Aias00 commented on issue #6507:
URL: https://github.com/apache/shenyu/issues/6507#issuecomment-5157897599
Follow-up verification note (2026-08-02 audit).
The underlying defect is real, but the reproduction example in this issue
does **not** trigger it.
`RequestHandle.isNotEmptyConfig()` (`RequestHandle.java:236-238`) is:
```java
return header.isNotEmptyConfig() || parameter.isNotEmptyConfig() ||
cookie.isNotEmptyConfig();
```
With a header-only non-empty config like
`{"header":{"addHeaders":{"X-Test":"1"}}}`, `header.isNotEmptyConfig()` returns
`true` and the `||` **short-circuits**, so `parameter`/`cookie` (null) are
never dereferenced. A header-only config works fine.
The NPE is actually reachable via:
- parameter-only config (`parameter` non-null, `header == null` -> NPE on
`header.isNotEmptyConfig()`), or
- cookie-only config, or
- any config where the *first* present section is null and a later section
is non-null.
Suggested correction: change the reproduction to a parameter-only or
cookie-only handle, e.g. `{"parameter":{"addHeaders":{"X-Test":"1"}}}` (with
`header`/`cookie` absent), which NPEs on `header.isNotEmptyConfig()`.
The fix (`isNotEmptyConfig()` null-guarding each section, or initializing
`header`/`parameter`/`cookie` to empty objects) covers all cases.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]