Aias00 opened a new issue, #6476:
URL: https://github.com/apache/shenyu/issues/6476

   ### Current Behavior
   
   The response cryptor plugin returns the original response body unchanged 
when the configured field path is missing.
   
   For field mapping, `MapTypeEnum.FIELD.convert()` returns `null` when the 
configured field cannot be parsed from the response body:
   
   ```java
   String parseBody = JsonUtil.parser(originalBody, ruleHandle.getFieldNames());
   if (Objects.isNull(parseBody)) {
       return null;
   }
   ```
   
   `AbstractCryptorPlugin.convert()` treats `null` as a field-parse error and 
delegates to `fieldErrorParse(...)`. For response cryptor, 
`CryptorResponsePlugin.fieldErrorParse()` returns `originalBody` unchanged.
   
   ### Expected Behavior
   
   When response encryption/decryption is configured but the target field 
cannot be found, the plugin should fail closed or return a clear cryptor 
configuration error instead of silently returning the unmodified body.
   
   ### Impact
   
   If an upstream response shape changes or a configured field path is wrong, 
response cryptor can silently bypass the configured response transformation and 
send plaintext/unencrypted data downstream.
   
   ### Code Location
   
   - 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/strategy/MapTypeEnum.java`
   - 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/plugin/AbstractCryptorPlugin.java`
   - 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/plugin/CryptorResponsePlugin.java`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to