Aias00 opened a new issue, #6509:
URL: https://github.com/apache/shenyu/issues/6509

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-plugin
   
   ### What happened
   
   `RewritePlugin` switches to placeholder replacement whenever `replace` 
contains `{`:
   
   ```java
   rewriteUri = rewriteHandle.getReplace().contains("{")
           ? PathMatchUtils.replaceAll(rewriteHandle.getReplace(), 
rewriteHandle.getRegex().substring(rewriteHandle.getRegex().indexOf("{")),
                   rewriteUri.substring(rewriteHandle.getRegex().indexOf("{") + 
1))
           : rewriteUri.replaceAll(rewriteHandle.getRegex(), 
rewriteHandle.getReplace());
   ```
   
   This assumes `regex` also contains `{`. If the rule's `replace` contains a 
placeholder but `regex` does not, `rewriteHandle.getRegex().indexOf("{")` 
returns `-1`, and `regex.substring(-1)` throws 
`StringIndexOutOfBoundsException`.
   
   A misconfigured rewrite rule should not crash request processing with an 
unchecked substring error.
   
   ### Expected behavior
   
   The rewrite plugin should validate placeholder mode consistently. If 
`replace` contains placeholders, `regex` should also be required to contain the 
matching placeholder pattern before substring operations are performed. Invalid 
rewrite config should be rejected when the rule is saved/synced or skipped with 
a clear error instead of failing the request.
   
   ### How to reproduce
   
   1. Enable the rewrite plugin.
   2. Create a rewrite rule with a `replace` value containing `{...}` but a 
`regex` value without `{`, for example:
   
   ```json
   {
     "regex": "/api/(.*)",
     "replace": "/v1/{path}"
   }
   ```
   
   3. Send a request matching the rule.
   4. `RewritePlugin` enters placeholder mode because `replace` contains `{`, 
then calls `regex.substring(regex.indexOf("{"))` with `-1`, causing 
`StringIndexOutOfBoundsException`.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to