X-LightYear opened a new issue, #4994:
URL: https://github.com/apache/rocketmq-dashboard/issues/4994

   ### Before Creating the Bug Report
   
   - [x] I searched open and closed issues and pull requests for 
`refreshClusterDetail`, instance-scoped cluster detail, configured cluster 
scope, and cross-instance cluster resolution.
   - [x] I reproduced the behavior on the current `rocketmq-studio` baseline 
(`1ef5d8607`).
   - [x] A deterministic regression test fails against the current production 
code.
   
   ### Problem
   
   The instance-scoped cluster detail endpoint can return a physical cluster 
that is not within the selected instance's configured cluster scope.
   
   When an Apache Studio instance is configured with a specific cluster name 
but its NameServer exposes multiple clusters, `GET 
/api/clusters/{id}?instanceId=...` does not apply the same configured-cluster 
filter used by `GET /api/clusters?instanceId=...`.
   
   ### Steps to Reproduce
   
   1. Configure an Apache instance `instance-a` whose endpoint exposes 
`ConfiguredCluster` and `OtherCluster`.
   2. Configure the instance's selected/default cluster as `ConfiguredCluster`.
   3. Call `GET /api/clusters/OtherCluster?instanceId=instance-a`.
   4. Observe the returned cluster detail.
   
   ### Expected behavior
   
   An instance-scoped detail request must reject or return no result for a 
cluster outside that instance's configured scope, consistently with the 
instance-scoped cluster list.
   
   ### Actual behavior
   
   The endpoint returns a populated `ClusterVO` for `OtherCluster`.
   
   ### Root cause
   
   `RocketMQClusterProvider.discoverClusters(String instanceId)` filters the 
discovered list with `configuredClusterName(instanceId)`, but 
`refreshClusterDetail(String clusterId, String instanceId)` looks up 
`clusterId` directly in the NameServer cluster table without applying that 
scope.
   
   ### Regression evidence
   
   
`RocketMQClusterProviderTest.refreshClusterDetailShouldRejectClusterOutsideConfiguredInstanceScope`
 fails on the current baseline with:
   
   ```text
   expected: null
   but was: ClusterVO(id=OtherCluster, ...)
   ```
   
   ### Scope
   
   This is limited to the instance-scoped cluster detail read path. The 
requested fix should preserve global cluster detail behavior when no 
`instanceId` is supplied.
   
   ### Are you Willing to Submit a Pull Request?
   
   Yes.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to