Sean-Walker0 opened a new pull request, #7333:
URL: https://github.com/apache/shenyu/pull/7333

   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   Found by code audit (no existing issue — happy to file one if maintainers 
prefer).
   
   `SwaggerImportServiceImpl#buildShenyuMcpTool` loops over 
`pathItem.readOperationsMap()` but puts every tool into **one** `HashMap` keyed 
by the bare `fullPath` — the key ignores the HTTP method, so each operation of 
a multi-method path overwrites the previous one and only the **last** method 
survives as an MCP tool. A standard OpenAPI path with `GET` + `POST` on 
`/users` yields exactly one tool; the others are silently dropped before 
registration. The outer container is already a `List<Map<String, 
ShenyuMcpTool>>` (multiple entries per selector anticipated), and the tools are 
intentionally per-operation — `tool.setMethod(httpMethod.name().toLowerCase())` 
two lines above — confirming each operation is meant to become its own tool.
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [x] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [x] You submit test cases (unit or integration tests) that back your 
changes.
   - [x] Your local test passed `./mvnw test -pl shenyu-admin -am and ./mvnw 
checkstyle:check -pl shenyu-admin` (module-scoped; full build left to CI).
   
   ### Modifications
   
   - Move the map creation inside the operation loop: each operation now adds 
its own single-entry map (`fullPath` → tool) to the list. The downstream 
generator (`buildMcpToolRegisterDTO`) still receives the path as the entry key 
— no signature or data-shape change, just no overwriting.
   
   ### Verifying this change
   
   - New `buildShenyuMcpToolKeepsEveryHttpMethodOfTheSamePath` (reflection on 
the private method, following the file's existing test patterns) builds an 
OpenAPI path with `get`+`post` and asserts **2** tools with methods `{get, 
post}` survive. It fails on current master with `expected: <2> but was: <1>` 
and passes with this change.
   - Full `shenyu-admin` module suite green (502 test classes); checkstyle 
green.
   
   ### Notes
   
   - Behavior change: Swagger/OpenAPI import now registers one MCP tool per 
operation instead of silently keeping only the last HTTP method of each path.
   - Orthogonal to open PRs: no open PR touches `SwaggerImportServiceImpl` 
(checked against the file lists of all 185 open PRs).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to