fix: log WHIP/WHEP authentication failures for abuse detection - #379
Conversation
The requireWhipAuth/requireWhepAuth hooks rejected invalid bearer tokens with a 401 but emitted no log entry, making brute-force and credential-stuffing attempts invisible. Add a warning-level log on each auth failure including the client IP and request path. The token value is never logged, and the path is sanitised to prevent log injection. Closes #238 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Code ReviewVerdict: LGTM Summary: Adds a warning-level log on WHIP/WHEP auth failures for abuse detection (Closes #238). Correct, minimal, and safe: the token value is never logged, the only user-controllable field logged ( Blocking
Warnings
Suggestions
Reviewed by a separate code-reviewer invocation (not the implementer). Self-authored PR: recording the verdict as a marker comment because GitHub blocks state-bearing self-review; merging via |
Summary
requireWhipAuth/requireWhepAuthhooks insrc/api_whip.tsandsrc/api_whep.tsrejected invalid/missing bearer tokens with a 401 but emitted no log entry, making brute-force and credential-stuffing attempts invisible.request.ip) and request path (request.url) so abuse can be detected.sanitizeForLoghelper to prevent log injection, matching the repo's defense-in-depth idiom.trustProxyor other configuration was touched, keeping the diff minimal and additive.Test plan
npm test) — 363 passednpm run typecheck)npm run lint) — 0 errorsWHIP/WHEP authentication failedwarning with IP and path is emitted on auth failure, and the bearer token never appears in any log lineCloses #238
🤖 Generated with Claude Code