{"record":{"id":"4e8452b18d1e3e00","repo":"apache/seatunnel","slug":"collector-authentication-timeout-from-connecti","errorCode":null,"errorMessage":"Collector authentication timeout from {}, connection rejected","messagePattern":"Collector authentication timeout from (.+?), connection rejected","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/protocol/IngressProtocolHandler.java","lineNumber":59,"sourceCode":"        this.config = config;\n        this.handler = handler;\n    }\n\n    public boolean authenticate(IngressChannel channel) throws IOException {\n        if (config.getAuthType() != EdgeSocketAuthType.TOKEN) {\n            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());\n            log.warn(\n                    \"Unsupported auth type: {}, from {}\",\n                    config.getAuthType(),\n                    channel.remoteAddress());\n            return false;\n        }\n        String authLine;\n        try {\n            authLine = channel.readLine();\n        } catch (SocketTimeoutException timeoutException) {\n            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());\n            log.warn(\n                    \"Collector authentication timeout from {}, connection rejected\",\n                    channel.remoteAddress());\n            return false;\n        }\n        if (authLine == null) {\n            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());\n            log.warn(\n                    \"Collector from {} closed connection before authentication\",\n                    channel.remoteAddress());\n            return false;\n        }\n        String presentedToken = parseAuthToken(authLine);\n        if (!constantTimeEquals(config.getToken(), presentedToken)) {\n            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());\n            log.warn(\"Collector authentication failed from {}\", channel.remoteAddress());\n            return false;\n        }\n        channel.writeLine(EdgeSocketResponseCode.ACK.getCode());","sourceCodeStart":41,"sourceCodeEnd":77,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/protocol/IngressProtocolHandler.java#L41-L77","documentation":"A WARN logged by IngressProtocolHandler.authenticate when reading the collector's auth line throws a SocketTimeoutException — the collector connected but did not send its token within the socket's read timeout. The connection is rejected with AUTH_FAILED.","triggerScenarios":"channel.readLine() in authenticate blocks past the socket SO_TIMEOUT because the collector never writes the auth token line (hung/slow client, half-open connection, or a non-EdgeSocket client probing the port).","commonSituations":"Load balancer health checks opening TCP connections without speaking the protocol; collector with stalled network; collectors waiting for a server greeting the protocol doesn't send; firewalled/NAT'd clients.","solutions":["Ensure collectors write the auth token line immediately after connecting.","Exclude health-check/probe sources from the EdgeSocket port or make them protocol-aware.","Increase the socket read timeout in the EdgeSocket config if collectors are legitimately slow.","Verify collectors are not stuck waiting for a server banner — the protocol is client-first."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// client side: send the token immediately after connect\nsocket.connect(addr, connectTimeoutMs);\nsocket.setSoTimeout(readTimeoutMs);\nout.write((\"token:\" + token + \"\\n\").getBytes());\nout.flush();","typeGuard":null,"tryCatchPattern":"try {\n    boolean ok = handler.authenticate(channel);\n} catch (SocketTimeoutException e) {\n    // expected for silent clients; connection already rejected\n}","preventionTips":["Collectors must write the auth line first (client-first protocol)","Exclude non-protocol health probes from the port","Tune read timeout for slow collectors"],"tags":["edge-socket","authentication","timeout","socket"],"backgroundTag":"request-timeout","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}