Commit Graph
2 Commits
Author SHA1 Message Date
rootandClaude Opus 5 74ef365f7d feat(streaming): tamper-proof stream tokens (AES-256-GCM), switched on per panel
Stream-link tokens were AES-CBC with a fixed IV and no MAC. A modified token
decrypts to modified bytes, and a padding error answers differently from a bad
credential (auth.php: BAD_TOKEN vs everything after), so with enough requests
anyone holding a link could read its username and password, or write a token of
their own. Several consumers trust a token's contents as they stand: the live /
vod / timeshift JSON (user_info, channel_info), HLS segment and key tokens, the
web player's proxy URL (fetched server-side) and the MAG portal's verify token
(passed to igbinary_unserialize).

Encryption::seal()/open() add AES-256-GCM with a random nonce, as
base64url(nonce ‖ ciphertext ‖ tag) — the same URL-safe alphabet, so no nginx
route or pattern changes. Every stream-link token is now made with
mintToken() and read with readToken(); StreamTokenCallSitesTest keeps new code
from calling the legacy encrypt()/decrypt() for one. Deterministic encryption
of stored data (HMAC keys looked up by ciphertext, image cache names) stays as
it was.

The new setting secure_stream_tokens (Settings → Tamper-proof Stream Tokens):
- on: tokens are sealed, and the legacy format is refused wherever a token's
  contents are trusted. /play/ playlist and portal links, RTMP tokens and
  probe's /play/ links still read the old format — they carry credentials that
  are looked up again, and saved playlists hold them — and every token auth.php
  cannot read now counts against the address (BruteforceGuard), which stops
  reading an old one through the error responses.
- off: legacy tokens are minted and every format is read.
Servers on an older version cannot read sealed tokens, so migration 021 turns it
off on a panel that has other servers (on for a single server, and for new
installs); turn it on once every server is updated.

key.php now also refuses a token that does not read, instead of serving the key
of stream 0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BbYsGKhirq9eRK8e6wsCHR
2026-09-13 08:49:06 +00:00
Divarion_D 5b35907388 refactor(admin): readable, testable stream entry points (+2 bug fixes)
Clean up the admin stream loopback scripts (api/live/proxy_api/thumb/
timeshift/vod) for readability and to give their core logic unit-test
coverage, without changing behavior — except the two bugs called out below.

Readability:
- Invert the pervasive empty `if (c) {} else { body }` into `if (!c) { body }`.
- Flatten deep if/else nests into guard-clause / elseif chains (live, vod).
- Drop dead blank lines.

Testability (pure logic extracted, then covered):
- New value object XcVm\Domain\Stream\AdminStreamToken (decode + isValid)
  replaces the uitoken decrypt+expiry+IP block duplicated across live/thumb/
  timeshift/vod; it reuses the existing-but-unadopted NetworkUtils::ipMatches().
  Token start/duration are kept raw (a timeshift date string must not be cast).
- Four pure helpers folded into the existing StreamUtils (not new one-method
  classes): sanitizeSegmentName, containerMimeType, timeshiftStartTimestamp,
  segmentRetryBudget — replacing inline path sanitization, a 44-line MIME
  switch, the timeshift date parser, and the retry-budget math.
- Tests: AdminStreamTokenTest, NetworkUtilsTest (ipMatches had no coverage),
  and StreamUtilsTest extended for the four helpers. OPENSSL_EXTRA is defined
  in tests/bootstrap.php so token round-trips work.

Bug fixes (behavior changes):
- live: the retry budget used `$rTotalFails < intval(...) ?: 20`, which by
  operator precedence parsed as `(... < ...) ?: 20` — always truthy — so the
  `seg_time * 2` floor was ignored and the budget was always the configured
  wait. Now max(seg_time*2, wait ?: 20) via StreamUtils::segmentRetryBudget().
- proxy_api: the per-second byte-rate divided by `time() - last`, which is 0
  for two samples in the same second (division by zero). Clamp to >= 1s.
2026-09-09 22:32:37 +03:00