This is an automated email from the ASF dual-hosted git repository.
Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git
The following commit(s) were added to refs/heads/master by this push:
new c2f7f3cbea fix(logging): stop KeyWordMatch accepting the empty keyword
(#7375)
c2f7f3cbea is described below
commit c2f7f3cbeae8a7cd4e2d89900ceaf1e7ab4fd554
Author: Sean-Walker0 <[email protected]>
AuthorDate: Thu Oct 1 12:01:18 2026 +0800
fix(logging): stop KeyWordMatch accepting the empty keyword (#7375)
---
.../desensitize/api/matcher/KeyWordMatch.java | 11 +++++--
.../desensitize/api/matcher/KeyWordMatchTest.java | 38 ++++++++++++++++++++++
2 files changed, 46 insertions(+), 3 deletions(-)
diff --git
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
index 6e429f4b8f..e682e71f3d 100644
---
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
+++
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/main/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatch.java
@@ -17,6 +17,7 @@
package org.apache.shenyu.plugin.logging.desensitize.api.matcher;
+import java.util.Objects;
import java.util.Set;
import java.util.regex.Pattern;
@@ -34,7 +35,11 @@ public class KeyWordMatch {
*/
public KeyWordMatch(final Set<String> keyWordSet) {
StringBuilder sb = new StringBuilder();
- keyWordSet.forEach(tempKeyWord -> {
+ // callers pass keywords.split(";") straight through, so blank tokens
must be filtered here
+ keyWordSet.stream().filter(keyword -> Objects.nonNull(keyword) &&
!keyword.isBlank()).forEach(tempKeyWord -> {
+ if (sb.length() > 0) {
+ sb.append("|");
+ }
sb.append("(?i)");
if (tempKeyWord.length() <= 6) {
sb.append(Pattern.quote(tempKeyWord));
@@ -42,9 +47,9 @@ public class KeyWordMatch {
sb.append("^").append(Pattern.quote(tempKeyWord.substring(0,
3))).append("(.*?)")
.append(Pattern.quote(tempKeyWord.substring(tempKeyWord.length() -
3))).append("$");
}
- sb.append("||");
});
- p = Pattern.compile(sb.toString());
+ // an empty or all-blank keyword set must never match, not even the
empty string
+ p = Pattern.compile(sb.length() > 0 ? sb.toString() : "(?!)");
}
/**
diff --git
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
index 881a1bcba3..4b2f0d3d6b 100644
---
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
+++
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-desensitize-api/src/test/java/org/apache/shenyu/plugin/logging/desensitize/api/matcher/KeyWordMatchTest.java
@@ -23,6 +23,7 @@ import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.extension.ExtendWith;
import org.mockito.junit.jupiter.MockitoExtension;
+import java.util.Arrays;
import java.util.HashSet;
import java.util.Set;
@@ -59,4 +60,41 @@ class KeyWordMatchTest {
Assertions.assertTrue(match.matches("ab[secret]yz"));
Assertions.assertTrue(match.matches("ab[other]yz"));
}
+
+ @Test
+ public void matchesShouldNotAcceptTheEmptyKeyword() {
+ Assertions.assertFalse(keyWordMatch.matches(""), "an empty key must
not be treated as a sensitive keyword");
+ }
+
+ @Test
+ public void matchesShouldIgnoreBlankTokensFromSplitKeywords() {
+ // keywords.split(";") on a value like "password;;name" contributes
empty tokens
+ Set<String> mixed = new HashSet<>(Arrays.asList("password", ""));
+ KeyWordMatch match = new KeyWordMatch(mixed);
+ Assertions.assertFalse(match.matches(""), "an empty token must not
recreate the empty-alternative bug");
+ Assertions.assertTrue(match.matches("password"));
+
+ Set<String> leadingBlank = new HashSet<>(Arrays.asList("", "name"));
+ Assertions.assertFalse(new KeyWordMatch(leadingBlank).matches(""));
+ }
+
+ @Test
+ public void matchesShouldNeverMatchWhenAllTokensAreBlank() {
+ Set<String> allBlank = new HashSet<>(Arrays.asList("", " "));
+ KeyWordMatch match = new KeyWordMatch(allBlank);
+ Assertions.assertFalse(match.matches(""));
+ Assertions.assertFalse(match.matches("anything"));
+ }
+
+ @Test
+ public void matchesShouldKeepKeywordSemantics() {
+ Set<String> set = new HashSet<>();
+ set.add("password");
+ KeyWordMatch match = new KeyWordMatch(set);
+
+ Assertions.assertTrue(match.matches("password"));
+ Assertions.assertTrue(match.matches("PASSWORD"));
+ Assertions.assertFalse(match.matches("userName"));
+ }
+
}