Sean-Walker0 opened a new pull request, #7419:
URL: https://github.com/apache/shenyu/pull/7419

   Fixes #6503
   
   ## Modifications
   
   `ForwardedRemoteAddressResolver#extractXForwardedValues` split the 
`X-Forwarded-For` header on the two-character separator `", "`. Per RFC 7239 
list syntax the values are comma-separated with *optional* whitespace, so a 
header like `203.0.113.10,198.51.100.1` (no space after the comma) was parsed 
as a single value, failed `InetAddresses.forString` validation, and the 
resolver silently fell back to the TCP remote address instead of using the 
forwarded chain. Entries padded with spaces (` 203.0.113.10 , 198.51.100.1 `) 
and empty entries (`203.0.113.10,,198.51.100.1`) hit the same path.
   
   Now the header is split on the bare comma, each entry is trimmed, and empty 
entries are dropped:
   
   ```java
   List<String> values = Arrays.stream(xForwardedValues.get(0).split(","))
           .map(String::trim)
           .filter(StringUtils::isNotEmpty)
           .collect(Collectors.toList());
   ```
   
   The existing behaviors are unchanged: no header / blank header / multiple 
`X-Forwarded-For` headers all still fall back to the remote address, and the 
per-value IP validation added by #7065 still guards the resolved address.
   
   ## Verifying this change
   
   - [x] `testResolveCommaSeparatedValuesWithoutWhitespace` — red on the 
pre-fix code (`expected: <127.0.0.1> but was: <192.0.2.10>`, i.e. fell back to 
the TCP address), green after.
   - [x] `testResolveTrimsWhitespaceAroundValues` — same red→green proof for 
whitespace padding.
   - [x] `testResolveIgnoresEmptyForwardedEntries` — same red→green proof for 
empty entries.
   - [x] `./mvnw -pl shenyu-web -am test -B` — 50/50 module tests green (all 
pre-existing `testResolver` cases unchanged), checkstyle clean.
   
   ## Notes
   
   - Behavior change: bare-comma XFF lists and space-padded entries now resolve 
from the forwarded chain instead of silently falling back to the TCP remote 
address; nothing that previously resolved correctly changes its result.
   - The single-value half of #6503 (one non-empty value being discarded) was 
already fixed on master by #7065; this PR completes the issue's remaining 
parsing half.
   - Orthogonality: no open PR touches `ForwardedRemoteAddressResolver` or 
`shenyu-web/.../forward/` (verified against the file lists of all 92 open PRs).
   
   Make sure that:
   
   - [x] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [x] You submit test cases (unit or integration tests) that back your 
changes.
   - [x] Your local test passed `./mvnw clean install 
-Dmaven.javadoc.skip=true` (module-scoped: `shenyu-web` with `-am`, tests + 
checkstyle green).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to