From cca0f5a0cbd91073f26fbbd366287ede3b73a166 Mon Sep 17 00:00:00 2001 From: Alessandro Ros Date: Mon, 17 Aug 2026 18:30:48 +0200 Subject: [PATCH] change default value of authHTTPExclude (#6103) by default, do not exclude any action from HTTP authentication. Old value triggered several security warnings. --- docs/2-features/06-authentication.md | 1 - internal/conf/conf.go | 11 ----------- mediamtx.yml | 11 ++++------- 3 files changed, 4 insertions(+), 19 deletions(-) diff --git a/docs/2-features/06-authentication.md b/docs/2-features/06-authentication.md index 98f5e370..97069b79 100644 --- a/docs/2-features/06-authentication.md +++ b/docs/2-features/06-authentication.md @@ -79,7 +79,6 @@ Authentication can be delegated to an external HTTP server: ```yml authMethod: http authHTTPAddress: http://myauthserver/auth -authHTTPExclude: [] # explicitly clear authHTTPExclude to validate every action ``` Each time a user needs to be authenticated, the specified URL will be requested with the POST method and this payload: diff --git a/internal/conf/conf.go b/internal/conf/conf.go index 19457f3d..291cebdc 100644 --- a/internal/conf/conf.go +++ b/internal/conf/conf.go @@ -439,17 +439,6 @@ func (conf *Conf) setDefaults() { // Authentication conf.AuthMethod = AuthMethodInternal conf.AuthInternalUsers = defaultAuthInternalUsers - conf.AuthHTTPExclude = []AuthInternalUserPermission{ - { - Action: AuthActionAPI, - }, - { - Action: AuthActionMetrics, - }, - { - Action: AuthActionPprof, - }, - } conf.AuthJWTClaimKey = "mediamtx_permissions" // Control API diff --git a/mediamtx.yml b/mediamtx.yml index 0ea85782..f4e141db 100644 --- a/mediamtx.yml +++ b/mediamtx.yml @@ -93,10 +93,10 @@ authInternalUsers: # HTTP-based authentication. # URL called to perform authentication. Every time a user wants -# to authenticate, the server calls this URL with the POST method +# to perform an action, the server calls this URL with the POST method # and a payload described in the documentation. -# If the response code is 20x, authentication is accepted, otherwise -# it is discarded. +# If the response code is 20x, the action is allowed, otherwise +# it is forbidden. authHTTPAddress: # If the HTTP authentication URL has a self-signed or invalid certificate, # you can provide the fingerprint of the certificate in order to @@ -106,10 +106,7 @@ authHTTPAddress: authHTTPFingerprint: # Actions to exclude from HTTP-based authentication. # Format is the same as the one of user permissions. -authHTTPExclude: - - action: api - - action: metrics - - action: pprof +authHTTPExclude: [] # JWT-based authentication. # Users have to log in through an external identity server and obtain a JWT.