[
https://issues.apache.org/jira/browse/DIRAPI-492?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Emmanuel Lécharny resolved DIRAPI-492.
--------------------------------------
Resolution: Fixed
Fixed with commit e2a80876b3d0606c32179d90308d5f222d2955fa
> Restore the pool identity after a SASL bind on a pooled connection - #337
> -------------------------------------------------------------------------
>
> Key: DIRAPI-492
> URL: https://issues.apache.org/jira/browse/DIRAPI-492
> Project: Directory Client API
> Issue Type: Bug
> Affects Versions: 2.1.8
> Reporter: Emmanuel Lécharny
> Priority: Major
> Fix For: 2.1.9
>
>
> When a connection goes back to the pool, the pool re-binds it with its own
> configured identity if the borrower issued a bind. It relies on
> _MonitoringLdapConnection_ to see those binds. That class covered every bind
> variant except _bind(SaslRequest)_. After a borrower did a *SASL* bind as
> another user, the pool didn't notice. The connection went back still logged
> in as that user, and the next borrower silently got their access rights.
> The patch adds the missing _bind(SaslRequest)_ override, so *SASL* binds are
> tracked like every other bind and the pool's identity is restored on release.
> Both pool factories use this class, so both are fixed. There are new tests
> for the monitor itself and for the full borrow → *SASL* bind → release path.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]