Aias00 opened a new issue, #6466: URL: https://github.com/apache/shenyu/issues/6466
### Is there an existing issue for this? - [x] I have searched the existing issues ### Current Behavior `/discovery-upstream` accepts `DiscoveryUpstreamDTO.discoveryHandlerId` with only `@NotBlank` validation. It does not verify that the referenced discovery handler exists. The create path inserts the row first and then refreshes discovery data: ```java discoveryUpstreamMapper.insert(discoveryUpstreamDO); fetchAll(discoveryUpstreamDTO.getDiscoveryHandlerId()); ``` `fetchAll(...)` then dereferences the handler returned by `discoveryHandlerMapper.selectById(discoveryHandlerId)` without a null check: ```java DiscoveryHandlerDO discoveryHandlerDO = discoveryHandlerMapper.selectById(discoveryHandlerId); ... SelectorDO selectorDO = selectorMapper.selectByDiscoveryHandlerId(discoveryHandlerDO.getId()); ... DiscoveryDO discoveryDO = discoveryMapper.selectById(discoveryHandlerDO.getDiscoveryId()); ``` The `discovery_upstream` schema has a unique key on `(discovery_handler_id, upstream_url)`, but no foreign key to `discovery_handler`. Therefore a request with a non-existent `discoveryHandlerId` can insert an orphan upstream row and then fail with a server error during refresh. ### Expected Behavior `discoveryHandlerId` should be validated before insert/update, or `fetchAll(...)` should fail gracefully before data is persisted. If the handler does not exist, the API should return a validation error and should not leave a broken `discovery_upstream` row behind. ### Steps To Reproduce 1. Call `POST /discovery-upstream` with a valid `namespaceId`, valid URL/status/weight fields, but a `discoveryHandlerId` that does not exist. 2. The DTO passes validation because `discoveryHandlerId` is nonblank. 3. `DiscoveryUpstreamServiceImpl#create(...)` inserts the row. 4. `fetchAll(...)` dereferences a null `DiscoveryHandlerDO`, returning a 500 and leaving inconsistent data. ### Environment ```markdown ShenYu version(s): current master ``` ### Debug logs _No response_ ### Anything else? Relevant current-master files: - `shenyu-admin/src/main/java/org/apache/shenyu/admin/model/dto/DiscoveryUpstreamDTO.java` - `shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/DiscoveryUpstreamController.java` - `shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/DiscoveryUpstreamServiceImpl.java` - `db/init/mysql/schema.sql` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
