Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TOTP stream security #6681

Open
filip-ams opened this issue Sep 30, 2024 · 0 comments
Open

TOTP stream security #6681

filip-ams opened this issue Sep 30, 2024 · 0 comments

Comments

@filip-ams
Copy link

Short description

We have TOTP stream security enabled on our test server, and after some playing around, it seems that we have found a way to keep playing while the stream is blocked for the user.

This can be done by providing the subcriberId and subscriberCode only on the first request and only providing the cookie on subsequent requests. This way, it appears that Ant Media Server does not know which subscriber is watching, and thus watching the stream cannot be blocked for this anonymous user.

Logs

I have asked for logs from the user and will provide them here when I receive them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Next Sprint
Development

No branches or pull requests

1 participant