fix(admin): remove deprecated raw-password lookup - #7413
sunnysabor wants to merge 1 commit into
Conversation
|
CI follow-up: the |
|
Additional CI result: the E2E workflow has completed with the WebSocket case failing before its E2E tests. Its |
|
Follow-up: the original integration and K8s workflows are now complete and green. I attempted to rerun the E2E workflow with |
Aias00
left a comment
There was a problem hiding this comment.
Clean removal. findByQuery is gone from every layer in one go — DashboardUserMapper, dashboard-user-sqlmap.xml, DashboardUserService, DashboardUserServiceImpl, plus the corresponding mapper and service tests — and nothing dangling is left behind: every remaining findByQuery in the tree belongs to TagService, RoleService or the doc services, which declare their own unrelated overloads.
Removing the password = #{password} equality predicate is the right call now that authentication goes through PasswordHashService; comparing stored hashes with .equals invites both timing side channels and a broken migration path. LGTM.
Summary
Remove the deprecated
findByQuery(userName, password)path from the dashboard-user service and mapper, including its plaintext password SQL and dedicated tests. No production code calls this method; authentication continues throughDashboardUserService.login(...)and the password-hash flow. The compatibility GET and POST login routes remain unchanged.Closes #6607
Validation
./mvnw -B -ntp -pl shenyu-admin -Djacoco.skip=true -Dmaven.javadoc.skip=true test(1,719 tests, 0 failures/errors, 1 skipped; Checkstyle clean)findByQuery(userName, password)mapper/service implementation or SQL mapping.git diff --check