fix(whip/whep): warn loudly when WHIP_AUTH_KEY is unset - #368
Conversation
Previously the WHIP and WHEP auth validators silently returned true when WHIP_AUTH_KEY was not configured, leaving these public internet-facing WebRTC ingest/egress endpoints completely unauthenticated with no operator-visible signal. Anyone able to reach the server could publish audio into, or subscribe to, live productions. Log a single loud SECURITY warning at plugin registration (startup) when the key is absent, mirroring the existing REAUTH_AUTH_KEY warning in server.ts. Auth still stays open by default to preserve backward compatibility for deployments that intentionally run without a key (Option B from the issue); fail-closed would break those deployments. Closes #223 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Code review verdict: LGTM (separate code-reviewer invocation, per the self-authored-PR review path — self-approval is blocked by GitHub, so this marker records the verdict). Minimal, focused, correct. Adds a one-time Non-blocking follow-ups (not gating): (1) the |
Summary
truesilently whenWHIP_AUTH_KEYwas unset, leaving these public, internet-facing WebRTC ingest/egress endpoints fully unauthenticated with no operator-visible signal.SECURITY: ...WARN at plugin registration (startup) in bothsrc/api_whip.tsandsrc/api_whep.tswhen the key is absent, so operators are aware of the open endpoints.REAUTH_AUTH_KEYwarning pattern inserver.ts.Test plan
npm test) — 336 passed, 18 suites; new warning visible in test outputnpm run typecheck) — 0 errorsnpm run lint) — 0 errors (only pre-existing warnings)WHIP_AUTH_KEYis unset, and auth still enforces a Bearer token when the key is setCloses #223
🤖 Generated with Claude Code