unbridled-41 opened a new pull request, #5991:
URL: https://github.com/apache/rocketmq-dashboard/pull/5991

   ### Which Issue(s) This PR Fixes
   Fixes #5990
   ### Problem / Evidence
   `AlertRuleRequestDTO` had `@Size(max = 4000)` on the notification template 
only, while `AlertService.createRule` catches just `DuplicateKeyException`:
   ```
   AlertRuleRequestDTOTest: textFieldsShouldBeBoundedToTheirColumnsTest
   Expecting actual ... to contain exactly in any order ... but could not find 
the following elements
   ```
   ### Root cause / Fix
   Column widths were enforced only by the database. Add `@Size` bounds 
matching each column (name/metric/brokerName/clusterName/instanceId 128, 
description 512, consumerGroup/topic 255, 
duration/reminderInterval/thresholdUnit 32) so the request is rejected with 400 
before any write.
   ### Priority and scoring
   **PRIORITY 60** - impact 22/40 (a 500 for valid-looking input, or silent 
truncation), blast radius 14/20 (every rule create/update, both domains), 
reproducibility 16/20 (pinned by DTO tests), maintenance value 8/20. 
**FIX_CONFIDENCE 88**.
   ### Tests
   `cd server && mvn -o -B -ntp test 
-Dtest='org.apache.rocketmq.studio.ops.alert.**'` -> `Tests run: 328, Failures: 
0, Errors: 0`; the new case fails before the change and passes after it, and a 
companion case pins that a value at the column width is still accepted; the 
controller tests keep passing; `checkstyle:check` passes.
   ### Risk
   Payloads longer than the columns are now rejected earlier with a 400; 
nothing that could be stored is refused.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to