From 2637003859127891a0dcf369fd3e0d25f67cc494 Mon Sep 17 00:00:00 2001 From: rustdesk Date: Sat, 5 Sep 2026 14:20:25 +0800 Subject: [PATCH] temporary password: rotate when a peer is let in, not when it leaves The one-time password was regenerated after the connection loop exited, so a remote desktop session kept it valid for hours and a port-forward tunnel for as long as its mapping lived. It now rotates the moment a connection becomes authorized. Reconnects and windows opened from a live session are unaffected: they log in on the password the session remembers, for 30 seconds past its last activity. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01EZ49AbZJYfm8NTp5yDPMab --- src/server/connection.rs | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/src/server/connection.rs b/src/server/connection.rs index 4767e05fc..0b179ef73 100644 --- a/src/server/connection.rs +++ b/src/server/connection.rs @@ -1087,9 +1087,6 @@ impl Connection { } } video_service::notify_video_frame_fetched_by_conn_id(id, None); - if conn.authorized { - password::update_temporary_password(); - } if let Err(err) = conn.try_port_forward_loop(&mut rx_from_cm).await { conn.on_close(&err.to_string(), false).await; raii::AuthedConnID::check_remove_session(conn.inner.id(), conn.session_key()); @@ -1747,6 +1744,10 @@ impl Connection { return false; } self.authorized = true; + // One-time means gone once it has let a peer in, not once that peer + // leaves. This session's later logins come in on the password the + // session remembers, so they are not affected. + password::update_temporary_password(); // Releases the budget `check_id_whitelist` charges against this address: only a peer // that got this far proved more than a self-reported id. self.clear_id_whitelist_failures();