Aias00 opened a new issue, #6511: URL: https://github.com/apache/shenyu/issues/6511
### Search before asking - [x] I had searched in the [issues](https://github.com/apache/shenyu/issues) and found no similar issues. ### Apache ShenYu Component shenyu-plugin ### What happened `LoggingConsolePlugin` stores the desensitization algorithm in a static mutable field: ```java private static String dataDesensitizeAlg = DataDesensitizeEnum.CHARACTER_REPLACE.getDataDesensitizeAlg(); ``` For every request whose logging rule enables masking, the plugin overwrites that static field from the current rule: ```java if (desensitized) { Collections.addAll(keywordSets, keywords.split(";")); dataDesensitizeAlg = Optional.ofNullable(commonLoggingRuleHandle.getMaskType()) .orElse(DataDesensitizeEnum.MD5_ENCRYPT.getDataDesensitizeAlg()); keyWordMatch = new KeyWordMatch(keywordSets); } ``` Later, when the response body is logged, the response decorator reads the same static field: ```java String responseBody = DataDesensitizeUtils.desensitizeBody(desensitized, writer.output(), keyWordMatch, dataDesensitizeAlg); ``` Because response logging happens asynchronously and after the plugin has already returned control to the chain, another concurrent request matching a different logging rule can overwrite `dataDesensitizeAlg` before the first response reaches `doFinally(...)`. The first request then logs with the second rule's masking algorithm. This makes console logs nondeterministic when different logging rules use different `maskType` values. ### Expected behavior The desensitization algorithm should be request-scoped, like `desensitized` and `keyWordMatch`. It should be captured in a local final variable and passed into `LoggingServerHttpRequest`/`LoggingServerHttpResponse` instead of being stored in a static mutable field. ### How to reproduce 1. Configure two logging-console rules with different `maskType` values. 2. Send concurrent requests matching both rules. 3. Let one response complete after the other request has entered `LoggingConsolePlugin.doExecute(...)` and overwritten `dataDesensitizeAlg`. 4. The first request's response log can be masked using the second rule's algorithm. ### Debug logs _No response_ ### Environment Current `master` branch. ### Are you willing to submit a PR? - [ ] Yes I am willing to submit a PR! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
