Skip to content

fix(obsws): clear errors for a missing OBS password or challenge - #72

Merged
Soulhackzlol merged 1 commit into
mainfrom
fix/codeql-obsws
Oct 4, 2026
Merged

Soulhackzlol merged 1 commit into
mainfrom
fix/codeql-obsws

Conversation

@Soulhackzlol

Copy link
Copy Markdown
Owner

Follow-up to 0.1.15, from CodeQL's rust/hard-coded-cryptographic-value alerts on src/integrations/obsws.rs.

  • Password is an Option. None when OBS's WebSocket server doesn't ask for one. A server that asks for a password that isn't saved is now reported when its settings are read, instead of at connect time.
  • No proof from empty text. A Hello asking for a password without its salt or challenge now fails with a clear message, instead of sending a proof OBS can only refuse.

Both new error paths are covered by tests. The remaining alerts from that rule are test fixtures (#[cfg(test)], the obs-websocket protocol example, the password-hash vectors) and are not changed here.

Test: cargo test obsws

The WebSocket password was an empty string both when OBS asks for none
and when it asks for one that isn't saved. It is now None when OBS's
server doesn't ask for one, and a server that asks with no saved password
is reported as soon as its settings are read.

A Hello that asks for a password without its salt or challenge used to
get a proof built from empty text, which OBS can only refuse with an
unclear close code. It now fails with a message saying so.

Also clears CodeQL's two rust/hard-coded-cryptographic-value alerts on
shipping code (the empty fallbacks flowed into the password proof).
@Soulhackzlol
Soulhackzlol merged commit c598cf3 into main Oct 4, 2026
6 checks passed
@Soulhackzlol
Soulhackzlol deleted the fix/codeql-obsws branch October 4, 2026 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant