[BUG] RequestPlugin resp unique-headers condition checks the wrong strategy field
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 85/100
Research direction
Start in shenyu-plugin/shenyu-plugin-request/src/main/java/org/apache/shenyu/plugin/request/RequestPlugin.java around lines 66-73 and compare the request and response strategy guards. Verify the response branch uses the response strategy and add focused coverage for both null-strategy cases. Done means response deduplication follows response settings without the reported ConcurrentHashMap NPE.
Written by the indexing model from the issue text.
Description
- severity: High
- files:
shenyu-plugin/shenyu-plugin-request/src/main/java/org/apache/shenyu/plugin/request/RequestPlugin.java:70 - description: The second
ifblock (lines 70-73) is intended to set up response header dedup but its guard condition checksrequestHandle.getRequestHeaderUniqueStrategy()(the request strategy) instead ofrequestHandle.getRespHeaderUniqueStrategy()(the response strategy). Copy-paste error from the block above (lines 66-69). If request strategy is non-null (default) but response strategy is explicitly null,exchange.getAttributes().put(..., null)on a ConcurrentHashMap-backed map throws NPE. - impact: (a) Resp dedup silently never applied when request strategy is null. (b) NPE when response strategy is null but request strategy is non-null.
- suggested_fix: Change line 70 to
Objects.nonNull(requestHandle.getRespHeaderUniqueStrategy()) && StringUtils.isNotEmpty(requestHandle.getRespUniqueHeaders()). - confidence: High
- related_existing: none — #6360 is about add* overwriting; #6507 is about partial config. This is a distinct copy-paste bug.
Identified during the 2026-08-02 deep re-scan; full list in docs/scan2-2026-08-02/00-consolidated-critical-high.md.
- Dominant language
- Java
- Stars
- 8.8k
- Forks
- 3.1k
- Avg merge
- 4d 11h
- Merged PRs (30d)
- 85
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/shenyu
-
plugin: mock priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 80/100
-
admin priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
[BUG] DivideIngressParser protocol[i++] throws AIOOBE when protocol array shorter than endpoints Openkubernetes priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
[BUG] ContextPathParser concatenates null annotation value with /** — literal null/** rule condition Openkubernetes priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
kubernetes priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
infinispan/infinispan#18150 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
opensearch-project/k-NN#3597 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100