MagicStack / MagicStack/asyncpg

`sslmode=prefere` surface misleading "no encryption" error when using a wrong password

Đang mở
#1,306 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Ngôn ngữ chính
Python
Star
8.1k
Fork
468
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

## Summary
When connecting with the default `sslmode=prefere` to a PostreSQL server that requires SSL (e.g. Amazon RDS with their default force_ssl=1), asyncpg reports:
```
asyncpg.exceptions.InvalidAuthorizationSpecificationError:
no pg_hba.conf entry for host "...", user "...", database "...", no encryption
```
The "no encryption" message points at an SSL/`pg_hba.conf` problem, when the actual issue is simply wrong credentials. This can send users on a lengthy debugging detour (so I heard).

## Steps to reproduce

1. Set up a PostgreSQL instance that requires SSL (e.g. Amazon RDS with `rds.force_ssl=1`).
2. Attempt to connect with `sslmode=prefer` (or rely on the default) using an **incorrect password**.

**Expected:** An error indicating password authentication failed (or at least something that points toward credentials). **Actual:** `no pg_hba.conf entry ... no encryption`

## Analysis
(Disclaimer: First glance at the asyncpg code and no Python dev)
I believe what's happening is the following
The retry logic in `_connect_addr` / `__connect_addr` (`connect_utils.py`) does the following for `sslmode=prefer`:

1. **First attempt** — connects with SSL. The TLS handshake succeeds, but authentication fails, raising `InvalidAuthorizationSpecificationError`. The exact server message from this first attempt is never surfaced to the user.
2. The exception handler at the `except InvalidAuthorizationSpecificationError` block checks `retry and params.sslmode == SSLMode.prefer and pr.is_ssl` — all `True` — and raises `_RetryConnectSignal`.
3. **Second attempt** — connects **without SSL**. The server, which requires SSL, rejects the plaintext connection with the `pg_hba.conf` / "no encryption" error. This is the only error the user sees.

Is there a way to safely distinguish between both cases and do not attempt to retry when the first attempt fails because of a wrong password? Or otherwise: Can we preserve the error message and raise both?

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu bằng cách tái hiện lỗi khi kết nối đến một máy chủ PostgreSQL yêu cầu SSL với mật khẩu không đúng, sau đó kiểm tra _connect_addr/__connect_addr và cách xử lý việc thử lại trong connect_utils.py. Được coi là hoàn tất khi lỗi xác thực đầu tiên được giữ nguyên hoặc lần thử lại không còn thay thế nó bằng lỗi gây hiểu nhầm "no encryption".

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
postgresql, python
Lĩnh vực
backend, databases
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.