Aias00 opened a new issue, #6516:
URL: https://github.com/apache/shenyu/issues/6516

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-plugin
   
   ### What happened
   
   When a namespace header is present, `ApacheDubboConfigCache` rewrites the 
Dubbo registry address in `changeRegistryAddressNamespace(...)`:
   
   ```java
   if (!currentRegistryConfig.getAddress().contains(Constants.NAMESPACE)) {
       registryConfigNew.setAddress(currentRegistryConfig.getAddress() + "?" + 
Constants.NAMESPACE + "=" + namespace);
   } else {
       String newAddress = currentRegistryConfig.getAddress().substring(0, 
currentRegistryConfig.getAddress().indexOf(Constants.NAMESPACE) + 1) + 
Constants.NAMESPACE + "=" + namespace;
       registryConfigNew.setAddress(newAddress);
   }
   ```
   
   `Constants.NAMESPACE` is the string `"namespace"`. If the existing address 
already contains a namespace query parameter, the substring keeps the first 
character of `namespace` and then appends `namespace` again.
   
   For example:
   
   ```text
   zookeeper://127.0.0.1:2181?namespace=old
   ```
   
   becomes:
   
   ```text
   zookeeper://127.0.0.1:2181?nnamespace=new
   ```
   
   The rewritten registry address is malformed. If the original address has 
additional query parameters after `namespace`, they are also dropped by the 
same substring operation.
   
   ### Expected behavior
   
   The namespace query parameter should be replaced without corrupting the 
parameter name and without discarding unrelated query parameters. Registry 
addresses should be parsed/updated as URIs or query parameter maps rather than 
by substring around the first occurrence of `"namespace"`.
   
   ### How to reproduce
   
   1. Configure the Apache Dubbo plugin registry address with an existing 
namespace parameter, for example:
   
   ```text
   zookeeper://127.0.0.1:2181?namespace=old
   ```
   
   2. Send a Dubbo gateway request with the `namespace` header set to `new`.
   3. `ApacheDubboConfigCache.changeRegistryAddressNamespace(...)` rewrites the 
address with `substring(0, indexOf("namespace") + 1) + "namespace=" + 
namespace`.
   4. The resulting address contains `?nnamespace=new`, so the Dubbo reference 
uses an invalid registry address.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to