This is an automated email from the ASF dual-hosted git repository.
Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git
The following commit(s) were added to refs/heads/master by this push:
new 990aa29b63 fix: return ERROR_TOKEN when basic auth credentials are
missing (#6533)
990aa29b63 is described below
commit 990aa29b63c279e84aa8721224eafa1d1f41d2d4
Author: lll-peanut <[email protected]>
AuthorDate: Sun Aug 2 20:42:31 2026 +0800
fix: return ERROR_TOKEN when basic auth credentials are missing (#6533)
* fix: skip maven-remote-resources-plugin in CI to avoid lock contention
(#6459)
The maven-remote-resources-plugin:1.5 inherited from org.apache:apache:21
parent POM causes intermittent 'Could not acquire lock(s)' failures when
mvnd builds multiple modules in parallel. This is a known race condition
in the plugin's file-based locking mechanism.
Changes:
- Add skipRemoteResources property (default false) in root pom.xml
- Explicitly configure maven-remote-resources-plugin with skip controlled
by the property, documenting the ability to skip it
- Pass -DskipRemoteResources=true in CI builds (clean test only, does
not affect release packaging)
The plugin only injects LICENSE/NOTICE into META-INF during packaging,
which is not needed for the CI 'clean test' phase. Release builds are
unaffected as the property defaults to false.
* fix: upgrade lombok to 1.18.34 for JDK 21 compatibility in e2e tests
Lombok 1.18.24 throws NoSuchFieldError on JDK 21 when processing
@ToString/@AllArgsConstructor annotations, causing e2e test compilation
failure. Upgrade to 1.18.34 which supports JDK 21.
Co-Authored-By: Claude Opus 4.8 <[email protected]>
* fix: resolve E2E test compilation and K8s ingress websocket upstream race
condition
- Upgrade lombok from 1.18.24 to 1.18.34 for JDK 21 compatibility
fixes NoSuchFieldError in e2e test annotation processing
- Fix race condition in IngressReconciler where EndpointsReconciler
could fire before ServiceIngressCache was populated during initial
informer sync, leaving websocket selector handle as []
- Add null checks for v1Endpoints in WebSocketParser and
DivideIngressParser to prevent NPE during initial informer sync
- Fix double-increment bug in
WebSocketParser.parseDefaultWebSocketService()
* fix: return ERROR_TOKEN when basic auth credentials are missing
Signed-off-by: lll-peanut <[email protected]>
---------
Signed-off-by: lll-peanut <[email protected]>
Co-authored-by: aias00 <[email protected]>
---
.../shenyu/plugin/basic/auth/BasicAuthPlugin.java | 3 +++
.../DefaultBasicAuthAuthenticationStrategy.java | 4 +++-
.../plugin/basic/auth/BasicAuthPluginTest.java | 21 +++++++++++++++++++++
.../DefaultBasicAuthAuthenticationStrategyTest.java | 8 ++++++++
4 files changed, 35 insertions(+), 1 deletion(-)
diff --git
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
index a0ced33d56..b44f69a227 100755
---
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
+++
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPlugin.java
@@ -54,6 +54,9 @@ public class BasicAuthPlugin extends AbstractShenyuPlugin {
@Override
protected Mono<Void> doExecute(final ServerWebExchange exchange, final
ShenyuPluginChain chain, final SelectorData selector, final RuleData rule) {
String authorization =
StringUtils.defaultString(exchange.getRequest().getHeaders().getFirst(HttpHeaders.AUTHORIZATION),
exchange.getRequest().getURI().getUserInfo());
+ if (StringUtils.isBlank(authorization)) {
+ return WebFluxResultUtils.result(exchange,
ShenyuResultWrap.error(exchange, ShenyuResultEnum.ERROR_TOKEN));
+ }
BasicAuthRuleHandle basicAuthRuleHandle =
BasicAuthPluginDataHandler.CACHED_HANDLE.get().obtainHandle(CacheKeyUtils.INST.getKey(rule));
BasicAuthAuthenticationStrategy authenticationStrategy =
