Topic Grant-Permission Operation caused MQTT Clients Disconnected

Đang mở
#753 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
java
Lĩnh vực
backend, networking

Hướng nghiên cứu

Reproduce with Pulsar 2.10.1 and MOP 2.10.1.7 using the standalone.conf MQTT settings and the documented pulsar-admin topics grant-permission command. Compare clients connected through the MQTT proxy in the same namespace with clients connected directly to the broker; done means repeating a grant does not disconnect either client.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Describe the bug
topic grant-permission operation caused all devices subcribed topics in the same namespace lost connection.
for example:
test-user-a is connected and subscribes persistent://test-tenant/ns/test-topic-a
test-user-b is connected and subscribes persistent://test-tenant/ns/test-topic-b
if i execute topic grant-permmision to any role with any topic in the same namespace, all mqtt clients will be disconnected instantly.

  • it shows the same result no matter i execute by pulsar-cli, pulsar-restful-api or pulsar-java-api
  • if topic grant-permission operation executes in another namespace, clients will not be disconnected.
  • if clients connect to pulsar broker directly without mop, clients will not be disconnected.

To Reproduce
Steps to reproduce the behavior:

  1. prepare and start a Pulsar Server with mop plugin in standalone or single cluster mode. (following steps are in standalone mode) (Pulsar version 2.10.1, MOP version 2.10.1.7)
  2. config standalone.conf (see next part)
  3. create a tenant called "test-tenant"
  4. create a namespace called "test-tenant/ns"
  5. create 2 topics, called "persistent://test-tenant/ns/test-topic-a" and "persistent://test-tenant/ns/test-topic-b"
  6. create 2 subjects called "test-user-a" and "test-user-b"
  7. grant consume permissions for subjects: bin/pulsar-admin --auth-plugin xxx --auth-params token:xxx --admin-url xxx topics grant-permission persistent://test-tenant/ns/test-topic-a --role test-user-a --actions consume, bin/pulsar-admin --auth-plugin xxx --auth-params token:xxx --admin-url xxx topics grant-permission persistent://test-tenant/ns/test-topic-b --role test-user-b --actions consume
  8. Start a Mqtt client like mqtt-spy on my desktop
  9. login "test-user-a" and let it subscribe topic "persistent://test-tenant/ns/test-topic-a"
  10. login "test-user-b" and let it subscribe topic "persistent://test-tenant/ns/test-topic-b"
  11. let's execute this command again bin/pulsar-admin --auth-plugin xxx --auth-params token:xxx --admin-url xxx topics grant-permission persistent://test-tenant/ns/test-topic-a --role test-user-a --actions consume
  12. see mqtt-spy, the 2 client are disconnected.

standalone.conf modified params

clusterName=standalone
proxyRoles=proxy
authenticateOriginalAuthData=false
authenticationEnabled=true
authenticationProviders=org.apache.pulsar.broker.authentication.AuthenticationProviderToken
authorizationEnabled=true
authorizationProvider=org.apache.pulsar.broker.authorization.PulsarAuthorizationProvider
superUserRoles=admin,proxy
brokerClientAuthenticationPlugin=org.apache.pulsar.client.impl.auth.AuthenticationToken
brokerClientAuthenticationParameters=token:xxxx
messagingProtocols=mqtt
protocolHandlerDirectory=./protocols
mqttListeners=mqtt://xxxx:1883
advertisedAddress=xxxx
mqttProxyEnabled=true
mqttProxyPort=5682
mqttAuthenticationEnabled=true
mqttAuthenticationMethods=token
mqttAuthorizationEnabled=true

Expected behavior
When i grant-permission for topic to a role, connections user the same namespace will not be disconnected.

Screenshots
If applicable, add screenshots to help explain your problem.

Desktop (please complete the following information):

  • Server OS: CentOS 7.9.2009
  • MQTT Client OS: Windows 10

Additional context
Add any other context about the problem here.

Ngôn ngữ chính
Java
Star
190
Fork
56
Merge trung bình
27 phút
Pull request đã merge (30 ngày)
1

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của streamnative/mop

Tất cả issue của streamnative/mop

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.