RockteMQ-AI commented on issue #4848:
URL: 
https://github.com/apache/rocketmq-dashboard/issues/4848#issuecomment-5771040395

   **Issue Evaluation**
   
   Category: `bug` | Status: **Confirmed**
   
   The reported issue has been verified against the current codebase.
   
   **Root Cause:** `MessageSendToolHandler` enforces topic-type dispatch rules 
(FIFO requires `messageGroup`, DELAY requires future `deliveryTimestamp`, 
TRANSACTION is rejected), but `MetadataService.sendMessage` at line 281 passes 
the request directly to `adminClient.sendMessage(request)` without any 
topic-type validation. The REST path and the AI tool handler share the same 
`MetadataService`, but only the tool handler applies the dispatch rules.
   
   **Impact:** Users sending messages via the REST API can bypass FIFO/DELAY 
constraints — e.g., sending to a FIFO topic without `messageGroup`, or to a 
DELAY topic without a future `deliveryTimestamp`. This creates a consistency 
gap between the AI tool path and the web UI / API path.
   **Severity:** High — silent protocol violation that can cause message 
ordering or delivery issues.
   
   **Suggested fix:** Move the topic-type dispatch logic from 
`MessageSendToolHandler` into `MetadataService.sendMessage` (or a shared 
helper) so both paths enforce the same rules.
   
   An automated fix proposal can be generated. Reply `/approve` to proceed with 
PR generation.
   
   ---
   *Automated evaluation by RockteMQ-AI*
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to