Optional.ofNullable(basicAuthRuleHandle).map(BasicAuthRuleHandle::getBasicAuthAuthenticationStrategy).orElse(null);
diff --git
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
index 14517c54fd..482589b74b 100755
---
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
+++
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/main/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategy.java
@@ -24,6 +24,8 @@ import org.apache.shenyu.spi.Join;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
+import java.util.Objects;
+
@Join
public class DefaultBasicAuthAuthenticationStrategy implements
BasicAuthAuthenticationStrategy {
@@ -41,6 +43,6 @@ public class DefaultBasicAuthAuthenticationStrategy
implements BasicAuthAuthenti
@Override
public boolean authenticate(final BasicAuthRuleHandle basicAuthRuleHandle,
final String authentication) {
- return authentication.equals(((DefaultBasicAuthRuleHandle)
basicAuthRuleHandle).getAuthorization());
+ return Objects.equals(authentication, ((DefaultBasicAuthRuleHandle)
basicAuthRuleHandle).getAuthorization());
}
}
diff --git
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
index b355b1afba..ca205ca882 100755
---
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
+++
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/BasicAuthPluginTest.java
@@ -32,6 +32,7 @@ import org.junit.jupiter.api.Test;
import org.springframework.context.ConfigurableApplicationContext;
import org.springframework.http.HttpHeaders;
import org.springframework.mock.http.server.reactive.MockServerHttpRequest;
+import org.springframework.mock.http.server.reactive.MockServerHttpResponse;
import org.springframework.mock.web.server.MockServerWebExchange;
import org.springframework.web.server.ServerWebExchange;
import reactor.core.publisher.Mono;
@@ -39,6 +40,7 @@ import reactor.test.StepVerifier;
import static org.mockito.ArgumentMatchers.any;
import static org.mockito.Mockito.mock;
+import static org.mockito.Mockito.never;
import static org.mockito.Mockito.verify;
import static org.mockito.Mockito.when;
@@ -132,4 +134,23 @@ public final class BasicAuthPluginTest {
.header(HttpHeaders.AUTHORIZATION, "test:test123")
.build());
}
+
+ @Test
+ public void testDoExecuteWithoutAuthorization() {
+ ruleData.setHandle("{\"authorization\":\"test:test123\"}");
+ basicAuthPluginDataHandler.handlerRule(ruleData);
+ when(this.chain.execute(any())).thenReturn(Mono.empty());
+
+ // 不带 Authorization 头、不带 URI userInfo
+ exchange =
MockServerWebExchange.from(MockServerHttpRequest.get("localhost").build());
+
+ // 修复前:这行直接抛 NullPointerException
+ Mono<Void> mono = basicAuthPlugin.doExecute(exchange, chain,
selectorData, ruleData);
+
+ StepVerifier.create(mono).expectSubscription().verifyComplete();
+ verify(chain, never()).execute(any());
+ MockServerHttpResponse response = (MockServerHttpResponse)
exchange.getResponse();
+
Assertions.assertTrue(response.getBodyAsString().block().contains("Illegal
authorization"));
+ }
+
}
diff --git
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
index 64e79cbeef..897e30b860 100755
---
a/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
+++
b/shenyu-plugin/shenyu-plugin-security/shenyu-plugin-basic-auth/src/test/java/org/apache/shenyu/plugin/basic/auth/strategy/DefaultBasicAuthAuthenticationStrategyTest.java
@@ -70,4 +70,12 @@ public class DefaultBasicAuthAuthenticationStrategyTest {
.authenticate(defaultBasicAuthRuleHandle, "test:test456"));
}
+ @Test
+ public void testAuthenticateWithNullAuthentication() {
+ String handleJson = "{\"authorization\":\"test:test123\"}";
+ DefaultBasicAuthRuleHandle defaultBasicAuthRuleHandle =
defaultBasicAuthAuthenticationStrategy.parseHandleJson(handleJson);
+
+
Assertions.assertFalse(defaultBasicAuthAuthenticationStrategy.authenticate(defaultBasicAuthRuleHandle,
null));
+ }
+
}