fix: 认证失败不泄漏连接表并脱敏 mochi 整包日志

This commit is contained in:
Nixevol
2026-09-30 16:21:05 +08:00
parent deb2398e27
commit 0b9ce0359a
5 changed files with 442 additions and 14 deletions
+12 -6
View File
@@ -3,6 +3,7 @@ package broker
import (
"bytes"
"context"
"time"
"git.asio.asia/nixevol/NixMsg/internal/app/port"
mqtt "github.com/mochi-mqtt/server/v2"
@@ -47,12 +48,11 @@ func (h *nixHook) OnConnect(cl *mqtt.Client, pk packets.Packet) error {
remoteIP: remoteIP,
client: cl,
maxPacketSize: pk.Properties.MaximumPacketSize,
createdAt: time.Now(),
}
// ClientID、Username 都必须等于端编号
if clientID == "" || endpointID == "" || clientID != endpointID {
st.authOK = false
h.rememberPending(cl, st)
return nil
}
@@ -81,11 +81,12 @@ func (h *nixHook) OnConnect(cl *mqtt.Client, pk packets.Packet) error {
res, err := h.b.auth.Authenticate(context.Background(), endpointID, pk.Connect.Password, remoteIP)
if err != nil {
st.authErr = err
h.rememberPending(cl, st)
return err // mochi 不回 CONNACK,直接断开
return err // mochi 不回 CONNACK,直接断开;不登记连接表
}
st.authOK = res.OK
if !res.OK {
return nil
}
st.authOK = true
st.sessionToken = res.SessionToken
h.rememberPending(cl, st)
return nil
@@ -94,6 +95,7 @@ func (h *nixHook) OnConnect(cl *mqtt.Client, pk packets.Packet) error {
func (h *nixHook) rememberPending(cl *mqtt.Client, st *connState) {
h.b.connsMu.Lock()
h.b.byClient[cl] = st
h.b.byConnID[st.connID] = st
h.b.connsMu.Unlock()
}
@@ -188,6 +190,7 @@ func (h *nixHook) OnSessionEstablished(cl *mqtt.Client, _ packets.Packet) {
st := h.b.byClient[cl]
if st != nil {
h.b.current[st.endpointID] = st
st.established = true
}
h.b.connsMu.Unlock()
if st == nil {
@@ -209,6 +212,9 @@ func (h *nixHook) OnDisconnect(cl *mqtt.Client, err error, _ bool) {
h.b.connsMu.Lock()
st := h.b.byClient[cl]
delete(h.b.byClient, cl)
if st != nil {
delete(h.b.byConnID, st.connID)
}
isCurrent := false
if st != nil && h.b.current[st.endpointID] == st {
delete(h.b.current, st.endpointID)