[ 
https://issues.apache.org/jira/browse/DIRAPI-492?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120641#comment-18120641
 ] 

Emmanuel Lécharny commented on DIRAPI-492:
------------------------------------------

Found by Claude

> Restore the pool identity after a SASL bind on a pooled connection - #337
> -------------------------------------------------------------------------
>
>                 Key: DIRAPI-492
>                 URL: https://issues.apache.org/jira/browse/DIRAPI-492
>             Project: Directory Client API
>          Issue Type: Bug
>    Affects Versions: 2.1.8
>            Reporter: Emmanuel Lécharny
>            Priority: Major
>             Fix For: 2.1.9
>
>
> When a connection goes back to the pool, the pool re-binds it with its own 
> configured identity if the borrower issued a bind. It relies on 
> _MonitoringLdapConnection_ to see those binds. That class covered every bind 
> variant except _bind(SaslRequest)_. After a borrower did a *SASL* bind as 
> another user, the pool didn't notice. The connection went back still logged 
> in as that user, and the next borrower silently got their access rights.
> The patch adds the missing _bind(SaslRequest)_ override, so *SASL* binds are 
> tracked like every other bind and the pool's identity is restored on release. 
> Both pool factories use this class, so both are fixed. There are new tests 
> for the monitor itself and for the full borrow → *SASL* bind → release path.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to