security(ws): /ws/realtime accepts unauthenticated connections #125
Labels
No labels
blocked
bug
enhancement
high-priority
low-priority
needs-info
needs-triage
ready-for-agent
ready-for-human
referenced
research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
gabogg/hikcentral#125
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Security. High priority.
Problem
/ws/realtimeonmaster(app/main.py,websocket_endpoint) accepts every connection with no authentication:Anyone who can reach the server can open the socket and receive every broadcast. That includes live door states and transitions, access cycles (cardholder names and card numbers when the name resolves, #46), occupancy updates and system status, with no login.
Found during the pass-2 review of #123 (viewer role). #123 refuses a viewer with 1008 only when the viewer sends a token, so a viewer who leaves out the token still gets the stream, and so does an anonymous client.
Decisions
hc_sessioncookie and/or the token the client already sends. With no session or an invalid one, the server closes with1008 POLICY_VIOLATIONbefore accepting.1008), as #121 decided.Acceptance
Coordination
#123 is changing the same handler. Whichever lands second rebases onto the other. If #123 merges first, this issue removes the "only when a token is sent" gap it leaves.
🤖 Generated with Claude Code