[BUG] ProxySelectorServiceImpl.update NPE on null discoveryRel / handler / discovery
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 72/100
Research direction
Start in shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/ProxySelectorServiceImpl.java at lines 347-394 and trace the createOrUpdate PUT /{id} path. Exercise updates with an omitted discovery object and with deleted or missing discovery bindings. Done means these cases return a clear 4xx error instead of throwing an NPE.
Written by the indexing model from the issue text.
Description
- severity: Medium
- files:
shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/ProxySelectorServiceImpl.java:347-394 - description:
discoveryRelMapper.selectByProxySelectorId(proxySelectorDO.getId())(353) is dereferenced at 354;discoveryHandlerMapper.selectById(discoveryHandlerId)(355) is mutated at 358;discoveryMapper.selectById(...)(364) is mutated at 366;proxySelectorAddDTO.getDiscovery()is dereferenced at 365-368 with no null check. Reached viacreateOrUpdate(PUT/{id}). - impact: Updating a proxy selector whose binding was deleted, or omitting
discoveryin the body, throws NPE rather than a 4xx. - suggested_fix: Null-check each lookup and return a clear error.
- confidence: Medium
- related_existing: #6517 is about omitted
discoveryUpstreams; this is the omitted/missingdiscoveryand missing rel/handler/discovery derefs, a separate path.
Identified during the 2026-08-02 deep re-scan; full list in docs/scan2-2026-08-02/06-medium-tiers.md.
- Dominant language
- Java
- Stars
- 8.8k
- Forks
- 3.1k
- Avg merge
- 4d 11h
- Merged PRs (30d)
- 85
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/shenyu
-
plugin: mock priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 80/100
-
admin priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
[BUG] DivideIngressParser protocol[i++] throws AIOOBE when protocol array shorter than endpoints Openkubernetes priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
[BUG] ContextPathParser concatenates null annotation value with /** — literal null/** rule condition Openkubernetes priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
kubernetes priority: medium type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
infinispan/infinispan#18150 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
opensearch-project/k-NN#3597 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100