This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 990aa29b63  fix: return ERROR_TOKEN when basic auth credentials are 
missing (#6533)
990aa29b63 is described below

commit 990aa29b63c279e84aa8721224eafa1d1f41d2d4
Author: lll-peanut <[email protected]>
AuthorDate: Sun Aug 2 20:42:31 2026 +0800

     fix: return ERROR_TOKEN when basic auth credentials are missing (#6533)
    
    * fix: skip maven-remote-resources-plugin in CI to avoid lock contention 
(#6459)
    
      The maven-remote-resources-plugin:1.5 inherited from org.apache:apache:21
      parent POM causes intermittent 'Could not acquire lock(s)' failures when
      mvnd builds multiple modules in parallel. This is a known race condition
      in the plugin's file-based locking mechanism.
    
      Changes:
      - Add skipRemoteResources property (default false) in root pom.xml
      - Explicitly configure maven-remote-resources-plugin with skip controlled
        by the property, documenting the ability to skip it
      - Pass -DskipRemoteResources=true in CI builds (clean test only, does
        not affect release packaging)
    
      The plugin only injects LICENSE/NOTICE into META-INF during packaging,
      which is not needed for the CI 'clean test' phase. Release builds are
      unaffected as the property defaults to false.
    
    * fix: upgrade lombok to 1.18.34 for JDK 21 compatibility in e2e tests
    
      Lombok 1.18.24 throws NoSuchFieldError on JDK 21 when processing
      @ToString/@AllArgsConstructor annotations, causing e2e test compilation
      failure. Upgrade to 1.18.34 which supports JDK 21.
    
      Co-Authored-By: Claude Opus 4.8 <[email protected]>
    
    * fix: resolve E2E test compilation and K8s ingress websocket upstream race 
condition
    
      - Upgrade lombok from 1.18.24 to 1.18.34 for JDK 21 compatibility
        fixes NoSuchFieldError in e2e test annotation processing
    
      - Fix race condition in IngressReconciler where EndpointsReconciler
        could fire before ServiceIngressCache was populated during initial
        informer sync, leaving websocket selector handle as []
    
      - Add null checks for v1Endpoints in WebSocketParser and
        DivideIngressParser to prevent NPE during initial informer sync
    
      - Fix double-increment bug in 
WebSocketParser.parseDefaultWebSocketService()
    
    * fix: return ERROR_TOKEN when basic auth credentials are missing
    
    Signed-off-by: lll-peanut <[email protected]>
    
    ---------
    
    Signed-off-by: lll-peanut <[email protected]>
    Co-authored-by: aias00 <[email protected]>
---
 .../shenyu/plugin/basic/auth/BasicAuthPlugin.java   |  3 +++
 .../DefaultBasicAuthAuthenticationStrategy.java     |  4 +++-
 .../plugin/basic/auth/BasicAuthPluginTest.java      | 21 +++++++++++++++++++++
 .../DefaultBasicAuthAuthenticationStrategyTest.java |  8 ++++++++
 4 files changed, 35 insertions(+), 1 deletion(-)

diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
index a0ced33d56..b44f69a227 100755
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
@@ -54,6 +54,9 @@ public class BasicAuthPlugin extends AbstractShenyuPlugin {
     @Override
     protected Mono<Void> doExecute(final ServerWebExchange exchange, final 
ShenyuPluginChain chain, final SelectorData selector, final RuleData rule) {
         String authorization = 
StringUtils.defaultString(exchange.getRequest().getHeaders().getFirst(HttpHeaders.AUTHORIZATION),
 exchange.getRequest().getURI().getUserInfo());
+        if (StringUtils.isBlank(authorization)) {
+            return WebFluxResultUtils.result(exchange, 
ShenyuResultWrap.error(exchange, ShenyuResultEnum.ERROR_TOKEN));
+        }
         BasicAuthRuleHandle basicAuthRuleHandle = 
BasicAuthPluginDataHandler.CACHED_HANDLE.get().obtainHandle(CacheKeyUtils.INST.getKey(rule));
         BasicAuthAuthenticationStrategy authenticationStrategy = 
Optional.ofNullable(basicAuthRuleHandle).map(BasicAuthRuleHandle::getBasicAuthAuthenticationStrategy).orElse(null);
 
diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
index 14517c54fd..482589b74b 100755
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
@@ -24,6 +24,8 @@ import org.apache.shenyu.spi.Join;
 import org.slf4j.Logger;
 import org.slf4j.LoggerFactory;
 
