Emmanuel Lécharny created DIRAPI-492:
----------------------------------------

             Summary: Restore the pool identity after a SASL bind on a pooled 
connection - #337
                 Key: DIRAPI-492
                 URL: https://issues.apache.org/jira/browse/DIRAPI-492
             Project: Directory Client API
          Issue Type: Bug
    Affects Versions: 2.1.8
            Reporter: Emmanuel Lécharny
             Fix For: 2.1.9


When a connection goes back to the pool, the pool re-binds it with its own 
configured identity if the borrower issued a bind. It relies on 
_MonitoringLdapConnection_ to see those binds. That class covered every bind 
variant except _bind(SaslRequest)_. After a borrower did a *SASL* bind as 
another user, the pool didn't notice. The connection went back still logged in 
as that user, and the next borrower silently got their access rights.

The patch adds the missing _bind(SaslRequest)_ override, so *SASL* binds are 
tracked like every other bind and the pool's identity is restored on release. 
Both pool factories use this class, so both are fixed. There are new tests for 
the monitor itself and for the full borrow → *SASL* bind → release path.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to