Skip to content

Conversation

@winlinvip
Copy link
Member

@winlinvip winlinvip commented Jun 21, 2023

Refer to talk at CommCon, the WHIP DELETE may be security risk if not verify.

In Sandro Gauci's talk at CommCon, he mentioned that the WHIP DELETE could pose a security risk if not properly verified. We have added a token for verification, but in the future, we should consider supporting Bear tokens for enhanced security.

See WebRTC & Video Delivery application security - what could possibly go wrong? for more details.

See FFmpeg commit WHIP: Enhance security by using BearToken for delete API.

@winlinvip winlinvip merged commit b1d1c7a into ossrs:develop Jul 1, 2023
winlinvip added a commit that referenced this pull request Jul 1, 2023
@winlinvip winlinvip added the EnglishNative This issue is conveyed exclusively in English. label Jul 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

EnglishNative This issue is conveyed exclusively in English.

Development

Successfully merging this pull request may close these issues.

2 participants