From c1776dc5a454597d552b12cb931af6193e2ae7fe Mon Sep 17 00:00:00 2001 From: Evgeny Date: Wed, 30 Sep 2026 09:04:28 +0100 Subject: [PATCH] server: improve control port auth (#1898) Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com> --- src/Simplex/Messaging/Protocol.hs | 6 +++++- src/Simplex/Messaging/Server.hs | 1 + 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/src/Simplex/Messaging/Protocol.hs b/src/Simplex/Messaging/Protocol.hs index e2cbef3a4..14f2a967f 100644 --- a/src/Simplex/Messaging/Protocol.hs +++ b/src/Simplex/Messaging/Protocol.hs @@ -241,6 +241,7 @@ import Data.Attoparsec.ByteString.Char8 (Parser, ()) import qualified Data.Attoparsec.ByteString.Char8 as A import Data.Bifunctor (bimap, first) import Data.Bits (xor) +import qualified Data.ByteArray as BA import qualified Data.ByteString as BS import qualified Data.ByteString.Base64 as B64 import Data.ByteString.Char8 (ByteString) @@ -1323,7 +1324,10 @@ instance ProtocolTypeI p => FromJSON (ProtocolServer p) where parseJSON = strParseJSON "ProtocolServer" newtype BasicAuth = BasicAuth {unBasicAuth :: ByteString} - deriving (Eq, Ord, Show) + deriving (Ord, Show) + +instance Eq BasicAuth where + BasicAuth s == BasicAuth s' = BA.constEq s s' instance IsString BasicAuth where fromString = BasicAuth . B.pack diff --git a/src/Simplex/Messaging/Server.hs b/src/Simplex/Messaging/Server.hs index 1c58a5a49..405e9b5f0 100644 --- a/src/Simplex/Messaging/Server.hs +++ b/src/Simplex/Messaging/Server.hs @@ -1092,6 +1092,7 @@ controlPortAuth h user admin role auth = do readTVarIO role >>= \case CPRNone -> do atomically $ writeTVar role $! newRole + when (newRole == CPRNone) $ logWarn "ControlPort: failed auth" hPutStrLn h $ currentRole newRole r -> hPutStrLn h $ currentRole r <> if r == newRole then "" else ", start new session to change." where