Skip to content

OCPP stations that send Basic auth only after a 401 challenge cannot connect #22

Description

@MarcoSpittka

Problem

The OCPP server accepts every WebSocket upgrade (101) and only then runs authenticateConnection(). When authentication fails it closes the socket with 1008 (ocpp-server.ts, handleConnection).

Charging stations that send HTTP Basic auth only in response to a challenge (RFC 7617: 401 with WWW-Authenticate: Basic) therefore never send their credentials and cannot connect at all. We hit this with a KEBA KC-P30 (firmware 2.1.0, OCPP 1.6J, security profile 1 with AuthorizationKey set): every attempt ended with connection_logs reason Missing credentials, although the password was configured on the station.

OCPP-J 1.6 also expects an HTTP response for an unrecognized charge point identity (404) instead of an accepted upgrade.

Reproduction

  1. Create a station with security profile 1 and a Basic auth password.
  2. Open a WebSocket to /<stationId> with subprotocol ocpp1.6 and no Authorization header.
  3. The server answers 101 Switching Protocols, then closes with 1008 Basic auth credentials required. No 401/WWW-Authenticate is ever sent.

Proposed fix (PR follows)

Run authenticateConnection() in the verifyClient callback of both WebSocket servers and reject before the upgrade: 401 with WWW-Authenticate: Basic for missing or invalid credentials, 401 without a challenge for TLS and client certificate failures, 404 for an unknown station, 403 for a blocked station, 503 if the database is unavailable. Per-IP limits and connection logging stay as they are.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions