yuluo-yx opened a new issue, #1774:
URL: https://github.com/apache/rocketmq-dashboard/issues/1774

   **BUG REPORT**
   
   1. Please describe the issue you observed:
   
   - What did you do (the steps to reproduce)?
   
   Ask the authentication `HandlerMethodArgumentResolver` whether it supports a 
controller parameter declared as `Object`.
   
   - What did you expect to see?
   
   Only `UserInfo` parameters, or valid subclasses of that model, should be 
handled by this resolver.
   
   - What did you see instead?
   
   The `Class.isAssignableFrom` operands are reversed. As a result, broad 
supertypes such as `Object` are accepted and may receive an unexpected 
authentication model.
   
   2. Please tell us about your environment:
   
   - apache/rocketmq-dashboard master
   - baseline commit `770822bbc812bfd0c2a94aa0128ab6f59b50d076`
   - JDK 17
   
   3. Other information:
   
   The change only corrects resolver type selection; UserInfo resolution itself 
remains unchanged.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to