Skip to content

Authorization denial should result in error+ready-for-query - #2

Merged
mostafa merged 2 commits into
mainfrom
deny-and-rfq
Feb 22, 2026
Merged

mostafa merged 2 commits into
mainfrom
deny-and-rfq

Conversation

@mostafa

@mostafa mostafa commented Feb 22, 2026 •

Copy link
Copy Markdown
Member

Ticket(s)

Description

BuildAccessDeniedResponse was using postgres.BuildTerminateWithError, which builds ErrorResponse + pgproto3.Terminate (type byte 'X'). The Terminate message is a frontend (client-to-server) message in the PostgreSQL wire protocol, so sending it from the server to the client during query execution causes psql/libpq to encounter an invalid backend message type and hang indefinitely.

This changes BuildAccessDeniedResponse to build ErrorResponse + ReadyForQuery instead. ReadyForQuery (type 'Z', transaction status 'I') is the correct PostgreSQL protocol response after a query error — it tells the client the server is ready for the next command and keeps the session open.

BuildAuthFailResponse (for wrong passwords) is left unchanged, since Terminate is appropriate there — the connection is being rejected during the startup/auth phase.

Related PRs

Development Checklist

  • I have added a descriptive title to this PR.
  • I have squashed related commits together.
  • I have rebased my branch on top of the latest main branch.
  • I have performed a self-review of my own code.
  • I have commented on my code, particularly in hard-to-understand areas.
  • I have added docstring(s) and type annotations to my code.
  • I have made corresponding changes to the documentation (docs).
  • I have added tests for my changes.

Legal Checklist

@mostafa mostafa self-assigned this Feb 22, 2026
@mostafa
mostafa merged commit 74b2a01 into main Feb 22, 2026
2 checks passed
@mostafa
mostafa deleted the deny-and-rfq branch February 22, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant