Found while writing the SASL integration test for #274.
Evidence
test/test_sasl_integration.py::test_wrong_password_is_rejected connects to a
real memcached started with -S and a Cyrus SASL user database. A wrong
password gives this:
bmemcached.exceptions.MemcachedException: ("Code: 32 Message: b'Auth failure.'", 32)
Status 32 is 0x20. bmemcached/protocol.py maps only 0x08 to
InvalidCredentials:
STATUS = {
...
'auth_error': 0x08,
...
}
and in authenticate:
if status == self.STATUS['auth_error']:
raise InvalidCredentials("Incorrect username or password", status)
So a real authentication failure raises the base MemcachedException, not
InvalidCredentials. A caller that catches InvalidCredentials never sees it.
test/test_auth.py::testAuthUnsuccessful passes today because it mocks
_get_response and feeds 0x08 by hand. No test used a real server, so the
gap was invisible.
Scope
Decide which status codes mean "bad credentials" and map them. 0x20 is
AUTH_ERROR / "Authentication required" in the memcached binary protocol.
Check whether 0x21 (further authentication steps required) needs handling
too.
Acceptance criteria
Order
Do #274 first. That issue adds the SASL fixture this work needs.
Found while writing the SASL integration test for #274.
Evidence
test/test_sasl_integration.py::test_wrong_password_is_rejectedconnects to areal memcached started with
-Sand a Cyrus SASL user database. A wrongpassword gives this:
Status 32 is
0x20.bmemcached/protocol.pymaps only0x08toInvalidCredentials:and in
authenticate:So a real authentication failure raises the base
MemcachedException, notInvalidCredentials. A caller that catchesInvalidCredentialsnever sees it.test/test_auth.py::testAuthUnsuccessfulpasses today because it mocks_get_responseand feeds0x08by hand. No test used a real server, so thegap was invisible.
Scope
Decide which status codes mean "bad credentials" and map them.
0x20isAUTH_ERROR/ "Authentication required" in the memcached binary protocol.Check whether
0x21(further authentication steps required) needs handlingtoo.
Acceptance criteria
InvalidCredentials.test/test_sasl_integration.py::test_wrong_password_is_rejectedassertsInvalidCredentialsin place ofMemcachedException.test/test_auth.pykeeps its mocked coverage of0x08.Order
Do #274 first. That issue adds the SASL fixture this work needs.