Good evening,
On Sun, 2024-01-21 at 20:01 +0000, TDAS wrote:> Thanks - so?
>
> > ???<role type="anonymous" match-
> > admin="publicstats,publicstats.json" deny-all="*"
/>
>
>
> ?worked, but also blocked all my mount points too! I guess I need to
> follow it with something like:
>
> ?<role type="anonymous"
match-admin=?stream.mp3,stream.aac" allow-
> all="*" />
>
> Or something else?
Something else. Feel free to check out the link I gave you. ;)
Was a bit too fast to reply to you, sadly. But while not in office I
still wanted to help you.
"stream.mp3" and "stream.aac" are clearly not admin commands
(nor valid
mount points).
Maybe you should try nomatch-web="*" as indicated in the link? For me
that works.
> But would that not open up the mount points for anonymous sources
> also?
Generally "allow-all" is a dangerous tool. Better not use it if
you're
not sure what you're doing. The deny-all="*" is much more helpful.
> > That endpoint is meant to be public
>
> I find this really strange. I?ve never known of an installation of
> Icecast where they would be happy for anyone to know how many
> listeners they have. That kind of info is closely guarded (at least,
> in small radio stations in the UK). So for it to be exposed by
> default (and on the end of a secure URL), is a bit of a surprise. I
> would be in a bit of trouble if anyone had spotted it! :)
The listener numbers have never been considered a secret. And it feels
like they should not. I mean they even listed in the directory.
If you really need to hide that information you need to seal all access
to the server statistics and skip sending data to a directory service.
But again, that might break any number of things.
With best regard,
--
Philipp Schafft (CEO/Gesch?ftsf?hrer)
Telephone:???????????+49.3535 490 17 92
Website:?????????????https://www.loewenfelsen.net/
Follow us:???????????https://www.linkedin.com/company/loewenfelsen/
Gesch?ftsf?hrer/CEO: Philipp Schafft
L?wenfelsen UG (haftungsbeschr?nkt)?????Registration number:
Bickinger Stra?e 21?????????????????????HRB 12308 CB
04916 Herzberg (Elster)?????????????????VATIN/USt-ID:
Germany?????????????????????????????????DE305133015