{"record":{"id":"45e7d277d136960c","repo":"risingwavelabs/risingwave","slug":"invalid-password","errorCode":null,"errorMessage":"Invalid password","messagePattern":"Invalid password","errorType":"error_code","errorClass":"PsqlError","httpStatus":null,"severity":"error","filePath":"src/utils/pgwire/src/error.rs","lineNumber":34,"sourceCode":"use std::io::Error as IoError;\n\nuse risingwave_common::error::code::PostgresErrorCode;\nuse thiserror::Error;\n\nuse crate::pg_server::BoxedError;\npub type PsqlResult<T> = std::result::Result<T, PsqlError>;\n\n/// Error type used in pgwire crates.\n#[derive(Error, Debug)]\npub enum PsqlError {\n    #[error(\"Failed to start a new session: {0}\")]\n    StartupError(\n        #[source]\n        #[backtrace]\n        BoxedError,\n    ),\n\n    #[error(\"Invalid password\")]\n    PasswordError,\n\n    #[error(\"Protocol violation: {0}\")]\n    ProtocolError(\n        #[source]\n        #[backtrace]\n        ProtocolViolationError,\n    ),\n\n    #[error(\"Failed to run the query: {0}\")]\n    SimpleQueryError(\n        #[source]\n        #[backtrace]\n        BoxedError,\n    ),\n\n    #[error(\"Failed to prepare the statement: {0}\")]\n    ExtendedPrepareError(","sourceCodeStart":16,"sourceCodeEnd":52,"githubUrl":"https://github.com/risingwavelabs/risingwave/blob/6469eb736d691e8e9b8a419a57edd6429ca77417/src/utils/pgwire/src/error.rs#L16-L52","documentation":"pgwire's fixed PsqlError::PasswordError variant, displayed as 'Invalid password'. It is returned when the password supplied during the cleartext/MD5 authentication exchange does not match the stored password for the user.","triggerScenarios":"Client responds to an AuthenticationCleartextPassword or MD5-hashed password request and the computed hash/stored comparison fails.","commonSituations":"User typo when running psql; password changed on the server (ALTER USER ... WITH PASSWORD) while clients cache the old one; MD5 salt mismatch; secrets/credential files (e.g. .pgpass) holding outdated entries.","solutions":["Re-enter the correct password for the connecting user.","Reset the user's password on the RisingWave server: ALTER USER <name> WITH PASSWORD '<new>';","Update cached credentials (.pgpass, connection strings, environment variables) to the new password.","Verify the user exists and authentication method configuration matches the client's capabilities."],"exampleFix":"// before: failing cached password\nlet password = env::var(\"OLD_PW\").unwrap();\n// after: use the current password from the secret store\nlet password = read_secret(\"risingwave/user_password\").unwrap();","handlingStrategy":"validation","validationCode":"// confirm credentials exist and are non-empty before connecting\nif password.is_empty() { return Err(\"password required for user authentication\"); }","typeGuard":"fn is_password_error(e: &PsqlError) -> bool { matches!(e, PsqlError::PasswordError) }","tryCatchPattern":"match connect(user, password).await {\n    Err(PsqlError::PasswordError) => prompt_user_for_credentials_and_retry(),\n    other => other,\n}","preventionTips":["Rotate server-side password changes together with all client credential stores.","Avoid hardcoding passwords; use secret managers or .pgpass kept in sync.","Test credentials with a lightweight connection before long-running jobs."],"tags":["pgwire","authentication","password"],"backgroundTag":"authentication-required","analyzedSha":"6469eb736d691e8e9b8a419a57edd6429ca77417","analyzedAt":"2026-09-11T21:06:21.487Z","contentChangedAt":"2026-09-11T21:06:21.487Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}