This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 5c11a252bb fix: guard null boxed numeric fields in 
AbstractLogCollector desensitize (#6899)
5c11a252bb is described below

commit 5c11a252bb42598d4e501b104930fc912c7344d6
Author: Nikhil Ramashasthri <[email protected]>
AuthorDate: Sun Aug 16 20:48:08 2026 -0400

    fix: guard null boxed numeric fields in AbstractLogCollector desensitize 
(#6899)
    
    Co-authored-by: aias00 <[email protected]>
---
 .../common/collector/AbstractLogCollector.java     | 16 ++--
 .../common/collector/AbstractLogCollectorTest.java | 87 ++++++++++++++++++++++
 2 files changed, 98 insertions(+), 5 deletions(-)

diff --git 
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollector.java
 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollector.java
index 78f5642f5b..93274d5319 100644
--- 
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollector.java
+++ 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/main/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollector.java
@@ -186,13 +186,19 @@ public abstract class AbstractLogCollector<T extends 
AbstractLogConsumeClient<?,
         
logInfo.setTimeLocal(desensitizeForSingleWord(GenericLoggingConstant.TIME_LOCAL,
 logInfo.getTimeLocal(), keyWordMatch, desensitizedAlg));
         
logInfo.setMethod(desensitizeForSingleWord(GenericLoggingConstant.METHOD, 
logInfo.getMethod(), keyWordMatch, desensitizedAlg));
         
logInfo.setRequestUri(desensitizeForSingleWord(GenericLoggingConstant.REQUEST_URI,
 logInfo.getRequestUri(), keyWordMatch, desensitizedAlg));
-        
logInfo.setResponseContentLength(Integer.valueOf(desensitizeForSingleWord(GenericLoggingConstant.RESPONSE_CONTENT_LENGTH,
-                logInfo.getResponseContentLength().toString(), keyWordMatch, 
desensitizedAlg)));
+        if (Objects.nonNull(logInfo.getResponseContentLength())) {
+            
logInfo.setResponseContentLength(Integer.valueOf(desensitizeForSingleWord(GenericLoggingConstant.RESPONSE_CONTENT_LENGTH,
+                    logInfo.getResponseContentLength().toString(), 
keyWordMatch, desensitizedAlg)));
+        }
         
logInfo.setRpcType(desensitizeForSingleWord(GenericLoggingConstant.RPC_TYPE, 
logInfo.getRpcType(), keyWordMatch, desensitizedAlg));
-        
logInfo.setStatus(Integer.valueOf(desensitizeForSingleWord(GenericLoggingConstant.STATUS,
 logInfo.getStatus().toString(), keyWordMatch, desensitizedAlg)));
+        if (Objects.nonNull(logInfo.getStatus())) {
+            
logInfo.setStatus(Integer.valueOf(desensitizeForSingleWord(GenericLoggingConstant.STATUS,
 logInfo.getStatus().toString(), keyWordMatch, desensitizedAlg)));
+        }
         
logInfo.setUpstreamIp(desensitizeForSingleWord(GenericLoggingConstant.UP_STREAM_IP,
 logInfo.getUpstreamIp(), keyWordMatch, desensitizedAlg));
-        
logInfo.setUpstreamResponseTime(Long.valueOf(desensitizeForSingleWord(GenericLoggingConstant.UP_STREAM_RESPONSE_TIME,
-                logInfo.getUpstreamResponseTime().toString(), keyWordMatch, 
desensitizedAlg)));
+        if (Objects.nonNull(logInfo.getUpstreamResponseTime())) {
+            
logInfo.setUpstreamResponseTime(Long.valueOf(desensitizeForSingleWord(GenericLoggingConstant.UP_STREAM_RESPONSE_TIME,
+                    logInfo.getUpstreamResponseTime().toString(), 
keyWordMatch, desensitizedAlg)));
+        }
         
logInfo.setUserAgent(desensitizeForSingleWord(GenericLoggingConstant.USERAGENT, 
logInfo.getUserAgent(), keyWordMatch, desensitizedAlg));
         logInfo.setHost(desensitizeForSingleWord(GenericLoggingConstant.HOST, 
logInfo.getHost(), keyWordMatch, desensitizedAlg));
         
