Aias00 opened a new issue, #6474:
URL: https://github.com/apache/shenyu/issues/6474

   ### Current Behavior
   
   The Basic Auth plugin can throw `NullPointerException` when a protected 
request does not provide credentials.
   
   `BasicAuthPlugin.doExecute()` reads the credential from the `Authorization` 
header or URI user info. If neither exists, `authorization` can be `null`, but 
it is still passed to the configured authentication strategy:
   
   ```java
   authenticationStrategy.authenticate(basicAuthRuleHandle, authorization)
   ```
   
   The default strategy then dereferences the value directly:
   
   ```java
   return authentication.equals(((DefaultBasicAuthRuleHandle) 
basicAuthRuleHandle).getAuthorization());
   ```
   
   ### Expected Behavior
   
   Missing Basic Auth credentials should fail authentication and return the 
normal `ERROR_TOKEN` response instead of throwing an internal exception.
   
   ### Steps to Reproduce
   
   1. Enable the Basic Auth plugin on a route with the default strategy.
   2. Send a request to that route without an `Authorization` header and 
without URI user info.
   3. The default strategy dereferences `authentication` and can throw 
`NullPointerException`.
   
   ### Code Location
   
   - 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java`
   - 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to