lll-peanut opened a new pull request, #6533:
URL: https://github.com/apache/shenyu/pull/6533

   Fixes #6474
   
     ## What's changed
     - BasicAuthPlugin.doExecute now short-circuits with ERROR_TOKEN when the
       Authorization header and URI user info are both missing, instead of 
passing
       null to the authentication strategy.
     - DefaultBasicAuthAuthenticationStrategy.authenticate now uses 
Objects.equals
       so a null credential fails authentication instead of throwing NPE.
   
     ## Why
     A request without credentials produced `authorization == null`, and the
     default strategy dereferenced it (`authentication.equals(...)`), causing a
     NullPointerException (HTTP 500) instead of the expected 401 ERROR_TOKEN.
   
     ## Tests
     - BasicAuthPluginTest.testDoExecuteWithoutAuthorization: request without
       Authorization header / user info must return Illegal authorization and 
not
       invoke the chain (failed with NPE before the fix).
     - 
DefaultBasicAuthAuthenticationStrategyTest.testAuthenticateWithNullAuthentication:
       authenticate(null) must return false, not throw.
     - `mvn -pl shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth 
test`
       → 15 tests passed.
   
     ## Manual verification
     - no credentials        → {"code":401,"message":"Illegal authorization"}
     - Authorization: test:test123 → request forwarded to upstream (200)
     - wrong credentials     → 401 Illegal authorization
   
   Make sure that:
   
   - [X ] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [X] You submit test cases (unit or integration tests) that back your 
changes.
   - [X] Your local test passed `./mvnw clean install 
-Dmaven.javadoc.skip=true`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to