Aias00 opened a new issue, #6501:
URL: https://github.com/apache/shenyu/issues/6501

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-plugin
   
   ### What happened
   
   `MockPlugin` assumes every cached mock rule has a valid `httpStatusCode`:
   
   ```java
   MockHandle mockHandle = 
MockPluginHandler.CACHED_HANDLE.get().obtainHandle(CacheKeyUtils.INST.getKey(rule));
   ...
   
exchange.getResponse().setStatusCode(HttpStatus.valueOf(mockHandle.getHttpStatusCode()));
   ```
   
   But `MockHandle.httpStatusCode` is nullable and has no model-level default:
   
   ```java
   private Integer httpStatusCode;
   ```
   
   The admin plugin handle metadata also marks this field as not required while 
only providing a UI/default metadata value:
   
   ```sql
   INSERT INTO plugin_handle ... 'httpStatusCode' ... 
'{"required":"0","defaultValue":"200","rule":""}'
   ```
   
   So a rule synced or saved with a missing `httpStatusCode` produces a 
`NullPointerException` from unboxing in `HttpStatus.valueOf(...)`. An 
out-of-range value such as `999` produces `IllegalArgumentException`. In both 
cases the mock rule cannot return its configured response and the request fails 
with a gateway error instead of a controlled mock response or a validation 
error when the rule is created.
   
   ### Expected behavior
   
   Mock rules should not be able to crash request processing because of an 
absent/invalid status code. Either:
   
   - validate `httpStatusCode` as required and within a valid HTTP status range 
when the rule is saved/synced, or
   - default missing values to `200` and reject/normalize invalid values before 
calling `HttpStatus.valueOf(...)`.
   
   ### How to reproduce
   
   1. Enable the mock plugin.
   2. Create or sync a mock rule whose handle omits `httpStatusCode`, for 
example:
   
   ```json
   {"responseContent":"{\"ok\":true}"}
   ```
   
   or uses an invalid code:
   
   ```json
   {"httpStatusCode":999,"responseContent":"{\"ok\":true}"}
   ```
   
   3. Send a request matching the mock rule.
   4. The request fails because `MockPlugin` calls 
`HttpStatus.valueOf(mockHandle.getHttpStatusCode())` without a null/range check.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to