diff --git a/application/src/test/java/org/thingsboard/server/transport/mqtt/mqttv3/credentials/BasicMqttCredentialsTest.java b/application/src/test/java/org/thingsboard/server/transport/mqtt/mqttv3/credentials/BasicMqttCredentialsTest.java index 288d0ca45c..496a13ad70 100644 --- a/application/src/test/java/org/thingsboard/server/transport/mqtt/mqttv3/credentials/BasicMqttCredentialsTest.java +++ b/application/src/test/java/org/thingsboard/server/transport/mqtt/mqttv3/credentials/BasicMqttCredentialsTest.java @@ -16,7 +16,8 @@ package org.thingsboard.server.transport.mqtt.mqttv3.credentials; import com.fasterxml.jackson.core.type.TypeReference; -import org.eclipse.paho.client.mqttv3.MqttSecurityException; +import org.eclipse.paho.client.mqttv3.MqttException; +import org.junit.Assert; import org.junit.Before; import org.junit.Test; import org.thingsboard.common.util.JacksonUtil; @@ -114,11 +115,15 @@ public class BasicMqttCredentialsTest extends AbstractMqttIntegrationTest { testTelemetryIsDelivered(accessToken2Device, mqttTestClient5); } - @Test(expected = MqttSecurityException.class) + @Test public void testCorrectClientIdAndUserNameButWrongPassword() throws Exception { // Not correct. Correct clientId and username, but wrong password MqttTestClient mqttTestClient = new MqttTestClient(CLIENT_ID); - mqttTestClient.connectAndWait(USER_NAME3, "WRONG PASSWORD"); + try { + mqttTestClient.connectAndWait(USER_NAME3, "WRONG PASSWORD"); + } catch (MqttException e) { + Assert.assertEquals(4, e.getReasonCode()); // 4 - Reason code for bad username or password in MQTT v3 + } testTelemetryIsNotDelivered(clientIdAndUserNameAndPasswordDevice3, mqttTestClient); } diff --git a/common/transport/mqtt/src/main/java/org/thingsboard/server/transport/mqtt/MqttTransportHandler.java b/common/transport/mqtt/src/main/java/org/thingsboard/server/transport/mqtt/MqttTransportHandler.java index c03a7dd441..2c3ac45326 100644 --- a/common/transport/mqtt/src/main/java/org/thingsboard/server/transport/mqtt/MqttTransportHandler.java +++ b/common/transport/mqtt/src/main/java/org/thingsboard/server/transport/mqtt/MqttTransportHandler.java @@ -1010,17 +1010,19 @@ public class MqttTransportHandler extends ChannelInboundHandlerAdapter implement private void onValidateDeviceResponse(ValidateDeviceCredentialsResponse msg, ChannelHandlerContext ctx, MqttConnectMessage connectMessage) { if (!msg.hasDeviceInfo()) { context.onAuthFailure(address); - if (MqttVersion.MQTT_5.equals(deviceSessionCtx.getMqttVersion())) { - ReturnCode returnCode = ReturnCode.NOT_AUTHORIZED_5; - if (sslHandler == null || getX509Certificate() == null) { - if (connectMessage.payload().userName() == null ^ connectMessage.payload().passwordInBytes() == null) { - returnCode = ReturnCode.BAD_USERNAME_OR_PASSWORD; - } else if (!StringUtils.isBlank(connectMessage.payload().clientIdentifier())) { - returnCode = ReturnCode.CLIENT_IDENTIFIER_NOT_VALID; - } + ReturnCode returnCode = ReturnCode.NOT_AUTHORIZED_5; + if (sslHandler == null || getX509Certificate() == null) { + String username = connectMessage.payload().userName(); + byte[] passwordBytes = connectMessage.payload().passwordInBytes(); + String clientId = connectMessage.payload().clientIdentifier(); + if ((username != null && passwordBytes != null && clientId != null) + || (username == null ^ passwordBytes == null)) { + returnCode = ReturnCode.BAD_USERNAME_OR_PASSWORD; + } else if (!StringUtils.isBlank(clientId)) { + returnCode = ReturnCode.CLIENT_IDENTIFIER_NOT_VALID; } - ctx.writeAndFlush(createMqttConnAckMsg(returnCode, connectMessage)); } + ctx.writeAndFlush(createMqttConnAckMsg(returnCode, connectMessage)); ctx.close(); } else { context.onAuthSuccess(address);