Skip to content

feat: separate digest username in Credential (auth_username) - #153

Open
paresy wants to merge 1 commit into
restsend:mainfrom
paresy:symcon/0.5.18-auth-username
Open

paresy wants to merge 1 commit into
restsend:mainfrom
paresy:symcon/0.5.18-auth-username

Conversation

@paresy

@paresy paresy commented Sep 28, 2026

Copy link
Copy Markdown

Add Credential::auth_username: Option<String> and Credential::digest_username() so the digest authentication username can differ from the AOR user. PBXs such as 3CX or Asterisk PJSIP auth objects hand out an "Authentication ID" that is not the extension: the AOR is sip:01@pbx, but the Authorization / Proxy-Authorization header and the digest must use that ID. With a single username this was not expressible (registering as the extension got 403, registering as the auth ID registered the wrong AOR).

handle_client_authenticate now uses digest_username() for the digest and the header; REGISTER From/To/Contact and the dialogs' local contact keep using username. None (the default; Credential now derives Default) keeps the previous behavior unchanged.

Tests: digest_username fallback, 401 and 407 answered with the auth username (digest verified, and shown to differ from one computed with the AOR user), and the unchanged default path.

-> Also tested on a real use-case against a 3CX :smile

Add `Credential::auth_username: Option<String>` and
`Credential::digest_username()` so the digest authentication username can
differ from the AOR user. PBXs such as 3CX or Asterisk PJSIP `auth`
objects hand out an "Authentication ID" that is not the extension: the
AOR is `sip:01@pbx`, but the Authorization / Proxy-Authorization header
and the digest must use that ID. With a single `username` this was not
expressible (registering as the extension got 403, registering as the
auth ID registered the wrong AOR).

`handle_client_authenticate` now uses `digest_username()` for the digest
and the header; REGISTER From/To/Contact and the dialogs' local contact
keep using `username`. `None` (the default; `Credential` now derives
`Default`) keeps the previous behavior unchanged.

Tests: digest_username fallback, 401 and 407 answered with the auth
username (digest verified, and shown to differ from one computed with the
AOR user), and the unchanged default path.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 521a36c)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant