Aias00 opened a new issue, #6543:
URL: https://github.com/apache/shenyu/issues/6543

   ## Description
   `doRequest` builds a deduplicated copy of the request headers 
(`httpHeaders`, lines 62-63) via `duplicateHeaders(..., REQ_UNIQUE_HEADER)`. 
But the outbound request is then populated from 
`exchange.getRequest().getHeaders()` — the **original, non-deduplicated** 
headers — via `headers.addAll(exchange.getRequest().getHeaders())` (line 67). 
The `httpHeaders` variable is computed and thrown away; it is never used to 
build the request. The sibling `NettyHttpClientPlugin.java:72` correctly 
applies the deduped copy via `httpHeaders.forEach(headers::set)`.
   
   ## Location
   ```
   shenyu-plugin-httpclient/.../WebClientPlugin.java:62-67
   NettyHttpClientPlugin.java:72 (correct)
   ```
   
   ## Impact
   The "unique header" feature is silently inactive on the WebClient path while 
it works on the Netty path — inconsistent behavior depending on which HTTP 
client is configured. Upstream servers that reject duplicate headers (or pick 
the wrong value) will misbehave, and the configured retain-first/last/unique 
policy is ignored.
   
   ## Suggested fix
   In the `WebClientPlugin` headers lambda, replace 
`headers.addAll(exchange.getRequest().getHeaders())` with 
`httpHeaders.forEach(headers::set)` (mirroring `NettyHttpClientPlugin`).
   
   ## Related existing issue(s)
   #6255/#6254 (closed) were about request-template custom headers; this is the 
dedup result being discarded entirely, distinct.
   
   _Identified during the 2026-08-02 audit; full list in 
[`docs/issue-candidates-2026-08-02.md`](docs/issue-candidates-2026-08-02.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to