Aias00 opened a new issue, #6829:
URL: https://github.com/apache/shenyu/issues/6829

   ## Description
   `alert-receiver-sqlmap.xml` `<sql id="Base_Column_List">` lists every column 
**except** `namespace_id`. `selectAll` uses this list, so every returned 
`AlertReceiverDTO.namespaceId` is null. 
`AlertDispatchServiceImpl.matchReceiverByRules` then runs `if 
(StringUtils.isNotBlank(item.getNamespaceId())) { ... namespaceIdMatch ... }` — 
the guard is always false, so the namespace-scoping branch never executes. 
`insert` writes `namespace_id` correctly, so the data is in the DB; only the 
read path is broken.
   
   ## Location
   - `shenyu-admin/src/main/resources/mappers/alert-receiver-sqlmap.xml:53-62`
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/AlertDispatchServiceImpl.java:151,160-164`
   
   ## Impact
   A receiver with `matchAll=false` (level/label matching only) receives alerts 
from ALL namespaces — a namespace-isolation bypass in the alerting subsystem. 
Receivers intended to be namespace-scoped silently become global.
   
   ## Suggested fix
   Add `namespace_id` to `Base_Column_List` in `alert-receiver-sqlmap.xml` 
(after `levels`, before `date_created`).
   
   ## Related existing
   Distinct from PERF-A11 (#6810, `selectAll` performance) and N56 (cache 
staleness across instances). This is a correctness defect: the column is 
omitted from the projection so namespaceId is always null and the namespace 
guard is dead.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to