Aias00 opened a new issue, #6481:
URL: https://github.com/apache/shenyu/issues/6481

   ### Current Behavior
   
   Config import accepts any nonblank `namespace` request parameter and writes 
imported records with that value as `namespace_id`, even when the namespace 
does not exist.
   
   `ConfigsExportImportController.importConfigs()` only checks that `namespace` 
is nonblank and that the file exists before calling 
`configsService.configsImport(namespace, ...)`.
   
   Several import services then stamp the raw request value onto imported rows, 
for example:
   
   - app auth import calls `appAuthDO.setNamespaceId(namespace)`
   - metadata import calls `metaDataDTO.setNamespaceId(namespace)`
   - discovery import calls `discoveryDTO.setNamespaceId(namespace)`
   
   The affected tables store `namespace_id` as a plain column, so the database 
does not prevent orphaned rows.
   
   ### Expected Behavior
   
   Config import should validate that the target namespace exists before 
importing namespace-scoped records.
   
   ### Steps to Reproduce
   
   1. Prepare a valid config export file containing namespace-scoped data such 
as auth, metadata, or discovery records.
   2. Call config import with a non-existing namespace id, for example:
   
   ```http
   POST /configs/import?namespace=ghost-ns
   ```
   
   3. The import can report success and create rows whose `namespace_id` is 
`ghost-ns`.
   
   ### Impact
   
   Invalid imports can create orphaned records that are not attached to any 
existing namespace and may be hard to manage or clean up from the admin UI.
   
   ### Code Location
   
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/controller/ConfigsExportImportController.java`
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/AppAuthServiceImpl.java`
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/MetaDataServiceImpl.java`
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/DiscoveryServiceImpl.java`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to