Aias00 commented on issue #6507:
URL: https://github.com/apache/shenyu/issues/6507#issuecomment-5157897599

   Follow-up verification note (2026-08-02 audit).
   
   The underlying defect is real, but the reproduction example in this issue 
does **not** trigger it.
   
   `RequestHandle.isNotEmptyConfig()` (`RequestHandle.java:236-238`) is:
   ```java
   return header.isNotEmptyConfig() || parameter.isNotEmptyConfig() || 
cookie.isNotEmptyConfig();
   ```
   With a header-only non-empty config like 
`{"header":{"addHeaders":{"X-Test":"1"}}}`, `header.isNotEmptyConfig()` returns 
`true` and the `||` **short-circuits**, so `parameter`/`cookie` (null) are 
never dereferenced. A header-only config works fine.
   
   The NPE is actually reachable via:
   - parameter-only config (`parameter` non-null, `header == null` -> NPE on 
`header.isNotEmptyConfig()`), or
   - cookie-only config, or
   - any config where the *first* present section is null and a later section 
is non-null.
   
   Suggested correction: change the reproduction to a parameter-only or 
cookie-only handle, e.g. `{"parameter":{"addHeaders":{"X-Test":"1"}}}` (with 
`header`/`cookie` absent), which NPEs on `header.isNotEmptyConfig()`.
   
   The fix (`isNotEmptyConfig()` null-guarding each section, or initializing 
`header`/`parameter`/`cookie` to empty objects) covers all cases.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to