Fix camera name collision bypassing admin check (#24516)

* don't let camera names waive the admin check on non-camera routes

The global admin guard skipped the admin check for any request whose first path segment matched a configured camera name, without looking at which route actually handled it. A camera named `faces`, `lpr`, `audio`, or `classification` let viewers reach the face, LPR, audio transcription, and classification endpoints that rely only on the global guard. The exemption now also requires the matched route to be a `/{camera_name}` route, so camera routes behave exactly as before.

* add test
This commit is contained in:
Josh Hawkins
2026-10-01 08:56:04 -06:00
committed by GitHub
parent 160d213025
commit 17a8efa09c
3 changed files with 35 additions and 19 deletions
+4 -2
View File
@@ -144,7 +144,9 @@ class BaseTestHttp(unittest.TestCase):
except OSError:
pass
def create_app(self, stats=None, event_metadata_publisher=None):
def create_app(
self, stats=None, event_metadata_publisher=None, enforce_default_admin=False
):
from frigate.api.auth import get_allowed_cameras_for_filter, get_current_user
app = create_fastapi_app(
@@ -158,7 +160,7 @@ class BaseTestHttp(unittest.TestCase):
event_metadata_publisher,
None,
DebugReplayManager(),
enforce_default_admin=False,
enforce_default_admin=enforce_default_admin,
)
# Default test mocks for authentication