Skip to content

[BUG] RequestPlugin resp unique-headers condition checks the wrong strategy field #6658

Description

@Aias00
  • severity: High
  • files: shenyu-plugin/shenyu-plugin-request/src/main/java/org/apache/shenyu/plugin/request/RequestPlugin.java:70
  • description: The second if block (lines 70-73) is intended to set up response header dedup but its guard condition checks requestHandle.getRequestHeaderUniqueStrategy() (the request strategy) instead of requestHandle.getRespHeaderUniqueStrategy() (the response strategy). Copy-paste error from the block above (lines 66-69). If request strategy is non-null (default) but response strategy is explicitly null, exchange.getAttributes().put(..., null) on a ConcurrentHashMap-backed map throws NPE.
  • impact: (a) Resp dedup silently never applied when request strategy is null. (b) NPE when response strategy is null but request strategy is non-null.
  • suggested_fix: Change line 70 to Objects.nonNull(requestHandle.getRespHeaderUniqueStrategy()) && StringUtils.isNotEmpty(requestHandle.getRespUniqueHeaders()).
  • confidence: High
  • related_existing: none — [BUG] Request plugin add* operations overwrite existing values like set* #6360 is about add* overwriting; [BUG] Request plugin fails when rule handle contains only partial config sections #6507 is about partial config. This is a distinct copy-paste bug.

Identified during the 2026-08-02 deep re-scan; full list in docs/scan2-2026-08-02/00-consolidated-critical-high.md.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions