This is an automated email from the ASF dual-hosted git repository.
Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git
The following commit(s) were added to refs/heads/master by this push:
new f158c08c09 Require permission for namespace plugin sync (#6384)
f158c08c09 is described below
commit f158c08c09992554b2912f9978cb35c3096caf89
Author: aias00 <[email protected]>
AuthorDate: Tue Jul 7 11:46:27 2026 +0800
Require permission for namespace plugin sync (#6384)
* goalx: snapshot before shenyu-analysis
* chore(ci): optimize workflow build cache and mvnd parallelism
* Require authorization for plugin data sync
The namespace plugin sync endpoint can publish uploaded plugin JAR data to
connected gateway nodes, so it needs the same plugin modify permission already
required by the bulk sync path. This adds the missing method-level Shiro
permission and locks the contract with a focused controller regression test.
Constraint: Existing Shiro method authorization depends on
@RequiresPermissions annotations.
Rejected: Add a new permission name | existing syncPluginAll already uses
system:plugin:modify for the same operation family.
Confidence: high
Scope-risk: narrow
Directive: Keep single-plugin and bulk plugin sync endpoints on equivalent
plugin sync permissions.
Tested: ./mvnw -pl shenyu-admin -Dskip.checkstyle=true -DskipLicense=true
-Dspotless.check.skip=true -Djacoco.skip=true
-Dtest=NamespacePluginControllerTest test -q
Tested: ./mvnw -pl shenyu-admin -Dskip.checkstyle=true -DskipLicense=true
-Dspotless.check.skip=true -Djacoco.skip=true
-Dtest=NamespacePluginControllerTest,DataPermissionControllerTest,SelectorControllerTest
test -q
Tested: ./mvnw -pl shenyu-admin -Dskip.checkstyle=true -DskipLicense=true
-Dspotless.check.skip=true -Djacoco.skip=true test -q
Tested: ./mvnw -pl shenyu-admin -DskipTests -Djacoco.skip=true verify -q
Not-tested: End-to-end admin login and WebSocket sync against a running
bootstrap.
---
.../controller/NamespacePluginController.java | 1 +
.../controller/NamespacePluginControllerTest.java | 49 ++++++++++++++++++++++
2 files changed, 50 insertions(+)
diff --git
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespacePluginController.java
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespacePluginController.java
index aba4a2eda4..86eef6b124 100644
---
a/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespacePluginController.java
+++
b/shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/NamespacePluginController.java
@@ -222,6 +222,7 @@ public class NamespacePluginController implements
PagedController<NamespacePlugi
* @return {@linkplain ShenyuAdminResult}
*/
@PutMapping("/syncPluginData")
+ @RequiresPermissions("system:plugin:modify")
public ShenyuAdminResult syncPluginData(@RequestParam("id") final String
id) {
return ShenyuAdminResult.success(syncDataService.syncPluginData(id) ?
ShenyuResultMessage.SYNC_SUCCESS : ShenyuResultMessage.SYNC_FAIL);
}
diff --git
a/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/NamespacePluginControllerTest.java
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/NamespacePluginControllerTest.java
new file mode 100644
index 0000000000..68f75b7d60
--- /dev/null
+++
b/shenyu-admin/src/test/java/org/apache/shenyu/admin/controller/NamespacePluginControllerTest.java
@@ -0,0 +1,49 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.shenyu.admin.controller;
+
+import org.apache.shiro.authz.annotation.RequiresPermissions;
+import org.junit.jupiter.api.Test;
+import org.springframework.core.annotation.AnnotationUtils;
+
+import java.lang.reflect.Method;
+import java.util.Objects;
+
+import static org.junit.jupiter.api.Assertions.assertArrayEquals;
+import static org.junit.jupiter.api.Assertions.assertNotNull;
+
+/**
+ * Test cases for {@link NamespacePluginController}.
+ */
+public final class NamespacePluginControllerTest {
+
+ @Test
+ public void shouldRequireModifyPermissionForSyncPluginData() throws
NoSuchMethodException {
+
assertPermissions(NamespacePluginController.class.getMethod("syncPluginData",
String.class),
+ "system:plugin:modify");
+ }
+
+ private void assertPermissions(final Method method, final String...
expectedPermissions) {
+ RequiresPermissions permissions =
AnnotationUtils.findAnnotation(method, RequiresPermissions.class);
+ if (Objects.isNull(permissions)) {
+ permissions =
AnnotationUtils.findAnnotation(method.getDeclaringClass(),
RequiresPermissions.class);
+ }
+ assertNotNull(permissions, method.getName() + " should declare
@RequiresPermissions");
+ assertArrayEquals(expectedPermissions, permissions.value(),
method.getName() + " should declare the expected permissions");
+ }
+}