diff options
| author | Lucas de Castro Borges <lucas@gnuabordo.com.br> | 2025-02-11 15:07:35 -0300 |
|---|---|---|
| committer | Lucas de Castro Borges <lucas@gnuabordo.com.br> | 2025-02-11 15:07:35 -0300 |
| commit | 4cb8841196d0625dfa3825aa326f071cd27c7b8b (patch) | |
| tree | 1682a647d4463397c119183369ae6f750d5fdcff /src/mongo/db/commands/authentication_commands.cpp | |
| parent | aa03c6362cbaa767638e6eed9b031d86dd2643d1 (diff) | |
| parent | 8f0827553e09872941945a093b647a4211a9db7f (diff) | |
Update upstream source from tag 'upstream/6.0.0'master
Update to upstream version '6.0.0'
with Debian dir 5604a80ec1c96ca76f25f40d78e6ef855abec322
Diffstat (limited to 'src/mongo/db/commands/authentication_commands.cpp')
| -rw-r--r-- | src/mongo/db/commands/authentication_commands.cpp | 10 |
1 files changed, 7 insertions, 3 deletions
diff --git a/src/mongo/db/commands/authentication_commands.cpp b/src/mongo/db/commands/authentication_commands.cpp index 81a844dacba..0fef67553d0 100644 --- a/src/mongo/db/commands/authentication_commands.cpp +++ b/src/mongo/db/commands/authentication_commands.cpp @@ -240,7 +240,7 @@ void _authenticateX509(OperationContext* opCtx, AuthenticationSession* session) auto user = [&] { if (session->getUserName().empty()) { auto user = UserName(clientName.toString(), session->getDatabase().toString()); - session->updateUserName(user, true /* isMechX509 */); + session->updateUserName(user); return user; } else { uassert(ErrorCodes::AuthenticationFailed, @@ -258,6 +258,10 @@ void _authenticateX509(OperationContext* opCtx, AuthenticationSession* session) auto sslConfiguration = opCtx->getClient()->session()->getSSLConfiguration(); + uassert(ErrorCodes::AuthenticationFailed, + "Unable to verify x.509 certificate, as no CA has been provided.", + sslConfiguration->hasCA); + uassert(ErrorCodes::ProtocolError, "X.509 authentication must always use the $external database.", user.getDB() == kExternalDB); @@ -337,9 +341,9 @@ AuthenticateReply authCommand(OperationContext* opCtx, // Allows authenticating as the internal user against the admin database. This is to // support the auth passthrough test framework on mongos (since you can't use the local // database on a mongos, so you can't auth as the internal user without this). - session->updateUserName(internalSecurityUser, mechanism == auth::kMechanismMongoX509); + session->updateUserName(internalSecurityUser); } else { - session->updateUserName(UserName{user, dbname}, mechanism == auth::kMechanismMongoX509); + session->updateUserName(UserName{user, dbname}); } if (mechanism.empty()) { |
