fix: preserve plus signs in param flow rules - #3628
Open
hutiefang76 wants to merge 1 commit into
Open
Conversation
hutiefang76
force-pushed
the
codex/sentinel-3505-param-plus
branch
from
June 27, 2026 02:44
cc5a35d to
69614d6
Compare
oss-sentinel-ai
approved these changes
Sep 3, 2026
oss-sentinel-ai
left a comment
There was a problem hiding this comment.
Summary
LGTM. Both bundled transports (simple-http HttpEventTask and netty-http HttpServerHandler via QueryStringDecoder) already URL-decode request parameters, so the handler-level decode was double-decoding and corrupting + in hot-param values. Removing it fixes the issue, and the test covers it.
Cross-handler Note
ModifyRulesCommandHandler (flow rules, sentinel-transport-common) still applies the same handler-level URLDecoder.decode and likely has the same double-decode behavior — worth a follow-up PR if you are interested.
Automated review by github-manager-bot
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Describe what this PR does / why we need it
When setting hotspot parameter flow rules through
setParamFlowRules, values containing a literal plus sign are currently decoded twice. The HTTP command layer already decodes request parameters before they reachCommandRequest, so decodingdataagain changes+into a space and alters the configured hotspot item value.Does this pull request fix one issue?
Fixes #3505
Describe how you did it
Removed the extra
URLDecoder.decode(...)call fromModifyParamFlowRulesCommandHandlerand added a regression test that submits already-decoded rule JSON with a hotspot item value ofa+b.Describe how to verify it
JAVA_HOME=$(/usr/libexec/java_home -v 17) mvn -pl sentinel-extension/sentinel-parameter-flow-control -am -Dtest=ModifyParamFlowRulesCommandHandlerTest -Dsurefire.failIfNoSpecifiedTests=false testJAVA_HOME=$(/usr/libexec/java_home -v 17) mvn -pl sentinel-extension/sentinel-parameter-flow-control -am -Dsurefire.failIfNoSpecifiedTests=false test