wy471x opened a new pull request, #7039: URL: https://github.com/apache/shenyu/pull/7039
Make sure that: - You have read the contribution guidelines. - You submit test cases (unit or integration tests) that back your changes. - Your local test passed ./mvnw clean install -Dmaven.javadoc.skip=true. ## Summary Fixes #6644. When a client sends a request carrying a sessionId that no longer exists on the server (server restart, session timeout, or stale client), createSessionAndRestoreId created a new McpServerSession and StreamableHttpSessionTransport, stored them in sessions/sessionTransports, processed one request, and then left them behind forever. Unlike createTemporarySessionAndProcess, which removes the session via doFinally, the restore path had no cleanup hook, so sessions/sessionTransports/ShenyuMcpExchangeHolder grew without bound. ### Changes: - ShenyuStreamableHttpServerTransportProvider.java — createSessionAndRestoreId: add a doFinally cleanup hook that calls removeSession(actualSessionId) and ShenyuMcpExchangeHolder.remove(actualSessionId) after the request completes (success, error, or cancellation), mirroring createTemporarySessionAndProcess. - ShenyuStreamableHttpServerTransportProvider.java — createSessionAndRestoreId javadoc: document that the restore-created session is one-shot and cleaned up after the request, so unknown/stale session ids cannot leave orphaned sessions in the maps. ### Test Cases: - ShenyuStreamableHttpServerTransportProviderTest — testStaleSessionRestoreCleansUpCreatedSession: sends tools/list with a stale session id, verifies the request still succeeds, then confirms sessions/sessionTransports are empty and the ShenyuMcpExchangeHolder entry is removed after completion. A follow-up request using the returned session id is handled by a fresh restore, proving the previous restore-created session was not retained. ## Verification - shenyu-plugin-mcp-server module: ShenyuStreamableHttpServerTransportProviderTest 5 tests passed (JDK 21). - Checkstyle and RAT (license header) checks passed (mvn -pl shenyu-plugin/shenyu-plugin-mcp-server validate). - Ablation check: with the doFinally hook removed, each stale-session request left one entry behind (1 request → 1 entry, 3 requests → 3 entries); with the fix restored, both maps return to 0 entries after every request. close #6644 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
