Aias00 opened a new issue, #6508: URL: https://github.com/apache/shenyu/issues/6508
### Search before asking - [x] I had searched in the [issues](https://github.com/apache/shenyu/issues) and found no similar issues. ### Apache ShenYu Component shenyu-plugin ### What happened `ContextPathPlugin` builds `realUrl` by cutting the request path at `contextPath.length()`: ```java String realURI = ""; String contextPath = handle.getContextPath(); if (StringUtils.isNoneBlank(contextPath)) { realURI = context.getPath().substring(contextPath.length()); attributes.put(Constants.CONTEXT_PATH, contextPath); } ``` There is no check that `context.getPath()` actually starts with the configured `contextPath`, or that the configured context path is not longer than the request path. This produces two failure modes: - If `contextPath` is longer than the request path, `substring(contextPath.length())` throws `StringIndexOutOfBoundsException` and the request fails. - If `contextPath` has the same/shorter length but is not a prefix, the plugin silently cuts the wrong characters and sets an incorrect `realUrl`, causing downstream routing to the wrong path. For example, with request path `/api/order` and configured `contextPath=/foo`, the plugin sets `realUrl=/order` even though `/foo` was never a prefix of the request path. ### Expected behavior `ContextPathPlugin` should only strip `contextPath` when the request path starts with that context path. If the configured context path does not match the request path, the plugin should skip rewriting or return a clear rule/configuration error instead of throwing or silently producing an incorrect `realUrl`. ### How to reproduce 1. Enable the context-path plugin. 2. Create a rule with `contextPath` that does not match the beginning of the incoming path, for example `contextPath=/foo`. 3. Send a request to `/api/order`. 4. The plugin computes `context.getPath().substring(contextPath.length())` and produces `/order`, incorrectly removing the first four characters even though `/foo` was not present. 5. If `contextPath` is longer than the request path, the same code throws `StringIndexOutOfBoundsException`. ### Debug logs _No response_ ### Environment Current `master` branch. ### Are you willing to submit a PR? - [ ] Yes I am willing to submit a PR! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
