Repository navigation
fix(errors): SSH tunnel failures are not reported as a database authentication failure (#1305) - #1322
Merged
Merged
Conversation
…ntication failure (#1305) SshAuthenticationException's text contains 'authentication failed', which the mapper turned into AuthFailed with the database hint and dropped the host. A wrong bastion password read as a wrong database password. - The mapper handles SshAuthenticationException, SshHostKeyMismatchException and the new SshConnectionException before any text matching, keeping the host and user and pointing at the SSH tunnel settings. - openTunnel tells a rejected login (SSHAuthError) from a transport or protocol failure, which is no longer 'SSH authentication failed', and the transport and jump host failures name the host and port. - describeDatabaseError keeps the hint of a mapped error.
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1305
Problem
SshAuthenticationExceptionreadsSSH authentication failed for user@host: ...;mapDatabaseErrormatchedauthentication failed, producedAuthFailedException(Check the username and password in the connection settings) anddescribeDatabaseErrorreturned only that. A wrong bastion password looked like a wrong database password, and the bastion host, user and reason were lost.openTunnelwrapped every failure after the transport was open (a reset, a timeout, a protocol error) as SSH authentication failed; the jump host login and the transport connects threw raw driver errors.Fix
mapDatabaseErrorhandlesSshAuthenticationException,SshHostKeyMismatchExceptionand the newSshConnectionExceptionfirst, keeping the SSH text and adding a hint at the SSH tunnel settings (a host key mismatch: do not connect unless the server was reinstalled). A connection failure isHostUnreachableException.openTunnel(_sshFailure):SSHAuthErroris an authentication failure; anything else isSshConnectionExceptionwith host and port. The transport connect (_dial) and the jump host login and forward are wrapped the same way, naming the jump host.describeDatabaseErrorkeeps the hint of an unrecognised-but-hinted error.Tests: tunnel — unreachable bastion names the host, a reset during the handshake is a connection failure, a rejected jump host login names
[email protected]; mapper — SSH auth is notAuthFailedand keeps the host, the one-line text points at the tunnel settings, a connection failure is unreachable, a mismatch says not to connect, a database password authentication failed is stillAuthFailed.