This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 279333c3a2 fix(admin): scope selective app auth updates by namespace 
(#7243)
279333c3a2 is described below

commit 279333c3a2b01067a5a1b8c141bc06866237ce6f
Author: Liming Deng <[email protected]>
AuthorDate: Thu Oct 1 07:05:06 2026 +0800

    fix(admin): scope selective app auth updates by namespace (#7243)
---
 .../apache/shenyu/admin/model/entity/AppAuthDO.java |  1 +
 .../admin/service/impl/AppAuthServiceImpl.java      |  4 ++++
 .../src/main/resources/mappers/app-auth-sqlmap.xml  |  3 ++-
 .../shenyu/admin/mapper/AppAuthMapperTest.java      | 14 ++++++++++++++
 .../shenyu/admin/service/AppAuthServiceTest.java    | 21 +++++++++++++++++++++
 5 files changed, 42 insertions(+), 1 deletion(-)

diff --git 
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/model/entity/AppAuthDO.java
 
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/model/entity/AppAuthDO.java
index 4c050968a7..d26813fd04 100644
--- 
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/model/entity/AppAuthDO.java
+++ 
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/model/entity/AppAuthDO.java
@@ -230,6 +230,7 @@ public final class AppAuthDO extends BaseDO {
         return Optional.ofNullable(appAuthDTO).map(item -> {
             Timestamp currentTime = new Timestamp(System.currentTimeMillis());
             AppAuthDO appAuthDO = AppAuthDO.builder()
+                    .namespaceId(item.getNamespaceId())
                     .appKey(item.getAppKey())
                     .appSecret(item.getAppSecret())
                     .open(item.getOpen())
diff --git 
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/AppAuthServiceImpl.java
 
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/AppAuthServiceImpl.java
index 8fae8407de..a33a6d359f 100644
--- 
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/AppAuthServiceImpl.java
+++ 
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/AppAuthServiceImpl.java
@@ -428,8 +428,12 @@ public class AppAuthServiceImpl implements AppAuthService {
             appAuthCount = appAuthMapper.updateSelective(appAuthDO);
             eventType = DataEventTypeEnum.UPDATE;
         }
+        if (appAuthCount == 0) {
+            return 0;
+        }
         // publish AppAuthData's event
         AppAuthData data = AppAuthData.builder()
+                .namespaceId(appAuthDO.getNamespaceId())
                 .appKey(appAuthDO.getAppKey())
                 .appSecret(appAuthDO.getAppSecret())
                 .open(appAuthDO.getOpen())
diff --git a/shenyu-admin/src/main/resources/mappers/app-auth-sqlmap.xml 
b/shenyu-admin/src/main/resources/mappers/app-auth-sqlmap.xml
index 3f0312a250..d77a5b8e8f 100644
--- a/shenyu-admin/src/main/resources/mappers/app-auth-sqlmap.xml
+++ b/shenyu-admin/src/main/resources/mappers/app-auth-sqlmap.xml
@@ -290,7 +290,8 @@
                 enabled = #{enabled, jdbcType=TINYINT},
             </if>
         </set>
-         WHERE id = #{id, jdbcType=VARCHAR}
+        WHERE id = #{id, jdbcType=VARCHAR}
+          AND namespace_id = #{namespaceId, jdbcType=VARCHAR}
     </update>
 
     <delete id="delete" parameterType="java.lang.String">
diff --git 
a/shenyu-admin/src/test/java/org/apache/shenyu/admin/mapper/AppAuthMapperTest.java
 
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/mapper/AppAuthMapperTest.java
index c288e0b820..fc0af21422 100644
--- 
a/shenyu-admin/src/test/java/org/apache/shenyu/admin/mapper/AppAuthMapperTest.java
+++ 
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/mapper/AppAuthMapperTest.java
@@ -125,6 +125,20 @@ public final class AppAuthMapperTest extends 
AbstractSpringIntegrationTest {
         assertEquals(appSecret, selectAppAuthDO.getAppSecret());
     }
 
+    @Test
+    public void testUpdateSelectiveRequiresMatchingNamespace() {
+        AppAuthDO update = 
AppAuthDO.builder().id(appAuthDO.getId()).phone("updated").namespaceId("other-namespace").build();
+        assertEquals(0, appAuthMapper.updateSelective(update));
+        assertEquals(appAuthDO.getPhone(), 
appAuthMapper.selectById(appAuthDO.getId()).getPhone());
+        update.setNamespaceId(null);
+        assertEquals(0, appAuthMapper.updateSelective(update));
+        update.setNamespaceId(appAuthDO.getNamespaceId());
+        assertEquals(1, appAuthMapper.updateSelective(update));
+        AppAuthDO persisted = appAuthMapper.selectById(appAuthDO.getId());
+        assertEquals("updated", persisted.getPhone());
+        assertEquals(appAuthDO.getAppSecret(), persisted.getAppSecret());
+    }
+
     @Test
     public void testUpdateSelective() {
         int count = appAuthMapper.updateSelective(appAuthDO);
diff --git 
a/shenyu-admin/src/test/java/org/apache/shenyu/admin/service/AppAuthServiceTest.java
 
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/service/AppAuthServiceTest.java
index 3715aa1c29..1888e3ec90 100644
--- 
a/shenyu-admin/src/test/java/org/apache/shenyu/admin/service/AppAuthServiceTest.java
+++ 
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/service/AppAuthServiceTest.java
@@ -76,6 +76,8 @@ import static org.mockito.Mockito.never;
 import static org.mockito.Mockito.times;
 import static org.mockito.Mockito.verify;
 import static org.mockito.Mockito.when;
+import static org.mockito.Mockito.verifyNoInteractions;
+import static 
org.apache.shenyu.common.constant.Constants.SYS_DEFAULT_NAMESPACE_ID;
 
 /**
  * Test cases for AppAuthService.
@@ -113,6 +115,25 @@ public final class AppAuthServiceTest {
         testApplyUpdateSuccess();
     }
 
+    @Test
+    public void testCreateOrUpdatePropagatesNamespace() {
+        AppAuthDTO dto = buildAppAuthDTO("auth-id");
+        dto.setNamespaceId(SYS_DEFAULT_NAMESPACE_ID);
+        given(appAuthMapper.updateSelective(any())).willReturn(1);
+        assertEquals(1, appAuthService.createOrUpdate(dto));
+        verify(appAuthMapper).updateSelective(argThat(auth -> 
SYS_DEFAULT_NAMESPACE_ID.equals(auth.getNamespaceId())));
+        verify(eventPublisher).publishEvent(any());
+    }
+
+    @Test
+    public void testRejectedNamespaceUpdateDoesNotPublish() {
+        AppAuthDTO dto = buildAppAuthDTO("auth-id");
+        dto.setNamespaceId("other-namespace");
+        given(appAuthMapper.updateSelective(any())).willReturn(0);
+        assertEquals(0, appAuthService.createOrUpdate(dto));
+        verifyNoInteractions(eventPublisher);
+    }
+
     @Test
     public void testApplyUpdatePreservesOpenWhenOmitted() {
         final AuthApplyDTO authApplyDTO = buildAuthApplyDTO();

Reply via email to