonElement replaceJsonNode(final JsonElement jsonElement,
-                                              final AtomicInteger initDeep,
+                                              final AtomicInteger startDepth,
                                               final String value,
                                               final List<String> deepKey) {
         if (CollectionUtils.isEmpty(deepKey)) {
             return jsonElement;
         }
-        if (jsonElement.isJsonPrimitive()) {
+        return replaceJsonNode(jsonElement, startDepth.get(), value, deepKey);
+    }
+
+    private static JsonElement replaceJsonNode(final JsonElement jsonElement,
+                                               final int depth,
+                                               final String value,
+                                               final List<String> deepKey) {
+        if (depth < 0 || depth >= deepKey.size() || 
jsonElement.isJsonPrimitive()) {
             return jsonElement;
         }
         if (jsonElement.isJsonArray()) {
             JsonArray jsonArray = jsonElement.getAsJsonArray();
             JsonArray jsonArrayNew = new JsonArray();
             for (JsonElement element : jsonArray) {
-                jsonArrayNew.add(replaceJsonNode(element, initDeep, value, 
deepKey));
+                jsonArrayNew.add(replaceJsonNode(element, depth, value, 
deepKey));
             }
             return jsonArrayNew;
         }
@@ -130,17 +137,15 @@ public final class JsonUtil {
             JsonObject object = jsonElement.getAsJsonObject();
             JsonObject objectNew = new JsonObject();
             for (Map.Entry<String, JsonElement> entry : object.entrySet()) {
-                if (deepKey.get(initDeep.get()).equals(entry.getKey())) {
-                    initDeep.incrementAndGet();
-                }
                 String key = entry.getKey();
-                if (initDeep.get() == deepKey.size()) {
-                    initDeep.set(deepKey.size() - 1);
-                    object.addProperty(key, value);
+                JsonElement child = entry.getValue();
+                if (!deepKey.get(depth).equals(key)) {
+                    objectNew.add(key, child);
+                } else if (depth == deepKey.size() - 1) {
+                    objectNew.addProperty(key, value);
+                } else {
+                    objectNew.add(key, replaceJsonNode(child, depth + 1, 
value, deepKey));
                 }
-                JsonElement jsonEle = object.get(key);
-                JsonElement jsonElementNew = replaceJsonNode(jsonEle, 
initDeep, value, deepKey);
-                objectNew.add(key, jsonElementNew);
             }
             return objectNew;
         }
diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/test/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtilTest.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/test/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtilTest.java
index 89577affb1..bd42fee0a1 100644
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/test/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtilTest.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/test/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtilTest.java
@@ -17,10 +17,16 @@
 
 package org.apache.shenyu.plugin.cryptor.utils;
 
+import com.google.gson.JsonElement;
+import com.google.gson.JsonParser;
 import org.junit.jupiter.api.Test;
 
+import java.util.Arrays;
+import java.util.concurrent.atomic.AtomicInteger;
+
 import static org.junit.jupiter.api.Assertions.assertEquals;
 import static org.junit.jupiter.api.Assertions.assertNull;
+import static org.junit.jupiter.api.Assertions.assertSame;
 
 public class JsonUtilTest {
 
@@ -46,4 +52,31 @@ public class JsonUtilTest {
         assertNull(JsonUtil.parser("{\"data\":{\"nested\":{}}}", 
"data.nested.name"));
         assertNull(JsonUtil.parser("{\"data\":{\"nested\":{\"name\":{}}}}", 
"data.nested.name"));
     }
+
+    @Test
+    public void testReplacementStartingDepthIsReadOnlyAndBoundsChecked() {
+        JsonElement source = JsonParser.parseString("{\"b\":1}");
+        AtomicInteger startDepth = new AtomicInteger(1);
+        JsonElement result = JsonUtil.replaceJsonNode(source, startDepth, 
"encrypted", Arrays.asList("a", "b"));
+        assertEquals("{\"b\":\"encrypted\"}", result.toString());
+        assertEquals(1, startDepth.get());
+        assertEquals("{\"b\":1}", source.toString());
+        for (int invalidDepth : new int[]{-1, 2, 3}) {
+            assertSame(source, JsonUtil.replaceJsonNode(source, new 
AtomicInteger(invalidDepth), "encrypted", Arrays.asList("a", "b")));
+        }
+    }
+
+    @Test
+    public void testReplaceJsonNodeOnlyUpdatesConfiguredPath() {
+        JsonElement source = 
JsonParser.parseString("{\"a\":{\"b\":1},\"c\":{\"b\":2}}");
+        JsonElement result = JsonUtil.replaceJsonNode(source, new 
AtomicInteger(0), "encrypted", Arrays.asList("a", "b"));
+        assertEquals("{\"a\":{\"b\":\"encrypted\"},\"c\":{\"b\":2}}", 
result.toString());
+    }
+
+    @Test
+    public void testReplaceJsonNodeUpdatesPathInArrayElements() {
+        JsonElement source = 
JsonParser.parseString("[{\"a\":{\"b\":1}},{\"a\":{\"b\":2}}]");
+        JsonElement result = JsonUtil.replaceJsonNode(source, new 
AtomicInteger(0), "encrypted", Arrays.asList("a", "b"));
+        
assertEquals("[{\"a\":{\"b\":\"encrypted\"}},{\"a\":{\"b\":\"encrypted\"}}]", 
result.toString());
+    }
 }

Reply via email to