finds.dev← search

// the find

jpmens/mosquitto-auth-plug

★ 839 · C · NOASSERTION · updated Mar 2019

Authentication plugin for Mosquitto with multiple back-ends (MySQL, Redis, CDB, SQLite3)

A Mosquitto plugin that checks MQTT logins and topic permissions against a database or other store, with back-ends for MySQL, PostgreSQL, MongoDB, Redis, SQLite, CDB, LDAP, HTTP, JWT and files, all configured through auth_opt_* lines in mosquitto.conf. It suits operators who want broker credentials in a store they already run. The author archived it in March 2019, so adopting it means owning the code.

Back-ends are tried in the order listed in auth_opt_backends, and once a user authenticates, ACLs come from that same back-end, so a mixed setup stays coherent. The LDAP back-end's ldap_acl_deny option lets LDAP handle logins while MySQL or Postgres handles topics, which is a sensible split. Cache TTLs get per-cache jitter, which matters when a broker restart makes every client hit the database at once. The SQL templates are supplied by the operator, so the plugin fits an existing users table instead of forcing a schema.

The project has been unmaintained since 2019. The author says he no longer uses it, open issues were closed, and any future Mosquitto or OpenSSL change is yours to fix. Some back-ends authenticate and then allow more than they should: SQLite and CDB leave ACL checking unimplemented and return TRUE, LDAP grants every topic once the bind succeeds, and Redis ACLs are exact string matches with no wildcards. Passwords must be PBKDF2 strings in the $-delimited format, so existing bcrypt or clear-text stores need migrating first. Building requires a full Mosquitto source tree referenced from config.mk, and the documented Postgres ACL example predates Mosquitto 1.5's permission values, so expect to debug ACL mismatches.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →