Aias00 opened a new issue, #6868:
URL: https://github.com/apache/shenyu/issues/6868

   ## Description
   `onResourcesCreated(BatchResourceDeletedEvent)` (line 165) calls 
`permissionMapper.deleteByResourceId(event.getDeletedIds())` and 
`onRoleDeleted` (line 174) calls 
`permissionMapper.deleteByObjectIds(event.getDeletedIds())` with no 
`CollectionUtils.isNotEmpty` guard. The mapper XMLs emit `WHERE resource_id IN 
<foreach open="(" close=")">` with no empty-collection guard, so an empty 
`deletedIds` renders `WHERE resource_id IN ()` → SQL syntax error. Other call 
sites in this service (e.g. `manageRolePermission`) guard with 
`CollectionUtils.isNotEmpty`. Also: the method at line 165 is named 
`onResourcesCreated` but handles `BatchResourceDeletedEvent` — a copy-paste 
naming defect.
   
   ## Location
   - 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/PermissionServiceImpl.java:165-167,174-177`
   - `shenyu-admin/src/main/resources/mappers/permission-sqlmap.xml:134-145`
   
   ## Impact
   A batch delete/select event with zero ids throws an unhandled SQL exception 
inside the event listener (logs a warning/stack trace; permission cleanup for 
that event is skipped).
   
   ## Suggested fix
   Guard each handler: `if (CollectionUtils.isNotEmpty(event.getDeletedIds())) 
{ permissionMapper.deleteByResourceId(event.getDeletedIds()); }`. Rename the 
line-165 method to `onResourcesDeleted`.
   
   ## Related existing
   Distinct from N18 (#6687, RegistryController/NamespaceController empty 
`IN()`) — these are event-listener call sites in `PermissionServiceImpl`, a 
different class and trigger path.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to