<div dir="ltr">ha funny stating about authorization i can't find anything either</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Feb 24, 2023 at 12:40 PM HGAlt <<a href="mailto:hgalt@gmx.net">hgalt@gmx.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Good Morning Philipp,<br>
<br>
that make be a good point.<br>
But it would be very helpful, if in the Icecast documentation would be very clear defined, which kind of authorization is required for which server version.<br>
<br>
At least, I could not find anything!<br>
<br>
-----Ursprüngliche Nachricht-----<br>
Von: Icecast [mailto:<a href="mailto:icecast-bounces@xiph.org" target="_blank">icecast-bounces@xiph.org</a>] Im Auftrag von Philipp Schafft<br>
Gesendet: Samstag, 18. Februar 2023 20:53<br>
An: Icecast streaming server user discussions<br>
Betreff: Re: [Icecast] Send admin kill request to server<br>
<br>
Good afternoon,<br>
<br>
On Sat, 2023-02-18 at 13:23 +0100, HGAlt wrote:<br>
> Hi everybody,<br>
><br>
> finally I found a solution!<br>
><br>
> First, Icecast requires a Basic Authorization, which has to provide<br>
> via a header.<br>
<br>
This is not fully correct. It depends on the configuration and may change with different versions of the server.<br>
<br>
An important note here, and to be honest the main reason why I answer:<br>
NEVER EVER just append a random Authorization:-header without implementing all of the HTTP authorisation mechanism. If you do so you basically are broadcasting cleartext passwords to random peers, and are likely to get in trouble with changes of software versions or configurations. It is a big no-go. Always use the mechanism as provided by your HTTP implementieren.<br>
<br>
Please see the relevant standards for a full discussion on how and why this breaks security and interoperability.<br>
<br>
<br>
> But this can’t be done via JavaScript or JQuery, due the security<br>
> features of the browsers.<br>
> For more detail information see<br>
> <a href="https://stackoverflow.com/questions/75463305/difference-basic-authoriz" rel="noreferrer" target="_blank">https://stackoverflow.com/questions/75463305/difference-basic-authoriz</a><br>
> ation-between-postman-and-jquery-ajax/75493285#75493285<br>
> .<br>
<br>
If you adhere to CORS it works fine for me. A simple XHR request with credentials passed via open() worked.<br>
<br>
Naturally you are bound to CORS. Icecast can announce any kind of CORS settings via it's config.<br>
<br>
XHR also allows you direct access to the response Icecast gives you as it provides you with the response's DOM. So you can directly check the result. :)<br>
<br>
<br>
With best regards,<br>
<br>
> Von: Icecast [mailto:<a href="mailto:icecast-bounces@xiph.org" target="_blank">icecast-bounces@xiph.org</a>] Im Auftrag von HGAlt<br>
> Gesendet: Donnerstag, 16. Februar 2023 15:49<br>
> An: 'Icecast streaming server user discussions'<br>
> Betreff: Re: [Icecast] Send admin kill request to server<br>
><br>
> Hi Fred,<br>
><br>
> I am understand the requirements already a little bit better.<br>
><br>
> What I have to Do is a HTTP GET with a Basic Authorization in the<br>
> header. I have tested it with ‘Postman’ and it works fine with<br>
> Icecast.<br>
> But I have to do it with Javascript or JQuery. Therefore curl doesn’t<br>
> help me.<br>
><br>
> I try to use Ajax for that, but something goes wrong.<br>
> If I do it without Autorization, I got a return message which says<br>
> 'Authentication required'.<br>
> If I enable the Autorization it tells me only readyState: 0.<br>
><br>
> If I will find a solution, I will post it here.<br>
><br>
> Cheers<br>
><br>
> Von: Icecast [mailto:<a href="mailto:icecast-bounces@xiph.org" target="_blank">icecast-bounces@xiph.org</a>] Im Auftrag von Fred<br>
> Gleason<br>
> Gesendet: Mittwoch, 15. Februar 2023 16:57<br>
> An: Icecast streaming server user discussions<br>
> Betreff: Re: [Icecast] Send admin kill request to server<br>
><br>
> On Feb 14, 2023, at 13:24, HGAlt <<a href="mailto:hgalt@gmx.net" target="_blank">hgalt@gmx.net</a>> wrote:<br>
><br>
> > I am a little bit confused!<br>
> ><br>
> > <a href="http://192.168.1.10:8000/admin/killclient?mount=/mystream.ogg&id=21" rel="noreferrer" target="_blank">http://192.168.1.10:8000/admin/killclient?mount=/mystream.ogg&id=21</a><br>
> ><br>
> > This is an example of the Icecast documentation for kill a client.<br>
> > And this is a HTTP GET, which is send to the Icecast server.<br>
> > You also wrote, that there are no user and pass for an API.<br>
> ><br>
> > What I have to know, what does the Icecast server expect?<br>
> > If there is no user and pass, how the server knows, that is a valid<br>
> > request.<br>
><br>
><br>
> You should be able to send this with proper HTTP authentication<br>
> parameters by using CURL. Something like:<br>
><br>
> curl -u admin:hackme<br>
> <a href="http://192.168.1.10:8000/admin/killclient?mount=/mystream.ogg&id=21" rel="noreferrer" target="_blank">http://192.168.1.10:8000/admin/killclient?mount=/mystream.ogg&id=21</a><br>
><br>
> This is different from encoding the parameters as if they were part of<br>
> an HTML form.<br>
><br>
<br>
--<br>
Philipp Schafft (CEO/Geschäftsführer)<br>
Telephone: +49.3535 490 17 92<br>
Website: <a href="https://www.loewenfelsen.net/" rel="noreferrer" target="_blank">https://www.loewenfelsen.net/</a><br>
Follow us: <a href="https://www.linkedin.com/company/loewenfelsen/" rel="noreferrer" target="_blank">https://www.linkedin.com/company/loewenfelsen/</a><br>
Geschäftsführer/CEO: Philipp Schafft<br>
<br>
Löwenfelsen UG (haftungsbeschränkt) Registration number:<br>
Bickinger Straße 21 HRB 12308 CB<br>
04916 Herzberg (Elster) VATIN/USt-ID:<br>
Germany DE305133015<br>
<br>
<br>
--<br>
Diese E-Mail wurde von Avast-Antivirussoftware auf Viren geprüft.<br>
<a href="http://www.avast.com" rel="noreferrer" target="_blank">www.avast.com</a><br>
_______________________________________________<br>
Icecast mailing list<br>
<a href="mailto:Icecast@xiph.org" target="_blank">Icecast@xiph.org</a><br>
<a href="http://lists.xiph.org/mailman/listinfo/icecast" rel="noreferrer" target="_blank">http://lists.xiph.org/mailman/listinfo/icecast</a><br>
</blockquote></div>