Problem
The OCPP server accepts every WebSocket upgrade (101) and only then runs authenticateConnection(). When authentication fails it closes the socket with 1008 (ocpp-server.ts, handleConnection).
Charging stations that send HTTP Basic auth only in response to a challenge (RFC 7617: 401 with WWW-Authenticate: Basic) therefore never send their credentials and cannot connect at all. We hit this with a KEBA KC-P30 (firmware 2.1.0, OCPP 1.6J, security profile 1 with AuthorizationKey set): every attempt ended with connection_logs reason Missing credentials, although the password was configured on the station.
OCPP-J 1.6 also expects an HTTP response for an unrecognized charge point identity (404) instead of an accepted upgrade.
Reproduction
- Create a station with security profile 1 and a Basic auth password.
- Open a WebSocket to
/<stationId> with subprotocol ocpp1.6 and no Authorization header.
- The server answers
101 Switching Protocols, then closes with 1008 Basic auth credentials required. No 401/WWW-Authenticate is ever sent.
Proposed fix (PR follows)
Run authenticateConnection() in the verifyClient callback of both WebSocket servers and reject before the upgrade: 401 with WWW-Authenticate: Basic for missing or invalid credentials, 401 without a challenge for TLS and client certificate failures, 404 for an unknown station, 403 for a blocked station, 503 if the database is unavailable. Per-IP limits and connection logging stay as they are.
Problem
The OCPP server accepts every WebSocket upgrade (
101) and only then runsauthenticateConnection(). When authentication fails it closes the socket with1008(ocpp-server.ts,handleConnection).Charging stations that send HTTP Basic auth only in response to a challenge (RFC 7617:
401withWWW-Authenticate: Basic) therefore never send their credentials and cannot connect at all. We hit this with a KEBA KC-P30 (firmware 2.1.0, OCPP 1.6J, security profile 1 withAuthorizationKeyset): every attempt ended withconnection_logsreasonMissing credentials, although the password was configured on the station.OCPP-J 1.6 also expects an HTTP response for an unrecognized charge point identity (
404) instead of an accepted upgrade.Reproduction
/<stationId>with subprotocolocpp1.6and noAuthorizationheader.101 Switching Protocols, then closes with1008 Basic auth credentials required. No401/WWW-Authenticateis ever sent.Proposed fix (PR follows)
Run
authenticateConnection()in theverifyClientcallback of both WebSocket servers and reject before the upgrade:401withWWW-Authenticate: Basicfor missing or invalid credentials,401without a challenge for TLS and client certificate failures,404for an unknown station,403for a blocked station,503if the database is unavailable. Per-IP limits and connection logging stay as they are.