im47cn commented on PR #6531:
URL: https://github.com/apache/shenyu/pull/6531#issuecomment-5182348161

   Thanks @Aias00 for the thorough review. All items addressed in the latest 
push:
   
   **Should-fix #1 (IV reuse Javadoc):** Added security warning to 
`AbstractCbcCryptorStrategy` class-level Javadoc documenting that the IV is 
fixed per rule, the CBC reuse risk, and operator guidance to regenerate IVs per 
deployment/rule.
   
   **Should-fix #2 (SPI-wiring regression test):** Added 
`CryptorStrategyFactorySpiTest` that loads strategies via 
`CryptorStrategyFactory.newInstance("aes")` / `newInstance("sm4")` — exercising 
the real `ExtensionLoader.getJoin` + META-INF SPI path, not direct 
instantiation. If the SPI file or `@Join` annotation is dropped, these tests 
fail.
   
   **Nit #3 (key format divergence):** Added cross-reference in the same 
Javadoc pointing to `AesUtils` and warning against interchanging secrets.
   
   **Nit #4 (negative test coverage):** Added 3 new negative tests: AES 15-byte 
key (wrong length), SM4 18-byte key (wrong length), and non-base64 key content.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to