Aias00 opened a new issue, #6517:
URL: https://github.com/apache/shenyu/issues/6517

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/shenyu/issues) and found no similar issues.
   
   ### Apache ShenYu Component
   
   shenyu-admin
   
   ### What happened
   
   `ProxySelectorAddDTO.discoveryUpstreams` is optional in the DTO; it has no 
`@NotNull` or `@NotEmpty` validation:
   
   ```java
   private List<DiscoveryUpstream> discoveryUpstreams;
   ```
   
   The create path handles this safely:
   
   ```java
   if (!CollectionUtils.isEmpty(proxySelectorAddDTO.getDiscoveryUpstreams())) {
       proxySelectorAddDTO.getDiscoveryUpstreams().forEach(...);
       ...
   }
   ```
   
   But the update path deletes existing upstream rows first and then directly 
iterates the request list without a null check:
   
   ```java
   int result = 
discoveryUpstreamMapper.deleteByDiscoveryHandlerId(discoveryHandlerId);
   LOG.info("delete discovery upstreams, count is: {}", result);
   proxySelectorAddDTO.getDiscoveryUpstreams().forEach(discoveryUpstream -> {
       DiscoveryUpstreamDO discoveryUpstreamDO = DiscoveryUpstreamDO.builder()
               ...
               .build();
       discoveryUpstreamMapper.insert(discoveryUpstreamDO);
   });
   ```
   
   If the client omits `discoveryUpstreams` or sends it as `null`, the update 
request throws `NullPointerException` after deleting the existing upstream rows 
inside the transaction. The transaction should roll back, but the API still 
returns a server error instead of treating the missing list consistently with 
the create path or rejecting it through validation.
   
   ### Expected behavior
   
   Proxy selector update should either:
   
   - validate `discoveryUpstreams` as required and return a clear validation 
error, or
   - handle null/empty lists consistently with the create path.
   
   It should not throw `NullPointerException` from 
`getDiscoveryUpstreams().forEach(...)`.
   
   ### How to reproduce
   
   1. Create a proxy selector with a discovery handler.
   2. Send a `PUT /proxy-selector/{id}` update request whose JSON body omits 
`discoveryUpstreams` or sets it to `null`.
   3. The controller accepts the DTO validation because `discoveryUpstreams` is 
not annotated as required.
   4. `ProxySelectorServiceImpl.update(...)` calls 
`proxySelectorAddDTO.getDiscoveryUpstreams().forEach(...)` and throws 
`NullPointerException`.
   
   ### Debug logs
   
   _No response_
   
   ### Environment
   
   Current `master` branch.
   
   ### Are you willing to submit a PR?
   
   - [ ] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to