Aias00 opened a new issue, #6504: URL: https://github.com/apache/shenyu/issues/6504
### Search before asking - [x] I had searched in the [issues](https://github.com/apache/shenyu/issues) and found no similar issues. ### Apache ShenYu Component shenyu-sync-data-http ### What happened `AccessTokenManager` starts a periodic token refresh task with `scheduleWithFixedDelay`: ```java private void start(final List<String> servers) { this.login(servers); this.executorService.scheduleWithFixedDelay(() -> this.login(servers), 5000, 5000, TimeUnit.MILLISECONDS); } ``` But `doLogin(...)` only catches `IOException`: ```java try (Response response = this.okHttpClient.newCall(request).execute()) { ... Map<String, Object> resultMap = GsonUtils.getInstance().convertToMap(result); ... Map<String, Object> tokenMap = GsonUtils.getInstance().convertToMap(tokenJson); this.accessToken = (String) tokenMap.get(Constants.ADMIN_RESULT_TOKEN); this.tokenExpiredTime = (long) tokenMap.get(Constants.ADMIN_RESULT_EXPIRED_TIME); this.tokenRefreshWindow = this.tokenExpiredTime / 10; return true; } catch (IOException e) { LOG.error("get token from server : [{}] error", server, e); return false; } ``` Runtime exceptions from response parsing or field conversion are not caught. For example, malformed JSON from a temporary admin/proxy error page can throw a JSON parsing exception. Also `expiredTime` is read through `Map<String, Object>` and cast directly with `(long)`, so a non-`Long` numeric representation can throw `ClassCastException`. Because the exception escapes the `scheduleWithFixedDelay` task, `ScheduledThreadPoolExecutor` suppresses all future refresh executions. Once the current token expires, HTTP sync can no longer authenticate to admin until the gateway is restarted. ### Expected behavior One bad login response or conversion error should be logged and treated like a failed login attempt. The scheduled refresh task should continue retrying later servers/later intervals. The login response should also be parsed into a typed DTO or converted through `Number.longValue()` rather than directly casting `Object` to `long`. ### How to reproduce 1. Enable HTTP data sync with admin credentials. 2. Make the admin login endpoint temporarily return a malformed JSON body or a login `data.expiredTime` value that is not represented as `Long` in `Map<String, Object>`. 3. Let the refresh task run. 4. `doLogin(...)` throws a runtime exception that is not caught by the `IOException` handler. 5. The scheduled refresh task stops permanently, so token refresh never retries. ### Debug logs _No response_ ### Environment Current `master` branch. ### Are you willing to submit a PR? - [ ] Yes I am willing to submit a PR! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
