Error message on missing SCRAM authentication with older clients
Started by Heikki Linnakangasover 8 years ago1 messages
Currently, if you use 9.6 libpq to connect to a v10 server that requires
SCRAM authentication, you get an error:
psql: authentication method 10 not supported
I'd like to apply this small patch to all the stable branches, to give a
nicer error message:
psql: SCRAM authentication not supported by this version of libpq
It won't help unless you upgrade to the latest minor version, of course,
but it's better than nothing. Any objections?
- Heikki
Attachments:
backport-nicer-error-on-scram.patchinvalid/octet-stream; name=backport-nicer-error-on-scram.patchDownload
diff --git a/src/include/libpq/pqcomm.h b/src/include/libpq/pqcomm.h
index c6bbfc2377..1d063d1248 100644
--- a/src/include/libpq/pqcomm.h
+++ b/src/include/libpq/pqcomm.h
@@ -172,6 +172,8 @@ extern bool Db_user_namespace;
#define AUTH_REQ_GSS 7 /* GSSAPI without wrap() */
#define AUTH_REQ_GSS_CONT 8 /* Continue GSS exchanges */
#define AUTH_REQ_SSPI 9 /* SSPI negotiate without wrap() */
+#define AUTH_REQ_SASL 10 /* SASL authentication. Not supported before
+ * libpq version 10. */
typedef uint32 AuthRequest;
diff --git a/src/interfaces/libpq/fe-auth.c b/src/interfaces/libpq/fe-auth.c
index 9bf6e52d63..ae3299e817 100644
--- a/src/interfaces/libpq/fe-auth.c
+++ b/src/interfaces/libpq/fe-auth.c
@@ -703,6 +703,19 @@ pg_fe_sendauth(AuthRequest areq, PGconn *conn)
return STATUS_ERROR;
break;
+ /*
+ * SASL authentication was introduced in version 10. Older
+ * versions recognize the request only to give a nicer error
+ * message. We call it "SCRAM authentication" in the error, rather
+ * SASL, because SCRAM is more familiar to users, and it's the
+ * only SASL authentication mechanism that has been implemented as
+ * of this writing, anyway.
+ */
+ case AUTH_REQ_SASL:
+ printfPQExpBuffer(&conn->errorMessage,
+ libpq_gettext("SCRAM authentication not supported by this version of libpq\n"));
+ return STATUS_ERROR;
+
default:
printfPQExpBuffer(&conn->errorMessage,
libpq_gettext("authentication method %u not supported\n"), areq);