mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-03 19:02:12 +02:00
Skip ALTER ROLE when the stored SCRAM verifier already matches the password (#3171)
* Skip ALTER ROLE when the stored SCRAM verifier already matches the password With password_encryption = scram-sha-256, syncSecrets compared the stored rolpassword with a freshly generated verifier. SCRAM verifiers embed a random salt, so the strings never match and every sync cycle re-issued ALTER ROLE ... PASSWORD for every managed role, re-salting the verifier each time. Besides the WAL and audit noise, this invalidates SCRAM pass-through credentials cached by connection poolers (e.g. pgbouncer behind auth_query), causing a short window of 'password authentication failed' server logins after every sync. Verify the stored hash against the desired password instead: for SCRAM verifiers the salt and iteration count are taken from the stored value and the derived keys are compared. Hashes whose type does not match the configured password_encryption are still reported as outdated, so switching between md5 and scram-sha-256 keeps re-hashing roles as before. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Update pkg/util/util.go --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Ida Novindasari <idanovinda@gmail.com> Co-authored-by: Felix Kunde <felix-kunde@gmx.de>
This commit is contained in:
committed by
Felix Kunde
co-authored by
Claude Fable 5
Ida Novindasari
Felix Kunde
parent
6138bc4a69
commit
6e65436624
@@ -60,11 +60,13 @@ func (strategy DefaultUserSyncStrategy) ProduceSyncRequests(dbUsers spec.PgUserM
|
||||
}
|
||||
} else {
|
||||
r := spec.PgSyncUserRequest{}
|
||||
newMD5Password := util.NewEncryptor(strategy.PasswordEncryption).PGUserPassword(newUser)
|
||||
|
||||
// do not compare for roles coming from docker image
|
||||
if dbUser.Password != newMD5Password {
|
||||
r.User.Password = newMD5Password
|
||||
// A plain string comparison with a freshly generated hash would
|
||||
// re-issue ALTER ROLE on every sync for SCRAM-SHA-256, because
|
||||
// each generated verifier embeds a new random salt. Verify the
|
||||
// stored hash against the desired password instead.
|
||||
if !util.PGUserPasswordUpToDate(newUser, dbUser.Password, strategy.PasswordEncryption) {
|
||||
r.User.Password = util.NewEncryptor(strategy.PasswordEncryption).PGUserPassword(newUser)
|
||||
r.Kind = spec.PGsyncUserAlter
|
||||
}
|
||||
if addNewRoles, equal := util.SubstractStringSlices(newUser.MemberOf, dbUser.MemberOf); !equal {
|
||||
|
||||
Reference in New Issue
Block a user