X-LightYear opened a new pull request, #4995:
URL: https://github.com/apache/rocketmq-dashboard/pull/4995

   ## Summary
   
   - keep instance-scoped cluster detail requests within the configured cluster 
scope
   - preserve the existing global lookup behavior when no instance is supplied
   - add deterministic regression coverage for cross-scope cluster detail 
requests
   
   ## Root cause
   
   `RocketMQClusterProvider.discoverClusters(instanceId)` filtered discovered 
clusters by the instance's configured cluster name, but 
`refreshClusterDetail(clusterId, instanceId)` looked up the requested cluster 
directly in the NameServer table.
   
   An instance-scoped detail request could therefore return another physical 
cluster exposed by the same NameServer.
   
   ## Fix
   
   Apply the same configured-cluster scope check before resolving 
instance-scoped detail. Requests for the configured cluster continue normally; 
out-of-scope requests return no detail and are handled by the existing 
service-level unavailable response. Global cluster detail behavior remains 
unchanged.
   
   ## Testing
   
   - 
`RocketMQClusterProviderTest#refreshClusterDetailShouldRejectClusterOutsideConfiguredInstanceScope`
   - `mvn -Dmaven.compiler.proc=full 
-Dtest=RocketMQClusterProviderTest,ClusterServiceTest,ClusterControllerTest 
test` — 96 passed
   - `mvn -Dmaven.compiler.proc=full -DskipTests package` — passed
   - Checkstyle — 0 violations
   
   Fixes #4994
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to