mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-07 23:32:48 +03:00
Fix camera name collision bypassing admin check (#24516)
* don't let camera names waive the admin check on non-camera routes
The global admin guard skipped the admin check for any request whose first path segment matched a configured camera name, without looking at which route actually handled it. A camera named `faces`, `lpr`, `audio`, or `classification` let viewers reach the face, LPR, audio transcription, and classification endpoints that rely only on the global guard. The exemption now also requires the matched route to be a `/{camera_name}` route, so camera routes behave exactly as before.
* add test
This commit is contained in:
@@ -144,7 +144,9 @@ class BaseTestHttp(unittest.TestCase):
|
||||
except OSError:
|
||||
pass
|
||||
|
||||
def create_app(self, stats=None, event_metadata_publisher=None):
|
||||
def create_app(
|
||||
self, stats=None, event_metadata_publisher=None, enforce_default_admin=False
|
||||
):
|
||||
from frigate.api.auth import get_allowed_cameras_for_filter, get_current_user
|
||||
|
||||
app = create_fastapi_app(
|
||||
@@ -158,7 +160,7 @@ class BaseTestHttp(unittest.TestCase):
|
||||
event_metadata_publisher,
|
||||
None,
|
||||
DebugReplayManager(),
|
||||
enforce_default_admin=False,
|
||||
enforce_default_admin=enforce_default_admin,
|
||||
)
|
||||
|
||||
# Default test mocks for authentication
|
||||
|
||||
Reference in New Issue
Block a user