second pass adding beacons admin (#10839)

* second pass adding beacons admin

* Bump protobufs submodule to merged MESHBEACON_CONFIG (PR #970)

clod helped.

* Gate MeshBeacon module config behind admin auth in PhoneAPI

The FromRadio module-config sync copied moduleConfig.mesh_beacon unconditionally. MeshBeaconConfig embeds two ChannelSettings (broadcast_offer_channel, broadcast_on_channel) that carry PSKs, so an unauthorized client could exfiltrate channel PSKs when MESHTASTIC_PHONEAPI_ACCESS_CONTROL is enabled - bypassing the redaction already applied to mqtt/network/security config.
Gate the payload copy on getAdminAuthorized(), mirroring the mqtt case; unauth clients now receive an empty MeshBeaconConfig.

clod helped
This commit is contained in:
Tom authored and GitHub committed 2026-07-02 23:06:33 +01:00
1 parent b4dd76a4db
commit fc7043f117
4 files changed
+30 -4

No files matched your search

+17
View File
@@ -897,6 +897,23 @@ size_t PhoneAPI::getFromRadio(uint8_t *buf)
fromRadioScratch.moduleConfig.which_payload_variant = meshtastic_ModuleConfig_tak_tag;
fromRadioScratch.moduleConfig.payload_variant.tak = moduleConfig.tak;
break;
#if !MESHTASTIC_EXCLUDE_BEACON
case meshtastic_ModuleConfig_mesh_beacon_tag:
LOG_DEBUG("Send module config: mesh beacon");
fromRadioScratch.moduleConfig.which_payload_variant = meshtastic_ModuleConfig_mesh_beacon_tag;
#ifdef MESHTASTIC_PHONEAPI_ACCESS_CONTROL
if (!getAdminAuthorized()) {
// Unauthenticated: emit an empty MeshBeaconConfig (zero-init from
// the top-of-loop memset). The embedded ChannelSettings
// (broadcast_offer_channel / broadcast_on_channel) carry PSKs that
// must not be visible to an unauth client.
} else
#endif
{
fromRadioScratch.moduleConfig.payload_variant.mesh_beacon = moduleConfig.mesh_beacon;
}
break;
#endif
default:
LOG_DEBUG("Unhandled module config type %d", config_state);
}