Aias00 opened a new issue, #6469:
URL: https://github.com/apache/shenyu/issues/6469

   ### Current Behavior
   
   `/shenyu-client/register-apiDoc` accepts `ApiDocRegisterDTO` without 
validating that `eventType` is present. The DTO field is nullable, but 
`RegisterApiDocServiceImpl.registerApiDocument()` calls 
`apiDocRegisterDTO.getEventType().equals(...)` directly:
   
   ```java
   if (apiDocRegisterDTO.getEventType().equals(EventType.REGISTER)) {
       ...
   } else if (apiDocRegisterDTO.getEventType().equals(EventType.OFFLINE)) {
       ...
   }
   ```
   
   If a client sends an API doc registration payload without `eventType`, the 
admin side can throw `NullPointerException` while processing the registration 
event.
   
   ### Expected Behavior
   
   The register API should either reject the request with a clear validation 
error when `eventType` is missing, or handle a missing/unknown event type 
without throwing an internal exception.
   
   ### Steps to Reproduce
   
   1. Send a request to the API doc registration endpoint without `eventType`, 
for example:
   
   ```http
   POST /shenyu-client/register-apiDoc
   Content-Type: application/json
   
   {
     "rpcType": "http",
     "contextPath": "/demo",
     "apiPath": "/demo/test"
   }
   ```
   
   2. The controller publishes the DTO without validation.
   3. The API doc registration service dereferences `getEventType()` and can 
throw `NullPointerException`.
   
   ### Code Location
   
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/ShenyuClientHttpRegistryController.java`
     - `registerApiDoc()` publishes the request body directly.
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/manager/impl/RegisterApiDocServiceImpl.java`
     - `registerApiDocument()` calls 
`apiDocRegisterDTO.getEventType().equals(...)`.
   - 
`shenyu-register-center/shenyu-register-common/src/main/java/org/apache/shenyu/register/common/dto/ApiDocRegisterDTO.java`
     - `eventType` is nullable and has no validation annotation.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to