apache / apache/shenyu

waf plugin NEP error..

Open
#5,274 2 comments 0 reactions 0 assignees View on GitHub
type: bug
Dominant language
Java
Stars
8.8k
Forks
3.1k
Avg merge
7d 1h
Merged PRs (30d)
85

Description

### Is there an existing issue for this?

- [X] I have searched the existing issues

### Current Behavior

When the statusCode of the waf plug-in rule is empty, a NEP error may occur.

### Expected Behavior

When the statusCode of waf plugin rule is empty, 403 is used by default

### Steps To Reproduce

![image](https://github.com/apache/shenyu/assets/18380553/b502a3f8-558a-4952-a0bc-778917943d46)
![image](https://github.com/apache/shenyu/assets/18380553/3bdf5841-ccf5-473a-8d91-ebc2f493fefe)
![image](https://github.com/apache/shenyu/assets/18380553/10b6d6b3-c627-458b-824d-0cb11f9cf2b3)

### Environment

```markdown
ShenYu version(s):2.6.0
```

### Debug logs

### Anything else?

Contributor guide

No contributing guide indexed for this repository

Research direction

Locate the Java WAF plugin handling for an empty statusCode and reproduce the NEP error using the reported ShenYu 2.6.0 behavior. Add or update a regression test for an empty statusCode; done means the rule uses HTTP 403 by default without an error.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.