Sean-Walker0 opened a new pull request, #7419:
URL: https://github.com/apache/shenyu/pull/7419
Fixes #6503
## Modifications
`ForwardedRemoteAddressResolver#extractXForwardedValues` split the
`X-Forwarded-For` header on the two-character separator `", "`. Per RFC 7239
list syntax the values are comma-separated with *optional* whitespace, so a
header like `203.0.113.10,198.51.100.1` (no space after the comma) was parsed
as a single value, failed `InetAddresses.forString` validation, and the
resolver silently fell back to the TCP remote address instead of using the
forwarded chain. Entries padded with spaces (` 203.0.113.10 , 198.51.100.1 `)
and empty entries (`203.0.113.10,,198.51.100.1`) hit the same path.
Now the header is split on the bare comma, each entry is trimmed, and empty
entries are dropped:
```java
List<String> values = Arrays.stream(xForwardedValues.get(0).split(","))
.map(String::trim)
.filter(StringUtils::isNotEmpty)
.collect(Collectors.toList());
```
The existing behaviors are unchanged: no header / blank header / multiple
`X-Forwarded-For` headers all still fall back to the remote address, and the
per-value IP validation added by #7065 still guards the resolved address.
## Verifying this change
- [x] `testResolveCommaSeparatedValuesWithoutWhitespace` — red on the
pre-fix code (`expected: <127.0.0.1> but was: <192.0.2.10>`, i.e. fell back to
the TCP address), green after.
- [x] `testResolveTrimsWhitespaceAroundValues` — same red→green proof for
whitespace padding.
- [x] `testResolveIgnoresEmptyForwardedEntries` — same red→green proof for
empty entries.
- [x] `./mvnw -pl shenyu-web -am test -B` — 50/50 module tests green (all
pre-existing `testResolver` cases unchanged), checkstyle clean.
## Notes
- Behavior change: bare-comma XFF lists and space-padded entries now resolve
from the forwarded chain instead of silently falling back to the TCP remote
address; nothing that previously resolved correctly changes its result.
- The single-value half of #6503 (one non-empty value being discarded) was
already fixed on master by #7065; this PR completes the issue's remaining
parsing half.
- Orthogonality: no open PR touches `ForwardedRemoteAddressResolver` or
`shenyu-web/.../forward/` (verified against the file lists of all 92 open PRs).
Make sure that:
- [x] You have read the [contribution
guidelines](https://shenyu.apache.org/community/contributor-guide).
- [x] You submit test cases (unit or integration tests) that back your
changes.
- [x] Your local test passed `./mvnw clean install
-Dmaven.javadoc.skip=true` (module-scoped: `shenyu-web` with `-am`, tests +
checkstyle green).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]