Aias00 opened a new issue, #6507:
URL: https://github.com/apache/shenyu/issues/6507

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-plugin
   
   ### What happened
   
   `RequestPlugin` calls `requestHandle.isEmptyConfig()` before applying 
request mutations:
   
   ```java
   if (requestHandle.isEmptyConfig()) {
       LOG.warn("request handler configuration is empty:{}", requestHandle);
       return chain.execute(exchange);
   }
   ```
   
   `RequestHandle.isEmptyConfig()` delegates to `isNotEmptyConfig()`, which 
dereferences all three nested config sections without null checks:
   
   ```java
   private boolean isNotEmptyConfig() {
       return header.isNotEmptyConfig() || parameter.isNotEmptyConfig() || 
cookie.isNotEmptyConfig();
   }
   ```
   
   But `header`, `parameter`, and `cookie` are nullable fields. A valid partial 
request rule can configure only headers, only parameters, or only cookies. In 
those cases the first missing section causes a `NullPointerException` before 
the plugin applies the configured mutation.
   
   Example handle that should be valid but fails because `parameter` and 
`cookie` are null:
   
   ```json
   {
     "header": {
       "addHeaders": {"X-Test":"1"}
     }
   }
   ```
   
   The plugin should apply the header change, but 
`RequestHandle.isNotEmptyConfig()` evaluates `parameter.isNotEmptyConfig()` 
after the header check if the first section is empty, or immediately fails when 
`header` itself is absent for parameter/cookie-only config.
   
   ### Expected behavior
   
   The request plugin should treat missing nested sections as empty. 
`isNotEmptyConfig()` should check each section for null before calling its 
`isNotEmptyConfig()` method, so partial request mutation configurations work 
correctly.
   
   ### How to reproduce
   
   1. Enable the request plugin.
   2. Create a request plugin rule whose handle contains only one of `header`, 
`parameter`, or `cookie` sections.
   3. Send a request matching the rule.
   4. The request fails with `NullPointerException` from 
`RequestHandle.isNotEmptyConfig()` instead of applying the configured mutation.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to