Files
XC_VM/tests/Unit/StreamTokenCallSitesTest.php
T
rootandClaude Opus 5 74ef365f7d feat(streaming): tamper-proof stream tokens (AES-256-GCM), switched on per panel
Stream-link tokens were AES-CBC with a fixed IV and no MAC. A modified token
decrypts to modified bytes, and a padding error answers differently from a bad
credential (auth.php: BAD_TOKEN vs everything after), so with enough requests
anyone holding a link could read its username and password, or write a token of
their own. Several consumers trust a token's contents as they stand: the live /
vod / timeshift JSON (user_info, channel_info), HLS segment and key tokens, the
web player's proxy URL (fetched server-side) and the MAG portal's verify token
(passed to igbinary_unserialize).

Encryption::seal()/open() add AES-256-GCM with a random nonce, as
base64url(nonce ‖ ciphertext ‖ tag) — the same URL-safe alphabet, so no nginx
route or pattern changes. Every stream-link token is now made with
mintToken() and read with readToken(); StreamTokenCallSitesTest keeps new code
from calling the legacy encrypt()/decrypt() for one. Deterministic encryption
of stored data (HMAC keys looked up by ciphertext, image cache names) stays as
it was.

The new setting secure_stream_tokens (Settings → Tamper-proof Stream Tokens):
- on: tokens are sealed, and the legacy format is refused wherever a token's
  contents are trusted. /play/ playlist and portal links, RTMP tokens and
  probe's /play/ links still read the old format — they carry credentials that
  are looked up again, and saved playlists hold them — and every token auth.php
  cannot read now counts against the address (BruteforceGuard), which stops
  reading an old one through the error responses.
- off: legacy tokens are minted and every format is read.
Servers on an older version cannot read sealed tokens, so migration 021 turns it
off on a panel that has other servers (on for a single server, and for new
installs); turn it on once every server is updated.

key.php now also refuses a token that does not read, instead of serving the key
of stream 0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BbYsGKhirq9eRK8e6wsCHR
2026-09-13 08:49:06 +00:00

41 lines
1.6 KiB
PHP

<?php
use PHPUnit\Framework\TestCase;
/**
* Stream-link tokens go through Encryption::mintToken / readToken, which seal
* them when secure_stream_tokens is on. Calling the legacy encrypt()/decrypt()
* directly for a token quietly brings back the format that can be read and
* forged through padding errors, so only the uses that are not stream links —
* deterministic encryption of stored data — may do that.
*/
final class StreamTokenCallSitesTest extends TestCase {
/** Stored data that must stay deterministic: HMAC keys are looked up by ciphertext, image cache names are reversed by the self-heal. */
private const LEGACY_ALLOWED = array(
'Core/Auth/AuthService.php',
'Core/Util/Encryption.php',
'Core/Util/ImageUtils.php',
'Cli/Commands/ToolsCommand.php',
);
public function testOnlyStoredDataUsesTheLegacyCipherDirectly(): void {
$rRoot = dirname(__DIR__, 2) . '/src/';
$rOffenders = array();
$rIterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($rRoot, FilesystemIterator::SKIP_DOTS));
foreach ($rIterator as $rFile) {
$rPath = $rFile->getPathname();
if (substr($rPath, -4) !== '.php' || strpos($rPath, '/vendor/') !== false) {
continue;
}
$rRelative = substr($rPath, strlen($rRoot));
if (in_array($rRelative, self::LEGACY_ALLOWED, true)) {
continue;
}
if (preg_match('/Encryption::(encrypt|decrypt)\s*\(/', (string) file_get_contents($rPath))) {
$rOffenders[] = $rRelative;
}
}
$this->assertSame(array(), $rOffenders, 'use Encryption::mintToken / readToken for stream-link tokens');
}
}