Aias00 opened a new issue, #6476:
URL: https://github.com/apache/shenyu/issues/6476
### Current Behavior
The response cryptor plugin returns the original response body unchanged
when the configured field path is missing.
For field mapping, `MapTypeEnum.FIELD.convert()` returns `null` when the
configured field cannot be parsed from the response body:
```java
String parseBody = JsonUtil.parser(originalBody, ruleHandle.getFieldNames());
if (Objects.isNull(parseBody)) {
return null;
}
```
`AbstractCryptorPlugin.convert()` treats `null` as a field-parse error and
delegates to `fieldErrorParse(...)`. For response cryptor,
`CryptorResponsePlugin.fieldErrorParse()` returns `originalBody` unchanged.
### Expected Behavior
When response encryption/decryption is configured but the target field
cannot be found, the plugin should fail closed or return a clear cryptor
configuration error instead of silently returning the unmodified body.
### Impact
If an upstream response shape changes or a configured field path is wrong,
response cryptor can silently bypass the configured response transformation and
send plaintext/unencrypted data downstream.
### Code Location
-
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/strategy/MapTypeEnum.java`
-
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/plugin/AbstractCryptorPlugin.java`
-
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/plugin/CryptorResponsePlugin.java`
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]