Skip to content

Soul Admin Service - #1

Merged
yu199195 merged 8 commits into
apache:dev-jiangxiaofengfrom
SteNicholas:dev_jiangxiaofeng
Jul 26, 2018
Merged

yu199195 merged 8 commits into
apache:dev-jiangxiaofengfrom
SteNicholas:dev_jiangxiaofeng

Conversation

@SteNicholas

Copy link
Copy Markdown
Member

No description provided.

@SteNicholas
SteNicholas changed the base branch from master to dev-jiangxiaofeng July 26, 2018 00:47
@yu199195
yu199195 merged commit 164489b into apache:dev-jiangxiaofeng Jul 26, 2018
yu199195 pushed a commit that referenced this pull request Aug 5, 2019
yu199195 pushed a commit that referenced this pull request Jul 22, 2020
yu199195 pushed a commit that referenced this pull request Aug 19, 2020
moremind added a commit that referenced this pull request Sep 8, 2023
* add dependency

* init alert notice

* init alert receiver controller api

* alert notice

* delete unused alert template

* fix pmd error

* support alarm sender in gateway plugins

* add license header

* pass pmd

* pass pmd

* bugfix error typehandler

* bugfix error unit test

* fix pmd error

* fix pmd error

* fix pmd error

* add db init table sql

* [Improve] delete alert support batch (#1)

* [Improve] delete alert support batch

* [Improve] add none arg constructor

* support send receiver test message controller

* fix pmd error

* ignore alert report auth

* add alarmLowWarning alarmMediumCritical alarmHighEmergency

* fix e2e test error

* update report url in docker-compose env

* fix test error

* fix test error

* fix test error

---------

Co-authored-by: 杨文杰 <31105009+ywj1352@users.noreply.github.com>
Co-authored-by: VampireAchao <achao1441470436@gmail.com>
Co-authored-by: moremind <hefengen@apache.org>
Aias00 added a commit that referenced this pull request Jun 16, 2026
…ermission, revert unrelated LICENSE changes

- Change /appAuth/updateSk to accept UpdateSkDTO as @RequestBody instead
  of @RequestParam, preventing appSecret from appearing in URLs, browser
  history, and server access logs (Copilot review comment #1)
- Change /sandbox/proxyGateway permission from system:authen:list to
  system:authen:modify — a write/signing endpoint should not be guarded
  by a read permission (Copilot review comment #3)
- Revert unrelated LICENSE file changes that were accidentally included
  (Copilot review comment #2 — re2j license issue is pre-existing)

Co-Authored-By: Claude <noreply@anthropic.com>
Aias00 added a commit that referenced this pull request Jul 7, 2026
…ndbox/proxyGateway (#6388)

* goalx: snapshot before shenyu-analysis

* chore(ci): optimize workflow build cache and mvnd parallelism

* chore: update LICENSE with new dependencies and versions

* [fix] Add missing permission annotations to /appAuth/updateSk and /sandbox/proxyGateway

- Add @RequiresPermissions("system:authen:edit") to AppAuthController.updateSk()
  This endpoint was the only one in the controller without a permission check,
  allowing any authenticated user to rotate arbitrary appAuth secrets.
- Change /appAuth/updateSk from GET to POST to prevent appSecret from
  appearing in URLs, browser history, and server access logs.
- Add @RequiresPermissions("system:authen:list") to SandboxController.proxyGateway()
  This endpoint generates server-side signed requests using stored appSecrets.
  Without permission checks, any authenticated user could abuse it to forge
  signed requests after compromising an appKey via the updateSk vulnerability.

These fixes address an authorization bypass where a low-privileged dashboard
user could chain updateSk + proxyGateway to impersonate arbitrary application
identities and send authenticated requests to allowlisted internal services.

Co-Authored-By: Claude <noreply@anthropic.com>

* [fix] Address PR review: use request body for updateSk, fix sandbox permission, revert unrelated LICENSE changes

- Change /appAuth/updateSk to accept UpdateSkDTO as @RequestBody instead
  of @RequestParam, preventing appSecret from appearing in URLs, browser
  history, and server access logs (Copilot review comment #1)
- Change /sandbox/proxyGateway permission from system:authen:list to
  system:authen:modify — a write/signing endpoint should not be guarded
  by a read permission (Copilot review comment #3)
- Revert unrelated LICENSE file changes that were accidentally included
  (Copilot review comment #2 — re2j license issue is pre-existing)

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: xiaoyu <xiaoyu@apache.org>
im47cn added a commit to im47cn/shenyu that referenced this pull request Aug 4, 2026
…ative test cases

Should-fix apache#1: Add Javadoc security warning on IV reuse in CBC mode,
including cross-reference to AesUtils key format divergence (nit apache#3).

Should-fix apache#2: Add CryptorStrategyFactorySpiTest that loads strategies
via CryptorStrategyFactory.newInstance() (exercising META-INF SPI +
ExtensionLoader.getJoin), not just direct instantiation.

Nit apache#4: Add negative tests for wrong byte-length keys (15-byte AES,
18-byte SM4) and non-base64 content.

apache#6531
im47cn added a commit to im47cn/shenyu that referenced this pull request Aug 6, 2026
…ative test cases

Should-fix apache#1: Add Javadoc security warning on IV reuse in CBC mode,
including cross-reference to AesUtils key format divergence (nit apache#3).

Should-fix apache#2: Add CryptorStrategyFactorySpiTest that loads strategies
via CryptorStrategyFactory.newInstance() (exercising META-INF SPI +
ExtensionLoader.getJoin), not just direct instantiation.

Nit apache#4: Add negative tests for wrong byte-length keys (15-byte AES,
18-byte SM4) and non-base64 content.

apache#6531
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants