Smack客户端连接MongooseIM时PLAIN SASL认证失败问题求助
Let's break down your issue: you're hitting a SASLError using PLAIN: not-authorized when connecting to your MongooseIM server (using local database authentication) via Smack, but other clients like Jitsi work perfectly. This tells us the problem is almost certainly on the client side—either in how Smack is configured or how it's handling your authentication data.
Here are targeted steps to diagnose and fix this:
1. Inspect the PLAIN SASL Payload
Looking at your captured auth packet:
<auth xmlns='urn:ietf:params:xml:ns:xmpp-sasl' mechanism='PLAIN'>ADkyMzE1NTEwNDI5MgA=</auth>
Decoding the Base64 string ADkyMzE1NTEwNDI5MgA= gives \x00923155104292\x00—notice the empty password field (the final null byte has no content before it). This means Smack isn't passing your password correctly to the PLAIN mechanism.
Fix:
- Add debug logs to confirm
mAccount.getPassword()returns a valid, non-empty value:Log.d(TAG, "Username: " + mAccount.getUserName() + ", Password present: " + (mAccount.getPassword() != null && !mAccount.getPassword().isEmpty())); - Check if the password is being truncated, cleared, or modified elsewhere in your code before passing it to the Smack configuration.
2. Correct the Username Format
MongooseIM's internal authentication typically expects the local part of the JID (e.g., test instead of test@ip) rather than the full JID. Your stream's from field uses the full JID, which might be causing a mismatch with the server's user records.
Fix:
Extract the local part from your full JID before passing it to Smack:
import org.jxmpp.jid.Jid; import org.jxmpp.jid.impl.JidCreate; // ... String fullJid = mAccount.getUserName(); Jid jid = JidCreate.from(fullJid); String localUsername = jid.getLocalpart().toString(); XMPPTCPConnectionConfiguration.Builder builder = XMPPTCPConnectionConfiguration.builder() .setUsernameAndPassword(localUsername, mAccount.getPassword()) // rest of your configuration...
3. Simplify SASL Mechanism Setup
Your current code manually registers SASLPlainMechanism and manages blacklists, which could introduce unintended conflicts. Smack supports PLAIN by default, so you can simplify this configuration:
// Only blacklist the mechanisms you don't want to use SASLAuthentication.blacklistSASLMechanism("DIGEST-MD5"); SASLAuthentication.blacklistSASLMechanism("SCRAM-SHA-1"); // Remove the manual registration of SASLPlainMechanism—Smack's native implementation works fine // SASLAuthentication.registerSASLMechanism(new SASLPlainMechanism());
4. Double-Check MongooseIM's Auth Configuration (Just to Be Sure)
Even though Jitsi works, confirm your MongooseIM server is set up correctly for internal authentication:
- In
mongooseim.cfg, verify these settings:{auth_method, internal}, {password_format, plain} % This should match how you stored user passwords; Jitsi works so this is likely correct - Ensure the user
923155104292exists in the MongooseIM database with the correct plaintext password.
5. Cross-Reference with Jitsi's Traffic
Use a tool like Wireshark to capture Jitsi's authentication flow. Compare the Base64-encoded PLAIN payload Jitsi sends to what Smack is sending. This will directly confirm if the username/password encoding is the root cause.
内容的提问来源于stack exchange,提问作者user2934930

