Aias00 opened a new issue, #6771:
URL: https://github.com/apache/shenyu/issues/6771

   - severity: Medium
   - files: 
`shenyu-plugin/shenyu-plugin-modify-response/.../ModifyResponsePlugin.java:148-171`
   - description: In `writeWith`, `modifyBody(bytes)` is unconditionally called 
regardless of whether any body modification rules are configured. 
`JsonPath.parse(jsonValue)` is always called and `context.jsonString()` always 
re-serializes. For non-JSON responses (XML, HTML, binary), `JsonPath.parse` 
throws → `ShenyuException`.
   - impact: (a) Non-JSON responses crash the plugin even when only header 
modifications are configured. (b) Re-serialization can change whitespace/key 
ordering for valid JSON.
   - suggested_fix: Short-circuit `modifyBody` when all body-key lists are 
empty/null; add a content-type guard.
   - confidence: Medium
   - related_existing: none
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to