Emmanuel Lécharny created DIRAPI-492:
----------------------------------------
Summary: Restore the pool identity after a SASL bind on a pooled
connection - #337
Key: DIRAPI-492
URL: https://issues.apache.org/jira/browse/DIRAPI-492
Project: Directory Client API
Issue Type: Bug
Affects Versions: 2.1.8
Reporter: Emmanuel Lécharny
Fix For: 2.1.9
When a connection goes back to the pool, the pool re-binds it with its own
configured identity if the borrower issued a bind. It relies on
_MonitoringLdapConnection_ to see those binds. That class covered every bind
variant except _bind(SaslRequest)_. After a borrower did a *SASL* bind as
another user, the pool didn't notice. The connection went back still logged in
as that user, and the next borrower silently got their access rights.
The patch adds the missing _bind(SaslRequest)_ override, so *SASL* binds are
tracked like every other bind and the pool's identity is restored on release.
Both pool factories use this class, so both are fixed. There are new tests for
the monitor itself and for the full borrow → *SASL* bind → release path.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]