wy471x opened a new pull request, #7047: URL: https://github.com/apache/shenyu/pull/7047
Make sure that: - [X] You have read the [contribution guidelines](https://shenyu.apache.org/community/contributor-guide). - [X] You submit test cases (unit or integration tests) that back your changes. - [X] Your local test passed `./mvnw clean install -Dmaven.javadoc.skip=true`. ## Summary Fixes #6615. `MetaDataServiceImpl.enabledByIdsAndNamespaceId` checked existence with a namespace-scoped query but passed the caller-supplied raw `ids` to `MetaDataMapper.updateEnableBatch`, whose SQL only filters by `id IN (...)`. A caller scoped to one namespace could therefore enable/disable metadata rows that belong to another namespace. ### Changes 1. `MetaDataServiceImpl.enabledByIdsAndNamespaceId` (`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/MetaDataServiceImpl.java:132`) — `updateEnableBatch` now receives only the ids of the rows returned by the namespace-scoped `selectByIdListAndNamespaceId` query (`ListUtil.map(metaDataDoList, MetaDataDO::getId)`) instead of the raw request ids. Mapper SQL and event publishing behavior are unchanged. ### Test Cases 1. `MetaDataServiceTest.testEnabledOnlyUpdatesIdsWithinNamespace` — verifies that when the request contains ids belonging to another namespace but the scoped select returns only the current namespace's row, `updateEnableBatch` and `onEnabled` only receive the current namespace's id. ## Verification - `./mvnw -pl shenyu-admin clean install -Dmaven.javadoc.skip=true -Dtest=org.apache.shenyu.admin.service.MetaDataServiceTest -DfailIfNoTests=false` — BUILD SUCCESS; Tests run: 16, Failures: 0, Errors: 0, Skipped: 0. - Checkstyle: 0 violations. - RAT: Unapproved 0, unknown 0, generated 0. close #6615 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
