Skip to content

Map memcached SASL status 0x20 to InvalidCredentials #283

Description

@jaysonsantos

Found while writing the SASL integration test for #274.

Evidence

test/test_sasl_integration.py::test_wrong_password_is_rejected connects to a
real memcached started with -S and a Cyrus SASL user database. A wrong
password gives this:

bmemcached.exceptions.MemcachedException: ("Code: 32 Message: b'Auth failure.'", 32)

Status 32 is 0x20. bmemcached/protocol.py maps only 0x08 to
InvalidCredentials:

STATUS = {
    ...
    'auth_error': 0x08,
    ...
}

and in authenticate:

if status == self.STATUS['auth_error']:
    raise InvalidCredentials("Incorrect username or password", status)

So a real authentication failure raises the base MemcachedException, not
InvalidCredentials. A caller that catches InvalidCredentials never sees it.

test/test_auth.py::testAuthUnsuccessful passes today because it mocks
_get_response and feeds 0x08 by hand. No test used a real server, so the
gap was invisible.

Scope

Decide which status codes mean "bad credentials" and map them. 0x20 is
AUTH_ERROR / "Authentication required" in the memcached binary protocol.
Check whether 0x21 (further authentication steps required) needs handling
too.

Acceptance criteria

  • A wrong password against a real SASL-enabled memcached raises
    InvalidCredentials.
  • test/test_sasl_integration.py::test_wrong_password_is_rejected asserts
    InvalidCredentials in place of MemcachedException.
  • test/test_auth.py keeps its mocked coverage of 0x08.

Order

Do #274 first. That issue adds the SASL fixture this work needs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    code-qualityCode quality, typing and defects

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions