unbridled-41 opened a new issue, #6004:
URL: https://github.com/apache/rocketmq-dashboard/issues/6004

   ### Studio Version
   branch: `rocketmq-studio` @ `7e7aa344`
   ### Runtime Environment
   Backend tests: `cd server && mvn -o -B -ntp test 
-Dtest='K8sCertServiceTest'`.
   ### Describe the Bug
   The certificate write path trims the identity fields and rejects blanks but 
never their width, while the columns are `k8s_id VARCHAR(128)`, `cluster 
VARCHAR(128)`, `issuer VARCHAR(256)`. A longer value reached the database, 
whose rejection no handler maps, so the API answered 500 - and for the issuer 
the caller cannot shorten it, because a supplied PEM wins and the DN is read 
out of the certificate (large enterprise CAs exceed 256 characters).
   ### Steps to Reproduce
   `POST /api/k8s-certs/create` with a 129-character `k8sId`, or a PEM whose 
issuer DN is longer than 256 characters.
   ### What Did You Expect to See?
   A 400 for a caller-supplied value, and a stored (bounded) issuer for a 
derived one.
   ### What Did You See Instead?
   A generic 500.
   ### Impact
   A legitimate registration fails with no usable reason; the certificate 
inventory is unusable for a CA with a long DN.
   ### Acceptance Criteria
   Caller-supplied identities are bounded with 400; a derived issuer is bounded 
with a visible marker instead of failing the registration, with regression 
tests.
   **Corresponding PR:** #ISSUEPR#
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to