This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new c2f7f3cbea fix(logging): stop KeyWordMatch accepting the empty keyword 
(#7375)
c2f7f3cbea is described below

commit c2f7f3cbeae8a7cd4e2d89900ceaf1e7ab4fd554
Author: Sean-Walker0 <[email protected]>
AuthorDate: Thu Oct 1 12:01:18 2026 +0800

    fix(logging): stop KeyWordMatch accepting the empty keyword (#7375)
---
 .../desensitize/api/matcher/KeyWordMatch.java      | 11 +++++--
 .../desensitize/api/matcher/KeyWordMatchTest.java  | 38 ++++++++++++++++++++++
 2 files changed, 46 insertions(+), 3 deletions(-)

diff --git 
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
index 6e429f4b8f..e682e71f3d 100644
--- 
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
+++ 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
@@ -17,6 +17,7 @@
 
 package org.apache.shenyu.plugin.logging.desensitize.api.matcher;
 
+import java.util.Objects;
 import java.util.Set;
 import java.util.regex.Pattern;
 
@@ -34,7 +35,11 @@ public class KeyWordMatch {
      */
     public KeyWordMatch(final Set<String> keyWordSet) {
         StringBuilder sb = new StringBuilder();
-        keyWordSet.forEach(tempKeyWord -> {
+        // callers pass keywords.split(";") straight through, so blank tokens 
must be filtered here
+        keyWordSet.stream().filter(keyword -> Objects.nonNull(keyword) && 
!keyword.isBlank()).forEach(tempKeyWord -> {
+            if (sb.length() > 0) {
+                sb.append("|");
+            }
             sb.append("(?i)");
             if (tempKeyWord.length() <= 6) {
                 sb.append(Pattern.quote(tempKeyWord));
@@ -42,9 +47,9 @@ public class KeyWordMatch {
                 sb.append("^").append(Pattern.quote(tempKeyWord.substring(0, 
3))).append("(.*?)")
                         
.append(Pattern.quote(tempKeyWord.substring(tempKeyWord.length() - 
3))).append("$");
             }
-            sb.append("||");
         });
-        p = Pattern.compile(sb.toString());
+        // an empty or all-blank keyword set must never match, not even the 
empty string
+        p = Pattern.compile(sb.length() > 0 ? sb.toString() : "(?!)");
     }
 
     /**
diff --git 
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
index 881a1bcba3..4b2f0d3d6b 100644
--- 
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
+++ 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
@@ -23,6 +23,7 @@ import org.junit.jupiter.api.Test;
 import org.junit.jupiter.api.extension.ExtendWith;
 import org.mockito.junit.jupiter.MockitoExtension;
 
+import java.util.Arrays;
 import java.util.HashSet;
 import java.util.Set;
 
@@ -59,4 +60,41 @@ class KeyWordMatchTest {
         Assertions.assertTrue(match.matches("ab[secret]yz"));
         Assertions.assertTrue(match.matches("ab[other]yz"));
     }
+
+    @Test
+    public void matchesShouldNotAcceptTheEmptyKeyword() {
+        Assertions.assertFalse(keyWordMatch.matches(""), "an empty key must 
not be treated as a sensitive keyword");
+    }
+
+    @Test
+    public void matchesShouldIgnoreBlankTokensFromSplitKeywords() {
+        // keywords.split(";") on a value like "password;;name" contributes 
empty tokens
+        Set<String> mixed = new HashSet<>(Arrays.asList("password", ""));
+        KeyWordMatch match = new KeyWordMatch(mixed);
+        Assertions.assertFalse(match.matches(""), "an empty token must not 
recreate the empty-alternative bug");
+        Assertions.assertTrue(match.matches("password"));
+
+        Set<String> leadingBlank = new HashSet<>(Arrays.asList("", "name"));
+        Assertions.assertFalse(new KeyWordMatch(leadingBlank).matches(""));
+    }
+
+    @Test
+    public void matchesShouldNeverMatchWhenAllTokensAreBlank() {
+        Set<String> allBlank = new HashSet<>(Arrays.asList("", "   "));
+        KeyWordMatch match = new KeyWordMatch(allBlank);
+        Assertions.assertFalse(match.matches(""));
+        Assertions.assertFalse(match.matches("anything"));
+    }
+
+    @Test
+    public void matchesShouldKeepKeywordSemantics() {
+        Set<String> set = new HashSet<>();
+        set.add("password");
+        KeyWordMatch match = new KeyWordMatch(set);
+
+        Assertions.assertTrue(match.matches("password"));
+        Assertions.assertTrue(match.matches("PASSWORD"));
+        Assertions.assertFalse(match.matches("userName"));
+    }
+
 }

Reply via email to