wy471x opened a new pull request, #7007:
URL: https://github.com/apache/shenyu/pull/7007

   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [X] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [X] You submit test cases (unit or integration tests) that back your 
changes.
   - [X] Your local test passed `./mvnw clean install 
-Dmaven.javadoc.skip=true`.
   
   ## Summary
   
   ### Changes:
   
   1. `discovery-sqlmap.xml` — added `AND namespace_id = #{namespaceId, 
jdbcType=VARCHAR}` to the WHERE clauses of `update` (:217), `updateSelective` 
(:248) and `delete` (:254), so discovery mutations are scoped to the caller's 
namespace; `delete` now takes `(id, namespaceId)` parameters.
   2. `DiscoveryMapper.java:134` — `delete(String id)` changed to 
`delete(@Param("id") String id, @Param("namespaceId") String namespaceId)`.
   3. `DiscoveryServiceImpl.java:192-206` — `delete` accepts `namespaceId` and 
verifies the selected `DiscoveryDO` belongs to the requested namespace before 
invoking the discovery processor, so cross-namespace ids produce no registry 
side effects (also fixes a potential NPE when the id does not exist); the 
mapper delete is then called with the scoped predicate.
   4. `SelectorServiceImpl.java:332` / `ProxySelectorServiceImpl.java:184` — 
internal cleanup paths pass `discoveryDO.getNamespaceId()` (the DO is freshly 
loaded from DB, so the value is authoritative).
   5. `DiscoveryController.java` — `DELETE /discovery/{discoveryId}` now 
requires a `namespaceId` request parameter (validated via 
`@Existed(NamespaceMapper)`); added 
`@RequiresPermissions("system:plugin:edit")` to `insertOrUpdate` and 
`@RequiresPermissions("system:plugin:delete")` to `delete`, consistent with the 
Selector/Rule controllers.
   
   ### Test Cases:
   
   - `DiscoveryMapperTest` — H2 integration tests: 
`delete`/`update`/`updateSelective` with a mismatched namespace mutate 0 rows; 
with a matching namespace they mutate only the target row and leave the other 
namespace's row intact.
   - `DiscoveryServiceImplTest` — delete succeeds in the matching namespace; 
throws `ShenyuException` with no processor/mapper side effects on namespace 
mismatch or when the discovery does not exist.
   
   ## Verification
   
   - `./mvnw clean install -Dmaven.javadoc.skip=true` passed locally (JDK 21).
   - Targeted tests: 23 run, 0 failures (`DiscoveryMapperTest`, 
`DiscoveryServiceImplTest`, `SelectorServiceTest`, `ProxySelectorServiceTest`).
   - `checkstyle:check` passed.
   
   Note: the dashboard frontend (apache/shenyu-dashboard) currently calls 
`DELETE /discovery/{id}` without a `namespaceId`; a follow-up in that 
repository is needed to pass the current namespace.
   
   close #6827
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to