Aias00 opened a new issue, #6674:
URL: https://github.com/apache/shenyu/issues/6674

   - severity: High; files: `AppAuthServiceImpl.java:565-572` 
(`app-auth-sqlmap.xml:96-111`), `DashboardUserServiceImpl.java:289-293` 
(`dashboard-user-sqlmap.xml:66-74`), `NamespacePluginServiceImpl.java:136` 
(`namespace-plugin-rel-sqlmap.xml:74-112`), `ApiServiceImpl.java:261`, 
`MockRequestRecordServiceImpl.java:83-86` 
(`mock-request-record-sqlmap.xml:45-67`), `InstanceInfoServiceImpl.java:81-84` 
(`instance-info-sqlmap.xml:80-94`), `NamespaceServiceImpl.java:128` 
(`namespace-sqlmap.xml:191-210`), `RegistryServiceImpl.java:57` 
(`registry-sqlmap.xml:231-248`), `AiProxyApiKeyServiceImpl` (listByPage)
   - description: `PageableAspect.java:54-75` only triggers 
`PageHelper.startPage` when the invoked method is annotated `@Pageable`. These 
nine are not, so `selectByQuery` runs unbounded and `PageResultUtils` merely 
wraps the full list with the page parameter object — "fake pagination".
   - impact: Every list call materialises the entire filtered table into JVM 
heap; large tenants blow up memory and DB latency.
   - suggested_fix: Annotate each `listByPage` with `@Pageable` (matching 
`SelectorServiceImpl`/`RuleServiceImpl`/`PluginServiceImpl`), or add explicit 
`LIMIT/OFFSET` to the mappers.
   - confidence: High
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to