fix: do not retry on wrong password (28P01) with sslmode=allow/prefer - #1331
Merged
elprans merged 2 commits intoSep 19, 2026
Merged
Conversation
elprans
reviewed
Sep 19, 2026
| # Do not retry on wrong password (28P01) — the issue is credentials, | ||
| # not SSL negotiation. Only pg_hba.conf rejections (28000) warrant a retry. | ||
| if isinstance(exc, exceptions.InvalidPasswordError): | ||
| raise |
Member
There was a problem hiding this comment.
Early re-raise would break valid sslmode=allow/prefer fallback. PostgreSQL can use different authentication methods for hostssl and hostnossl. libpq performs that retry for every startup ErrorResponse, including 28P01. I pushed an improved fix that remembers the original password error and reraises it after all fallbacks have been exhausted.
elprans
enabled auto-merge (squash)
September 19, 2026 06:14
elprans
approved these changes
Sep 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1306
Problem
When connecting with
sslmode=prefer(the default) orsslmode=allowto aPostgreSQL server and providing wrong credentials, asyncpg surfaces a misleading
no pg_hba.conf entry ... no encryptionerror instead of a clear authenticationfailure.
Root Cause
The retry logic in
__connect_addrcatchesInvalidAuthorizationSpecificationError(SQLSTATE 28000) and triggers an SSL retry for both
sslmode=preferandsslmode=allow. However, wrong password failures raiseInvalidPasswordError(SQLSTATE 28P01), a subclass of
InvalidAuthorizationSpecificationError. The retrythen connects with a different SSL state, which the server rejects with the misleading
pg_hba.conf error — hiding the real cause from the user.
Fix
Check if the caught exception is specifically
InvalidPasswordError(28P01) beforedeciding to retry. Wrong password errors are not SSL-related and retrying with
different SSL settings cannot fix them. Only pg_hba.conf rejections (28000) warrant
a retry.