mirror of
https://github.com/meshtastic/firmware.git
synced 2026-09-29 17:55:25 -04:00
second pass adding beacons admin (#10839)
* second pass adding beacons admin * Bump protobufs submodule to merged MESHBEACON_CONFIG (PR #970) clod helped. * Gate MeshBeacon module config behind admin auth in PhoneAPI The FromRadio module-config sync copied moduleConfig.mesh_beacon unconditionally. MeshBeaconConfig embeds two ChannelSettings (broadcast_offer_channel, broadcast_on_channel) that carry PSKs, so an unauthorized client could exfiltrate channel PSKs when MESHTASTIC_PHONEAPI_ACCESS_CONTROL is enabled - bypassing the redaction already applied to mqtt/network/security config. Gate the payload copy on getAdminAuthorized(), mirroring the mqtt case; unauth clients now receive an empty MeshBeaconConfig. clod helped
This commit is contained in:
4 files changed
+30
-4
No files matched your search
@@ -1487,6 +1487,13 @@ void AdminModule::handleGetModuleConfig(const meshtastic_MeshPacket &req, const
|
||||
res.get_module_config_response.which_payload_variant = meshtastic_ModuleConfig_traffic_management_tag;
|
||||
res.get_module_config_response.payload_variant.traffic_management = moduleConfig.traffic_management;
|
||||
break;
|
||||
#if !MESHTASTIC_EXCLUDE_BEACON
|
||||
case meshtastic_AdminMessage_ModuleConfigType_MESHBEACON_CONFIG:
|
||||
configName = "MeshBeacon";
|
||||
res.get_module_config_response.which_payload_variant = meshtastic_ModuleConfig_mesh_beacon_tag;
|
||||
res.get_module_config_response.payload_variant.mesh_beacon = moduleConfig.mesh_beacon;
|
||||
break;
|
||||
#endif
|
||||
}
|
||||
LOG_INFO("Get module config: %s", configName);
|
||||
|
||||
|
||||
Reference in new issue
Block a user