mirror of
https://github.com/AletheiaVox/signal_bridge_remote.git
synced 2026-10-07 03:18:17 +08:00
fix(security): require auth on every MCP request; stop stale refreshes banning clients
- Remove the authless "sole connected phone" fallback and SB_REQUIRE_MCP_AUTH: an unauthenticated request no longer reaches whichever phone is online alone. - Mcp-Session-Id is no longer a credential; the Bearer token is checked on every request (MCP auth spec). - Refresh tokens live 90 days (was 30, equal to the access token, so they were always dead when first needed). - A rejected refresh no longer counts toward the IP ban: a client with an expired token was retrying into a self-renewing ban on its own IP. - 401s carry the RFC 9728 WWW-Authenticate discovery header.
This commit is contained in:
@@ -14,10 +14,6 @@ SB_PORT=8420
|
||||
SB_REGISTRATION_OPEN=true
|
||||
# How long login tokens last (hours)
|
||||
SB_TOKEN_EXPIRY_HOURS=168
|
||||
# Set to "true" to require OAuth/token auth on every MCP request (multi-user
|
||||
# servers). Default "false" keeps the single-user convenience fallback: an
|
||||
# unauthenticated MCP request is routed to the sole connected phone session.
|
||||
SB_REQUIRE_MCP_AUTH=false
|
||||
|
||||
# ═══ Rate Limiting (anti-harassment) ════════════════════════════════════
|
||||
# Auth endpoint: strict to prevent credential stuffing
|
||||
|
||||
Reference in New Issue
Block a user