wy471x opened a new pull request, #7047:
URL: https://github.com/apache/shenyu/pull/7047

   Make sure that:
   
   - [X] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [X] You submit test cases (unit or integration tests) that back your 
changes.
   - [X] Your local test passed `./mvnw clean install 
-Dmaven.javadoc.skip=true`.
   
   ## Summary
   
   Fixes #6615. `MetaDataServiceImpl.enabledByIdsAndNamespaceId` checked 
existence with a namespace-scoped query but passed the caller-supplied raw 
`ids` to `MetaDataMapper.updateEnableBatch`, whose SQL only filters by `id IN 
(...)`. A caller scoped to one namespace could therefore enable/disable 
metadata rows that belong to another namespace.
   
   ### Changes
   
   1. `MetaDataServiceImpl.enabledByIdsAndNamespaceId` 
(`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/MetaDataServiceImpl.java:132`)
 — `updateEnableBatch` now receives only the ids of the rows returned by the 
namespace-scoped `selectByIdListAndNamespaceId` query 
(`ListUtil.map(metaDataDoList, MetaDataDO::getId)`) instead of the raw request 
ids. Mapper SQL and event publishing behavior are unchanged.
   
   ### Test Cases
   
   1. `MetaDataServiceTest.testEnabledOnlyUpdatesIdsWithinNamespace` — verifies 
that when the request contains ids belonging to another namespace but the 
scoped select returns only the current namespace's row, `updateEnableBatch` and 
`onEnabled` only receive the current namespace's id.
   
   ## Verification
   
   - `./mvnw -pl shenyu-admin clean install -Dmaven.javadoc.skip=true 
-Dtest=org.apache.shenyu.admin.service.MetaDataServiceTest 
-DfailIfNoTests=false` — BUILD SUCCESS; Tests run: 16, Failures: 0, Errors: 0, 
Skipped: 0.
   - Checkstyle: 0 violations.
   - RAT: Unapproved 0, unknown 0, generated 0.
   
   close #6615
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to