Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions src/api_whep.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -370,6 +370,32 @@ describe('apiWhep', () => {
expect(res.headers['www-authenticate']).toMatch(/Bearer.*realm="whep"/i);
});

it('should log a warning (without the token) on auth failure for abuse detection', async () => {
const fastify = await createAuthServer();
const res = await fastify.inject({
method: 'POST',
url: '/whep/123/456/testuser',
headers: {
'content-type': 'application/sdp',
authorization: 'Bearer super-secret-token'
},
payload:
'v=0\r\no=- 0 0 IN IP4 127.0.0.1\r\nm=audio 0 RTP/AVP 0\r\na=mid:0\r\n'
});
expect(res.statusCode).toBe(401);
expect(mockLogger.warn).toHaveBeenCalledWith(
expect.stringMatching(/WHEP authentication failed/i)
);
// The token value must never be logged.
for (const call of mockLogger.warn.mock.calls) {
for (const arg of call) {
if (typeof arg === 'string') {
expect(arg).not.toContain('super-secret-token');
}
}
}
});

it('should return 401 with wrong token auth key', async () => {
const fastify = await createAuthServer();
const res = await fastify.inject({
Expand Down
7 changes: 7 additions & 0 deletions src/api_whep.ts
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,13 @@ export const apiWhep: FastifyPluginCallback<ApiWhepOptions> = (
tokenBuf.length === keyBuf.length && timingSafeEqual(tokenBuf, keyBuf);

if (!authHeader || typeof authHeader !== 'string' || !isValid) {
// Log auth failures (without the token) so brute-force/credential-stuffing
// attempts are visible for abuse detection. See #238.
Log().warn(
`WHEP authentication failed - IP: ${request.ip}, path: ${sanitizeForLog(
request.url
)}`
);
reply
.header('WWW-Authenticate', 'Bearer realm="whep", charset="UTF-8"')
.code(401)
Expand Down
26 changes: 26 additions & 0 deletions src/api_whip.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -380,6 +380,32 @@ describe('apiWhip', () => {
expect(res.headers['www-authenticate']).toMatch(/Bearer.*realm="whip"/i);
});

it('should log a warning (without the token) on auth failure for abuse detection', async () => {
const fastify = await createAuthServer();
const res = await fastify.inject({
method: 'POST',
url: '/whip/123/456/testuser',
headers: {
'content-type': 'application/sdp',
authorization: 'Bearer super-secret-token'
},
payload:
'v=0\r\no=- 0 0 IN IP4 127.0.0.1\r\nm=audio 0 RTP/AVP 0\r\na=mid:0\r\n'
});
expect(res.statusCode).toBe(401);
expect(mockLogger.warn).toHaveBeenCalledWith(
expect.stringMatching(/WHIP authentication failed/i)
);
// The token value must never be logged.
for (const call of mockLogger.warn.mock.calls) {
for (const arg of call) {
if (typeof arg === 'string') {
expect(arg).not.toContain('super-secret-token');
}
}
}
});

it('should return 401 with wrong token auth key', async () => {
const fastify = await createAuthServer();
const res = await fastify.inject({
Expand Down
7 changes: 7 additions & 0 deletions src/api_whip.ts
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,13 @@ export const apiWhip: FastifyPluginCallback<ApiWhipOptions> = (
tokenBuf.length === keyBuf.length && timingSafeEqual(tokenBuf, keyBuf);

if (!authHeader || typeof authHeader !== 'string' || !isValid) {
// Log auth failures (without the token) so brute-force/credential-stuffing
// attempts are visible for abuse detection. See #238.
Log().warn(
`WHIP authentication failed - IP: ${request.ip}, path: ${sanitizeForLog(
request.url
)}`
);
reply
.header('WWW-Authenticate', 'Bearer realm="whip", charset="UTF-8"')
.code(401)
Expand Down
Loading