This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new e9654ef2ae fix(mqtt): null-safe credential comparison in 
MqttContext#isValid (#7323)
e9654ef2ae is described below

commit e9654ef2ae264a0b9c6b4b1925f177b5496d507b
Author: Sean-Walker0 <[email protected]>
AuthorDate: Sun Sep 27 13:53:15 2026 +0800

    fix(mqtt): null-safe credential comparison in MqttContext#isValid (#7323)
    
    MqttServerConfiguration initializes the static userName/password from
    config properties that default to "shenyu", but an explicitly empty
    YAML value (shenyu.mqtt.userName:) binds null. isValid then evaluates
    MqttContext.userName.equals(userName) on every CONNECT carrying
    credentials and throws NullPointerException, failing the connection
    handler instead of rejecting the login. Objects.equals compares the
    configured and incoming credentials null-safely, so an unconfigured
    server rejects every credentialed client instead of crashing.
    
    The new test fails on current master with the exact NPE and passes with
    this change.
    
    Co-authored-by: Sean-Walker0 
<[email protected]>
    Co-authored-by: aias00 <[email protected]>
---
 .../main/java/org/apache/shenyu/protocol/mqtt/MqttContext.java |  2 +-
 .../java/org/apache/shenyu/protocol/mqtt/MqttContextTest.java  | 10 ++++++++++
 2 files changed, 11 insertions(+), 1 deletion(-)

diff --git 
a/shenyu-protocol/shenyu-protocol-mqtt/src/main/java/org/apache/shenyu/protocol/mqtt/MqttContext.java
 
b/shenyu-protocol/shenyu-protocol-mqtt/src/main/java/org/apache/shenyu/protocol/mqtt/MqttContext.java
index 7ecaf06856..f6312ee66d 100644
--- 
a/shenyu-protocol/shenyu-protocol-mqtt/src/main/java/org/apache/shenyu/protocol/mqtt/MqttContext.java
+++ 
b/shenyu-protocol/shenyu-protocol-mqtt/src/main/java/org/apache/shenyu/protocol/mqtt/MqttContext.java
@@ -53,7 +53,7 @@ public class MqttContext {
             return false;
         }
 
-        return MqttContext.userName.equals(userName) && 
MqttContext.password.equals(password);
+        return Objects.equals(MqttContext.userName, userName) && 
Objects.equals(MqttContext.password, password);
     }
 
     /**
diff --git 
a/shenyu-protocol/shenyu-protocol-mqtt/src/test/java/org/apache/shenyu/protocol/mqtt/MqttContextTest.java
 
b/shenyu-protocol/shenyu-protocol-mqtt/src/test/java/org/apache/shenyu/protocol/mqtt/MqttContextTest.java
index 296c19f015..d77d90e104 100644
--- 
a/shenyu-protocol/shenyu-protocol-mqtt/src/test/java/org/apache/shenyu/protocol/mqtt/MqttContextTest.java
+++ 
b/shenyu-protocol/shenyu-protocol-mqtt/src/test/java/org/apache/shenyu/protocol/mqtt/MqttContextTest.java
@@ -126,4 +126,14 @@ public final class MqttContextTest {
         assertTrue(MqttContext.isValid(updatedUserName, 
updatedPassword.getBytes(StandardCharsets.UTF_8)));
         assertFalse(MqttContext.isValid(USER_NAME, PASSWORD_IN_BYTES));
     }
+
+    @Test
+    public void 
isValidShouldRejectRatherThanThrowWhenServerCredentialsAreUnset() {
+        // shenyu.mqtt.userName: with an empty YAML value binds null into the 
statics
+        mqttContext.setUserName(null);
+        mqttContext.setPassword(null);
+
+        assertFalse(MqttContext.isValid(USER_NAME, PASSWORD_IN_BYTES));
+        assertFalse(MqttContext.isValid("some-client", 
"some-secret".getBytes(StandardCharsets.UTF_8)));
+    }
 }

Reply via email to