[SERVER-37527] Broken logic in ServerMechanismBase class. Created: 09/Oct/18 Updated: 29/Oct/23 Resolved: 29/Nov/18 |
|
| Status: | Closed |
| Project: | Core Server |
| Component/s: | Internal Code, Security |
| Affects Version/s: | 4.0.0, 4.0.3, 4.1.3 |
| Fix Version/s: | 4.0.5, 4.1.6 |
| Type: | Bug | Priority: | Major - P3 |
| Reporter: | Igor Solodovnikov | Assignee: | Sara Golemon |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Issue Links: |
|
||||||||||||||||
| Backwards Compatibility: | Fully Compatible | ||||||||||||||||
| Operating System: | ALL | ||||||||||||||||
| Backport Requested: |
v4.0
|
||||||||||||||||
| Sprint: | Security 2018-11-05, Security 2018-11-19, Security 2018-12-03 | ||||||||||||||||
| Participants: | |||||||||||||||||
| Description |
|
The ServerMechanismBase class has isDone method. Comment in the source code of this method say:
The problem is that if SASL error occurs isDone will never return true because of this code in ServerMechanismBase::step:
As you can see _done variable is only assigned if step's result is OK.
This bug affects AuthenticationSession's lifecycle management implemented in CmdSaslStart::run and CmdSaslContinue::run methods. In case of authentication error (for example in case of the wrong password) those methods fail to destroy current client's AuthenticationSession instance because mechanism.isDone() returns false. |
| Comments |
| Comment by Githook User [ 01/Dec/18 ] |
|
Author: {'name': 'Sara Golemon', 'email': 'sara.golemon@mongodb.com', 'username': 'sgolemon'}Message: (cherry picked from commit 662bec7c902c7e2eacdbeed0c8fca59563d73155) |
| Comment by Githook User [ 01/Dec/18 ] |
|
Author: {'name': 'Sara Golemon', 'email': 'sara.golemon@mongodb.com', 'username': 'sgolemon'}Message: (cherry picked from commit 145966a7ce2a677cd697f842ae7c471b301fdf8d) |
| Comment by Githook User [ 29/Nov/18 ] |
|
Author: {'name': 'Sara Golemon', 'email': 'sara.golemon@mongodb.com', 'username': 'sgolemon'}Message: |