Conversation
Add `Credential::auth_username: Option<String>` and `Credential::digest_username()` so the digest authentication username can differ from the AOR user. PBXs such as 3CX or Asterisk PJSIP `auth` objects hand out an "Authentication ID" that is not the extension: the AOR is `sip:01@pbx`, but the Authorization / Proxy-Authorization header and the digest must use that ID. With a single `username` this was not expressible (registering as the extension got 403, registering as the auth ID registered the wrong AOR). `handle_client_authenticate` now uses `digest_username()` for the digest and the header; REGISTER From/To/Contact and the dialogs' local contact keep using `username`. `None` (the default; `Credential` now derives `Default`) keeps the previous behavior unchanged. Tests: digest_username fallback, 401 and 407 answered with the auth username (digest verified, and shown to differ from one computed with the AOR user), and the unchanged default path. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit 521a36c)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add
Credential::auth_username: Option<String>andCredential::digest_username()so the digest authentication username can differ from the AOR user. PBXs such as 3CX or Asterisk PJSIPauthobjects hand out an "Authentication ID" that is not the extension: the AOR issip:01@pbx, but the Authorization / Proxy-Authorization header and the digest must use that ID. With a singleusernamethis was not expressible (registering as the extension got 403, registering as the auth ID registered the wrong AOR).handle_client_authenticatenow usesdigest_username()for the digest and the header; REGISTER From/To/Contact and the dialogs' local contact keep usingusername.None(the default;Credentialnow derivesDefault) keeps the previous behavior unchanged.Tests: digest_username fallback, 401 and 407 answered with the auth username (digest verified, and shown to differ from one computed with the AOR user), and the unchanged default path.
-> Also tested on a real use-case against a 3CX :smile