+import java.util.Objects;
+
 @Join
 public class DefaultBasicAuthAuthenticationStrategy implements 
BasicAuthAuthenticationStrategy {
 
@@ -41,6 +43,6 @@ public class DefaultBasicAuthAuthenticationStrategy 
implements BasicAuthAuthenti
 
     @Override
     public boolean authenticate(final BasicAuthRuleHandle basicAuthRuleHandle, 
final String authentication) {
-        return authentication.equals(((DefaultBasicAuthRuleHandle) 
basicAuthRuleHandle).getAuthorization());
+        return Objects.equals(authentication, ((DefaultBasicAuthRuleHandle) 
basicAuthRuleHandle).getAuthorization());
     }
 }
diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
index b355b1afba..ca205ca882 100755
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
@@ -32,6 +32,7 @@ import org.junit.jupiter.api.Test;
 import org.springframework.context.ConfigurableApplicationContext;
 import org.springframework.http.HttpHeaders;
 import org.springframework.mock.http.server.reactive.MockServerHttpRequest;
+import org.springframework.mock.http.server.reactive.MockServerHttpResponse;
 import org.springframework.mock.web.server.MockServerWebExchange;
 import org.springframework.web.server.ServerWebExchange;
 import reactor.core.publisher.Mono;
@@ -39,6 +40,7 @@ import reactor.test.StepVerifier;
 
 import static org.mockito.ArgumentMatchers.any;
 import static org.mockito.Mockito.mock;
+import static org.mockito.Mockito.never;
 import static org.mockito.Mockito.verify;
 import static org.mockito.Mockito.when;
 
@@ -132,4 +134,23 @@ public final class BasicAuthPluginTest {
                 .header(HttpHeaders.AUTHORIZATION, "test:test123")
                 .build());
     }
+
+    @Test
+    public void testDoExecuteWithoutAuthorization() {
+        ruleData.setHandle("{\"authorization\":\"test:test123\"}");
+        basicAuthPluginDataHandler.handlerRule(ruleData);
+        when(this.chain.execute(any())).thenReturn(Mono.empty());
+
+        // 不带 Authorization 头、不带 URI userInfo
+        exchange = 
MockServerWebExchange.from(MockServerHttpRequest.get("localhost").build());
+
+        // 修复前:这行直接抛 NullPointerException
+        Mono<Void> mono = basicAuthPlugin.doExecute(exchange, chain, 
selectorData, ruleData);
+
+        StepVerifier.create(mono).expectSubscription().verifyComplete();
+        verify(chain, never()).execute(any());
+        MockServerHttpResponse response = (MockServerHttpResponse) 
exchange.getResponse();
+        
Assertions.assertTrue(response.getBodyAsString().block().contains("Illegal 
authorization"));
+    }
+
 }
diff --git 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
index 64e79cbeef..897e30b860 100755
--- 
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
+++ 
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
@@ -70,4 +70,12 @@ public class DefaultBasicAuthAuthenticationStrategyTest {
             .authenticate(defaultBasicAuthRuleHandle, "test:test456"));
     }
 
+    @Test
+    public void testAuthenticateWithNullAuthentication() {
+        String handleJson = "{\"authorization\":\"test:test123\"}";
+        DefaultBasicAuthRuleHandle defaultBasicAuthRuleHandle = 
defaultBasicAuthAuthenticationStrategy.parseHandleJson(handleJson);
+
+        
Assertions.assertFalse(defaultBasicAuthAuthenticationStrategy.authenticate(defaultBasicAuthRuleHandle,
 null));
+    }
+
 }

Reply via email to