logInfo.setModule(desensitizeForSingleWord(GenericLoggingConstant.MODULE, 
logInfo.getModule(), keyWordMatch, desensitizedAlg));
diff --git 
a/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/test/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollectorTest.java
 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/test/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollectorTest.java
new file mode 100644
index 0000000000..fb7404b131
--- /dev/null
+++ 
b/shenyu-plugin/shenyu-plugin-logging/shenyu-plugin-logging-common/src/test/java/org/apache/shenyu/plugin/logging/common/collector/AbstractLogCollectorTest.java
@@ -0,0 +1,87 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.shenyu.plugin.logging.common.collector;
+
+import org.apache.shenyu.plugin.logging.common.client.AbstractLogConsumeClient;
+import org.apache.shenyu.plugin.logging.common.config.GenericGlobalConfig;
+import org.apache.shenyu.plugin.logging.common.constant.GenericLoggingConstant;
+import org.apache.shenyu.plugin.logging.common.entity.ShenyuRequestLog;
+import 
org.apache.shenyu.plugin.logging.desensitize.api.enums.DataDesensitizeEnum;
+import org.apache.shenyu.plugin.logging.desensitize.api.matcher.KeyWordMatch;
+import org.junit.jupiter.api.Test;
+
+import java.util.Collections;
+import java.util.HashSet;
+import java.util.Set;
+
+import static org.junit.jupiter.api.Assertions.assertDoesNotThrow;
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertNotEquals;
+import static org.junit.jupiter.api.Assertions.assertNull;
+
+/**
+ * The Test Case For AbstractLogCollector.
+ */
+public class AbstractLogCollectorTest {
+
+    private final AbstractLogCollector<AbstractLogConsumeClient<?, 
ShenyuRequestLog>, ShenyuRequestLog, GenericGlobalConfig> collector =
+            new AbstractLogCollector<>() {
+                @Override
+                protected AbstractLogConsumeClient<?, ShenyuRequestLog> 
getLogConsumeClient() {
+                    return null;
+                }
+
+                @Override
+                protected GenericGlobalConfig getLogCollectConfig() {
+                    return null;
+                }
+
+                @Override
+                protected void desensitizeLog(final ShenyuRequestLog log, 
final KeyWordMatch keyWordMatch, final String desensitizeAlg) {
+                }
+            };
+
+    @Test
+    public void testDesensitizeToleratesNullBoxedNumericFields() {
+        // a chunked byte-type response reaches desensitize with 
responseContentLength,
+        // status and upstreamResponseTime unset (LoggingServerHttpResponse 
passes a null
+        // writer for byte media and only sets status once the status code is 
committed)
+        ShenyuRequestLog log = new ShenyuRequestLog();
+        log.setClientIp("192.168.1.1");
+        KeyWordMatch keyWordMatch = new KeyWordMatch(new 
HashSet<>(Collections.singletonList(GenericLoggingConstant.CLIENT_IP)));
+        assertDoesNotThrow(() -> collector.desensitize(log, keyWordMatch, 
DataDesensitizeEnum.CHARACTER_REPLACE.getDataDesensitizeAlg()));
+        assertNull(log.getResponseContentLength());
+        assertNull(log.getStatus());
+        assertNull(log.getUpstreamResponseTime());
+        assertNotEquals("192.168.1.1", log.getClientIp());
+    }
+
+    @Test
+    public void testDesensitizePreservesPopulatedNumericFields() {
+        ShenyuRequestLog log = new ShenyuRequestLog();
+        log.setClientIp("192.168.1.1");
+        log.setResponseContentLength(1024);
+        log.setStatus(200);
+        log.setUpstreamResponseTime(15L);
+        Set<String> keyWords = new 
HashSet<>(Collections.singletonList(GenericLoggingConstant.CLIENT_IP));
+        collector.desensitize(log, new KeyWordMatch(keyWords), 
DataDesensitizeEnum.CHARACTER_REPLACE.getDataDesensitizeAlg());
+        assertEquals(1024, log.getResponseContentLength());
+        assertEquals(200, log.getStatus());
+        assertEquals(15L, log.getUpstreamResponseTime());
+    }
+}

Reply via email to