zjncs opened a new pull request, #5606:
URL: https://github.com/apache/rocketmq-dashboard/pull/5606

   Closes #5605
   
   ## Problem
   
   The paginated `listDataSources(search, type, page, pageSize)` overload 
carried the same `@Cacheable(DATA_SOURCE_CACHE)` as the full-list method, 
contradicting the comment that documents the cache as a cache of the **full 
list only**. Consequences:
   
   - the Spring cache key is `SimpleKey(search, type, page, pageSize)` — 
`search`/`type` are arbitrary caller strings on `GET 
/api/settings/datasources/page`, which is **not** admin-only, so any 
authenticated reader can drive it
   - the configured `ConcurrentMapCacheManager` has no TTL, size bound, or 
eviction (entries only clear on data-source create/update/delete)
   - every distinct search term permanently pins a `PageResult<DataSourceVO>` — 
DTOs carrying data-source auth fields (authType/username/password/bearerToken)
   
   ## Fix
   
   Remove the annotation from the parameterized overload only (the full-list 
method keeps it, and the write-path `@CacheEvict(allEntries=true)` methods 
continue to maintain it); leave a comment stating why the paged overload is 
intentionally uncached.
   
   ## Verification
   
   - New `SettingsServiceDataSourceCacheBoundTest` boots an 
`AnnotationConfigApplicationContext` registering the **production** 
`CacheConfig`:
     - control `fullDataSourceListIsCachedAsDocumented` — the full list is 
served once and cached (proves the harness is live); passes on master and with 
this change
     - `parameterizedDataSourceSearchMustNotAccumulatePermanentCacheEntries` — 
**FAILS on master** (50 permanent entries after 50 distinct searches: 
`Expecting empty but was: {SimpleKey [search-1, null, 1, 20]=PageResult@…, 
…}`), **PASSES with this change**
   - Regression: all existing settings suites green — `SettingsServiceTest` 
43/43, `SettingsServiceCachingTest` 1/1, `SettingsControllerTest` 23/23, 
DTO/factory tests 5/5
   - Mutation check: reverting the annotation removal makes the new test fail 
again; restoring it passes
   
   ## Collision note
   
   `SettingsService.java` is touched by #4681 (hunks @394-440), #4708 
(@325-340), #5484 (@160-170) — this change is confined to lines ~213-234, 
disjoint from all three with wide margins. `CacheConfig.java` and the new test 
file are untouched by any open PR.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to