Files
XC_VM/tests/Unit/AdminStreamTokenTest.php
T
rootandClaude Opus 5 74ef365f7d feat(streaming): tamper-proof stream tokens (AES-256-GCM), switched on per panel
Stream-link tokens were AES-CBC with a fixed IV and no MAC. A modified token
decrypts to modified bytes, and a padding error answers differently from a bad
credential (auth.php: BAD_TOKEN vs everything after), so with enough requests
anyone holding a link could read its username and password, or write a token of
their own. Several consumers trust a token's contents as they stand: the live /
vod / timeshift JSON (user_info, channel_info), HLS segment and key tokens, the
web player's proxy URL (fetched server-side) and the MAG portal's verify token
(passed to igbinary_unserialize).

Encryption::seal()/open() add AES-256-GCM with a random nonce, as
base64url(nonce ‖ ciphertext ‖ tag) — the same URL-safe alphabet, so no nginx
route or pattern changes. Every stream-link token is now made with
mintToken() and read with readToken(); StreamTokenCallSitesTest keeps new code
from calling the legacy encrypt()/decrypt() for one. Deterministic encryption
of stored data (HMAC keys looked up by ciphertext, image cache names) stays as
it was.

The new setting secure_stream_tokens (Settings → Tamper-proof Stream Tokens):
- on: tokens are sealed, and the legacy format is refused wherever a token's
  contents are trusted. /play/ playlist and portal links, RTMP tokens and
  probe's /play/ links still read the old format — they carry credentials that
  are looked up again, and saved playlists hold them — and every token auth.php
  cannot read now counts against the address (BruteforceGuard), which stops
  reading an old one through the error responses.
- off: legacy tokens are minted and every format is read.
Servers on an older version cannot read sealed tokens, so migration 021 turns it
off on a panel that has other servers (on for a single server, and for new
installs); turn it on once every server is updated.

key.php now also refuses a token that does not read, instead of serving the key
of stream 0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BbYsGKhirq9eRK8e6wsCHR
2026-09-13 08:49:06 +00:00

84 lines
3.3 KiB
PHP

<?php
use XcVm\Core\Util\Encryption;
use XcVm\Domain\Stream\AdminStreamToken;
use PHPUnit\Framework\TestCase;
/**
* @covers XcVm\Domain\Stream\AdminStreamToken
*/
final class AdminStreamTokenTest extends TestCase {
private const KEY = 'live-streaming-pass';
/** @param array<string,mixed> $data */
private function makeToken(array $data): string {
return Encryption::encrypt(json_encode($data), self::KEY, OPENSSL_EXTRA);
}
public function testDecodeReturnsNullOnGarbageCiphertext() {
$this->assertNull(AdminStreamToken::decode('not-a-valid-token', self::KEY, true));
}
public function testDecodeReturnsNullOnWrongKey() {
$token = $this->makeToken(array('stream_id' => 7, 'ip' => '1.2.3.4', 'expires' => time() + 60));
$this->assertNull(AdminStreamToken::decode($token, 'wrong-key', true));
}
public function testDecodeReturnsNullWhenRequiredFieldMissing() {
$token = $this->makeToken(array('stream_id' => 7, 'ip' => '1.2.3.4')); // no expires
$this->assertNull(AdminStreamToken::decode($token, self::KEY, true));
}
public function testDecodeExposesTypedFieldsAndKeepsStartRaw() {
$token = $this->makeToken(array(
'stream_id' => '7',
'ip' => '1.2.3.4',
'expires' => '123',
'container' => 'mp4',
'start' => '20250101-13',
'duration' => 30,
));
$rToken = AdminStreamToken::decode($token, self::KEY, true);
$this->assertNotNull($rToken);
$this->assertSame(7, $rToken->streamId);
$this->assertSame('1.2.3.4', $rToken->ip);
$this->assertSame(123, $rToken->expires);
$this->assertSame('mp4', $rToken->container);
$this->assertSame('20250101-13', $rToken->start); // raw — NOT cast to int
$this->assertSame(30, $rToken->duration);
}
public function testIsValidExpiryBoundaryIsInclusive() {
$rToken = AdminStreamToken::decode($this->makeToken(array('stream_id' => 1, 'ip' => '1.2.3.4', 'expires' => 1000)), self::KEY, true);
$this->assertTrue($rToken->isValid(false, '1.2.3.4', 1000)); // expires == now → valid
$this->assertFalse($rToken->isValid(false, '1.2.3.4', 1001)); // now past expiry
}
public function testIsValidExactIpMatch() {
$rToken = AdminStreamToken::decode($this->makeToken(array('stream_id' => 1, 'ip' => '1.2.3.4', 'expires' => 2000)), self::KEY, true);
$this->assertTrue($rToken->isValid(false, '1.2.3.4', 1000));
$this->assertFalse($rToken->isValid(false, '1.2.3.5', 1000));
}
public function testIsValidSubnetMatch() {
$rToken = AdminStreamToken::decode($this->makeToken(array('stream_id' => 1, 'ip' => '1.2.3.4', 'expires' => 2000)), self::KEY, true);
$this->assertTrue($rToken->isValid(true, '1.2.3.99', 1000)); // same /24
$this->assertFalse($rToken->isValid(true, '1.2.9.4', 1000)); // different third octet
}
/** A sealed token decodes whatever the setting; a legacy one only while it is still accepted. */
public function testDecodeReadsSealedTokensAndRefusesLegacyOnesWhenSecure() {
$data = array('stream_id' => 9, 'ip' => '1.2.3.4', 'expires' => 2000);
$sealed = Encryption::seal(json_encode($data), self::KEY, OPENSSL_EXTRA);
$this->assertSame(9, AdminStreamToken::decode($sealed, self::KEY, false)->streamId);
$this->assertSame(9, AdminStreamToken::decode($sealed, self::KEY, true)->streamId);
$this->assertNull(AdminStreamToken::decode($this->makeToken($data), self::KEY, false));
}
}