Require authentication to participate in chat (#4762)

* feat(chat): require authentication to participate in chat

* fix: it's pretty much impossible to bypass the auth requirement, addressing review feedback anyway

* feat(chat): render chat text input as disabled if chat auth is required

* Commit updated API documentation

---------

Co-authored-by: Owncast <owncast@owncast.online>
This commit is contained in:
Gabe Kangas
2026-01-28 11:49:07 -08:00
committed by GitHub
co-authored by Owncast
parent 83c8b2b3d5
commit 93b482871f
29 changed files with 5194 additions and 5143 deletions
+19
View File
@@ -877,6 +877,25 @@ func SetChatSlurFilterEnabled(w http.ResponseWriter, r *http.Request) {
webutils.WriteSimpleResponse(w, true, "chat message slur filter changed")
}
// SetChatRequireAuthentication will enable or disable requiring authentication for chat.
func SetChatRequireAuthentication(w http.ResponseWriter, r *http.Request) {
if !requirePOST(w, r) {
return
}
configValue, success := getValueFromRequest(w, r)
if !success {
return
}
configRepository := configrepository.Get()
if err := configRepository.SetChatRequireAuthentication(configValue.Value.(bool)); err != nil {
webutils.WriteSimpleResponse(w, false, err.Error())
return
}
webutils.WriteSimpleResponse(w, true, "chat authentication requirement changed")
}
func requirePOST(w http.ResponseWriter, r *http.Request) bool {
if r.Method != http.MethodPost {
webutils.WriteSimpleResponse(w, false, r.Method+" not supported")
+2
View File
@@ -66,6 +66,7 @@ func GetServerConfig(w http.ResponseWriter, r *http.Request) {
ChatEstablishedUserMode: configRepository.GetChatEstbalishedUsersOnlyMode(),
ChatSpamProtectionEnabled: configRepository.GetChatSpamProtectionEnabled(),
ChatSlurFilterEnabled: configRepository.GetChatSlurFilterEnabled(),
ChatRequireAuthentication: configRepository.GetChatRequireAuthentication(),
HideViewerCount: configRepository.GetHideViewerCount(),
DisableSearchIndexing: configRepository.GetDisableSearchIndexing(),
VideoSettings: videoSettings{
@@ -129,6 +130,7 @@ type serverConfigAdminResponse struct {
ChatEstablishedUserMode bool `json:"chatEstablishedUserMode"`
ChatSpamProtectionEnabled bool `json:"chatSpamProtectionEnabled"`
ChatSlurFilterEnabled bool `json:"chatSlurFilterEnabled"`
ChatRequireAuthentication bool `json:"chatRequireAuthentication"`
DisableSearchIndexing bool `json:"disableSearchIndexing"`
StreamKeyOverridden bool `json:"streamKeyOverridden"`
HideViewerCount bool `json:"hideViewerCount"`
+2
View File
@@ -36,6 +36,7 @@ type webConfigResponse struct {
HideViewerCount bool `json:"hideViewerCount"`
ChatDisabled bool `json:"chatDisabled"`
ChatSpamProtectionDisabled bool `json:"chatSpamProtectionDisabled"`
ChatRequireAuthentication bool `json:"chatRequireAuthentication"`
NSFW bool `json:"nsfw"`
Authentication authenticationConfigResponse `json:"authentication"`
}
@@ -134,6 +135,7 @@ func getConfigResponse() webConfigResponse {
SocialHandles: socialHandles,
ChatDisabled: configRepository.GetChatDisabled(),
ChatSpamProtectionDisabled: configRepository.GetChatSpamProtectionEnabled(),
ChatRequireAuthentication: configRepository.GetChatRequireAuthentication(),
ExternalActions: configRepository.GetExternalActions(),
CustomStyles: configRepository.GetCustomStyles(),
MaxSocketPayloadSize: config.MaxSocketPayloadSize,
+8
View File
@@ -127,6 +127,14 @@ func (*ServerInterfaceImpl) SetChatSlurFilterEnabledOptions(w http.ResponseWrite
middleware.RequireAdminAuth(admin.SetChatSlurFilterEnabled)(w, r)
}
func (*ServerInterfaceImpl) SetChatRequireAuthentication(w http.ResponseWriter, r *http.Request) {
middleware.RequireAdminAuth(admin.SetChatRequireAuthentication)(w, r)
}
func (*ServerInterfaceImpl) SetChatRequireAuthenticationOptions(w http.ResponseWriter, r *http.Request) {
middleware.RequireAdminAuth(admin.SetChatRequireAuthentication)(w, r)
}
func (*ServerInterfaceImpl) SetVideoCodec(w http.ResponseWriter, r *http.Request) {
middleware.RequireAdminAuth(admin.SetVideoCodec)(w, r)
}
@@ -1,6 +1,6 @@
// Package generated provides primitives to interact with the openapi HTTP API.
//
// Code generated by github.com/oapi-codegen/oapi-codegen/v2 version v2.3.0 DO NOT EDIT.
// Code generated by github.com/oapi-codegen/oapi-codegen/v2 version v2.5.1 DO NOT EDIT.
package generated
import (
@@ -918,6 +918,9 @@ type SetForbiddenUsernameListJSONRequestBody SetForbiddenUsernameListJSONBody
// SetChatJoinMessagesEnabledJSONRequestBody defines body for SetChatJoinMessagesEnabled for application/json ContentType.
type SetChatJoinMessagesEnabledJSONRequestBody = AdminConfigValue
// SetChatRequireAuthenticationJSONRequestBody defines body for SetChatRequireAuthentication for application/json ContentType.
type SetChatRequireAuthenticationJSONRequestBody = AdminConfigValue
// SetChatSlurFilterEnabledJSONRequestBody defines body for SetChatSlurFilterEnabled for application/json ContentType.
type SetChatSlurFilterEnabledJSONRequestBody = AdminConfigValue
File diff suppressed because it is too large Load Diff