Topic Grant-Permission Operation caused MQTT Clients Disconnected
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- java
- Domain
- backend, networking
Research direction
Reproduce with Pulsar 2.10.1 and MOP 2.10.1.7 using the standalone.conf MQTT settings and the documented pulsar-admin topics grant-permission command. Compare clients connected through the MQTT proxy in the same namespace with clients connected directly to the broker; done means repeating a grant does not disconnect either client.
Written by the indexing model from the issue text.
Description
Describe the bug
topic grant-permission operation caused all devices subcribed topics in the same namespace lost connection.
for example:
test-user-a is connected and subscribes persistent://test-tenant/ns/test-topic-a
test-user-b is connected and subscribes persistent://test-tenant/ns/test-topic-b
if i execute topic grant-permmision to any role with any topic in the same namespace, all mqtt clients will be disconnected instantly.
- it shows the same result no matter i execute by pulsar-cli, pulsar-restful-api or pulsar-java-api
- if topic grant-permission operation executes in another namespace, clients will not be disconnected.
- if clients connect to pulsar broker directly without mop, clients will not be disconnected.
To Reproduce
Steps to reproduce the behavior:
- prepare and start a Pulsar Server with mop plugin in standalone or single cluster mode. (following steps are in standalone mode) (Pulsar version 2.10.1, MOP version 2.10.1.7)
- config standalone.conf (see next part)
- create a tenant called "test-tenant"
- create a namespace called "test-tenant/ns"
- create 2 topics, called "persistent://test-tenant/ns/test-topic-a" and "persistent://test-tenant/ns/test-topic-b"
- create 2 subjects called "test-user-a" and "test-user-b"
- grant consume permissions for subjects:
bin/pulsar-admin --auth-plugin xxx --auth-params token:xxx --admin-url xxx topics grant-permission persistent://test-tenant/ns/test-topic-a --role test-user-a --actions consume,bin/pulsar-admin --auth-plugin xxx --auth-params token:xxx --admin-url xxx topics grant-permission persistent://test-tenant/ns/test-topic-b --role test-user-b --actions consume - Start a Mqtt client like mqtt-spy on my desktop
- login "test-user-a" and let it subscribe topic "persistent://test-tenant/ns/test-topic-a"
- login "test-user-b" and let it subscribe topic "persistent://test-tenant/ns/test-topic-b"
- let's execute this command again
bin/pulsar-admin --auth-plugin xxx --auth-params token:xxx --admin-url xxx topics grant-permission persistent://test-tenant/ns/test-topic-a --role test-user-a --actions consume - see mqtt-spy, the 2 client are disconnected.
standalone.conf modified params
clusterName=standalone
proxyRoles=proxy
authenticateOriginalAuthData=false
authenticationEnabled=true
authenticationProviders=org.apache.pulsar.broker.authentication.AuthenticationProviderToken
authorizationEnabled=true
authorizationProvider=org.apache.pulsar.broker.authorization.PulsarAuthorizationProvider
superUserRoles=admin,proxy
brokerClientAuthenticationPlugin=org.apache.pulsar.client.impl.auth.AuthenticationToken
brokerClientAuthenticationParameters=token:xxxx
messagingProtocols=mqtt
protocolHandlerDirectory=./protocols
mqttListeners=mqtt://xxxx:1883
advertisedAddress=xxxx
mqttProxyEnabled=true
mqttProxyPort=5682
mqttAuthenticationEnabled=true
mqttAuthenticationMethods=token
mqttAuthorizationEnabled=true
Expected behavior
When i grant-permission for topic to a role, connections user the same namespace will not be disconnected.
Screenshots
If applicable, add screenshots to help explain your problem.
Desktop (please complete the following information):
- Server OS: CentOS 7.9.2009
- MQTT Client OS: Windows 10
Additional context
Add any other context about the problem here.
- Dominant language
- Java
- Stars
- 190
- Forks
- 56
- Avg merge
- 27m
- Merged PRs (30d)
- 1
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from streamnative/mop
-
Difficulty 2/5 1-3 hours Newbie friendliness 35/100
streamnative/mop#1868 · 5 comments ·
-
Difficulty 3/5 1-2 days Newbie friendliness 25/100
streamnative/mop#1818 · 1 comment ·
-
Can not build mop Open
Difficulty 4/5 3-5 days Newbie friendliness 20/100
streamnative/mop#1765 · 2 comments ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
streamnative/mop#1758 · 1 comment ·
-
Difficulty 5/5 Over a week Newbie friendliness 20/100
streamnative/mop#1665 ·
All issues in streamnative/mop
Similar issues
-
Bug Java Platform: Java
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
getsentry/sentry-java#6138 · 1 comment ·
-
bug needs triage p2
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
GoogleCloudPlatform/DataflowTemplates#4273 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
bug needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100