Aias00 opened a new issue, #6868:
URL: https://github.com/apache/shenyu/issues/6868
## Description
`onResourcesCreated(BatchResourceDeletedEvent)` (line 165) calls
`permissionMapper.deleteByResourceId(event.getDeletedIds())` and
`onRoleDeleted` (line 174) calls
`permissionMapper.deleteByObjectIds(event.getDeletedIds())` with no
`CollectionUtils.isNotEmpty` guard. The mapper XMLs emit `WHERE resource_id IN
<foreach open="(" close=")">` with no empty-collection guard, so an empty
`deletedIds` renders `WHERE resource_id IN ()` → SQL syntax error. Other call
sites in this service (e.g. `manageRolePermission`) guard with
`CollectionUtils.isNotEmpty`. Also: the method at line 165 is named
`onResourcesCreated` but handles `BatchResourceDeletedEvent` — a copy-paste
naming defect.
## Location
-
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/PermissionServiceImpl.java:165-167,174-177`
- `shenyu-admin/src/main/resources/mappers/permission-sqlmap.xml:134-145`
## Impact
A batch delete/select event with zero ids throws an unhandled SQL exception
inside the event listener (logs a warning/stack trace; permission cleanup for
that event is skipped).
## Suggested fix
Guard each handler: `if (CollectionUtils.isNotEmpty(event.getDeletedIds()))
{ permissionMapper.deleteByResourceId(event.getDeletedIds()); }`. Rename the
line-165 method to `onResourcesDeleted`.
## Related existing
Distinct from N18 (#6687, RegistryController/NamespaceController empty
`IN()`) — these are event-listener call sites in `PermissionServiceImpl`, a
different class and trigger path.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]