Skip to content

fix(errors): SSH tunnel failures are not reported as a database authentication failure (#1305) - #1322

Merged
ZhuchkaTriplesix merged 3 commits into
devfrom
fix/1305-ssh-errors-not-db-auth
Oct 10, 2026
Merged

ZhuchkaTriplesix merged 3 commits into
devfrom
fix/1305-ssh-errors-not-db-auth

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Closes #1305

Problem

  • SshAuthenticationException reads SSH authentication failed for user@host: ...; mapDatabaseError matched authentication failed, produced AuthFailedException (Check the username and password in the connection settings) and describeDatabaseError returned only that. A wrong bastion password looked like a wrong database password, and the bastion host, user and reason were lost.
  • openTunnel wrapped every failure after the transport was open (a reset, a timeout, a protocol error) as SSH authentication failed; the jump host login and the transport connects threw raw driver errors.

Fix

  • mapDatabaseError handles SshAuthenticationException, SshHostKeyMismatchException and the new SshConnectionException first, keeping the SSH text and adding a hint at the SSH tunnel settings (a host key mismatch: do not connect unless the server was reinstalled). A connection failure is HostUnreachableException.
  • openTunnel (_sshFailure): SSHAuthError is an authentication failure; anything else is SshConnectionException with host and port. The transport connect (_dial) and the jump host login and forward are wrapped the same way, naming the jump host.
  • describeDatabaseError keeps the hint of an unrecognised-but-hinted error.

Tests: tunnel — unreachable bastion names the host, a reset during the handshake is a connection failure, a rejected jump host login names [email protected]; mapper — SSH auth is not AuthFailed and keeps the host, the one-line text points at the tunnel settings, a connection failure is unreachable, a mismatch says not to connect, a database password authentication failed is still AuthFailed.

…ntication failure (#1305)

SshAuthenticationException's text contains 'authentication failed', which
the mapper turned into AuthFailed with the database hint and dropped the
host. A wrong bastion password read as a wrong database password.

- The mapper handles SshAuthenticationException, SshHostKeyMismatchException
  and the new SshConnectionException before any text matching, keeping the
  host and user and pointing at the SSH tunnel settings.
- openTunnel tells a rejected login (SSHAuthError) from a transport or
  protocol failure, which is no longer 'SSH authentication failed', and the
  transport and jump host failures name the host and port.
- describeDatabaseError keeps the hint of a mapped error.
@github-actions github-actions Bot added bug Something isn't working error-handling Theme parser epic label: error-handling connections Database connections, URI parsing, pools ux User experience, keyboard shortcuts and interactions P2 Medium priority / Parity & Refactoring labels Oct 10, 2026
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit 5a93892 into dev Oct 10, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working connections Database connections, URI parsing, pools error-handling Theme parser epic label: error-handling P2 Medium priority / Parity & Refactoring ux User experience, keyboard shortcuts and interactions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant