Replies: 4 comments 2 replies
-
|
This would be useless without also having HTTPS support. That is a prerequisite for any type of password protection. |
Beta Was this translation helpful? Give feedback.
-
|
previous conversation: #22 |
Beta Was this translation helpful? Give feedback.
-
|
Based off the conversation @untitaker mentioned then it seems like adding TLS support even with a locally generated self signed root CA we could get some protection. That would at least prevent leaking the credential, plus there's some CSRF issues while there's no auth which could have an attacker on another tab make a call to delete recordings or do all sorts of stuff. |
Beta Was this translation helpful? Give feedback.
-
|
Any objections to me starting with adding TLS support then? |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I would like to add basic HTTP auth to the endpoints and the UI. I can get this done pretty quick.
Reason needed
This is a concern since every device that has connected to the wifi will essentially remember the password forever and there's no way to revoke access. A compromised device that once accessed it can't be prevented from messing with the rayhunter.
Proposed Changes
Add to the configuration section in the GUI an area
On the backend endpoints it would enforce the password (if enabled). Basic http auth is compatible with pretty much everything including CURL.
Beta Was this translation helpful? Give feedback.
All reactions