Skip to content

v0.1.0 Security Update

Latest

Choose a tag to compare

@Jime567 Jime567 released this 08 Apr 17:10
· 2 commits to master since this release
ac46109

This release solves several security issues by implementing the control key as a required cookie for every camera control command.

  • Adds Auth package locally to project
  • Updates "dgrijalva/jwt-go to golang-jwt/jwt v3.2.1+incompatible" to solve CVE issues
  • Aver service checks every request for the control cookie key and then verifies with the control key service
  • Aver service requires new flag "key-service"
  • Control service UI updated
  • Control service writes control key as cookie in requests to Aver service
  • Control service notifies user when key expires and returns them to key entry page
  • Aver and Axis now require access to Couch for additional verification