Summary
After a WebSocket API connection is renewed (scheduled reconnect or serverShutdown), session_re_log_on re-sends session.logon without apiKey and signature, then marks the connection as logged on without waiting for the reply. The server rejects that logon, and every signed request sent afterwards is also unsigned, because the client believes the session is authenticated.
This affects Ed25519 users who call session_logon; session_re_logon is enabled by default.
Where
common/src/binance_common/websocket.py, session_re_log_on:
websocket_options = WebsocketApiOptions(
signer=signer, api_key=False, is_signed=True, skip_auth=True
)
payload = ws_api_payload(self.configuration, data, websocket_options)
...
await WebSocketCommon.send_message(self, payload, connection)
connection.is_session_log_on = True
With api_key=False and skip_auth=True, ws_api_payload only adds timestamp. The initial logon goes through send_signed_message(..., session_logon=True), which adds apiKey and signature.
Reproduce
Self-contained: a local aiohttp WebSocket server records what the client sends. binance-common==4.5.1 (same as master at 43f19a9), Python 3.13.
import asyncio, json, logging
from aiohttp import web
from Crypto.PublicKey import ECC
from binance_common.configuration import ConfigurationWebSocketAPI
from binance_common.models import WebsocketApiUserDataEndpoints
from binance_common.signature import Signers
from binance_common.websocket import WebSocketAPIBase
logging.disable(logging.CRITICAL)
received = []
async def handler(request):
ws = web.WebSocketResponse(); await ws.prepare(request)
async for msg in ws:
d = json.loads(msg.data); received.append(d)
p = d.get("params", {})
if d["method"] == "session.logon" and not ("apiKey" in p and "signature" in p):
await ws.send_json({"id": d["id"], "status": 400, "error": {"code": -1102, "msg": "Mandatory parameter 'apiKey' was not sent"}})
else:
await ws.send_json({"id": d["id"], "status": 200, "result": {}, "rateLimits": []})
return ws
async def main():
app = web.Application(); app.router.add_get("/ws", handler)
r = web.AppRunner(app); await r.setup(); await web.TCPSite(r, "127.0.0.1", 18765).start()
pem = ECC.generate(curve="ed25519").export_key(format="PEM")
cfg = ConfigurationWebSocketAPI(api_key="KEY", private_key=pem, stream_url="ws://127.0.0.1:18765/ws", reconnect_delay=100)
api = WebSocketAPIBase(cfg, WebsocketApiUserDataEndpoints(user_data_stream_subscribe="userDataStream.subscribe", user_data_stream_logout="session.logout"))
signer = Signers.get_signer(pem)
await api.create_connection()
await api.send_signed_message({"method": "session.logon", "params": {}}, signer=signer, session_logon=True)
print("1 initial logon params keys:", sorted(received[-1]["params"]))
await api.reconnect(api.connections[0], cfg) # what the 23h auto-reconnect / serverShutdown does
await asyncio.sleep(0.3)
relog = [m for m in received if m["method"] == "session.logon"][-1]
print("2 re-logon params keys:", sorted(relog["params"]))
print(" connection.is_session_log_on =", api.connections[0].is_session_log_on)
await api.send_signed_message({"method": "order.place", "params": {"symbol": "BTCUSDT"}}, signer=signer, api_key=True)
print("3 order after rec params keys:", sorted(received[-1]["params"]))
await api.close_connection()
await r.cleanup()
asyncio.run(main())
Output:
1 initial logon params keys: ['apiKey', 'signature', 'timestamp']
2 re-logon params keys: ['timestamp']
connection.is_session_log_on = True
3 order after rec params keys: ['symbol', 'timestamp']
Sending a session.logon with only timestamp to the Spot testnet WebSocket API returns 400, code -1102, Mandatory parameter 'apiKey' was not sent.
Expected
The re-logon carries the same apiKey, timestamp and signature as the first logon, and is_session_log_on only becomes True when the server answers with status 200.
Suggested fix
Build the re-logon payload with api_key=True, skip_auth=False (new timestamp and signature), wait for the response, and set is_session_log_on from its status. On failure, leave it False so later requests keep being signed individually.
Summary
After a WebSocket API connection is renewed (scheduled reconnect or
serverShutdown),session_re_log_onre-sendssession.logonwithoutapiKeyandsignature, then marks the connection as logged on without waiting for the reply. The server rejects that logon, and every signed request sent afterwards is also unsigned, because the client believes the session is authenticated.This affects Ed25519 users who call
session_logon;session_re_logonis enabled by default.Where
common/src/binance_common/websocket.py,session_re_log_on:With
api_key=Falseandskip_auth=True,ws_api_payloadonly addstimestamp. The initial logon goes throughsend_signed_message(..., session_logon=True), which addsapiKeyandsignature.Reproduce
Self-contained: a local aiohttp WebSocket server records what the client sends.
binance-common==4.5.1(same as master at 43f19a9), Python 3.13.Output:
Sending a
session.logonwith onlytimestampto the Spot testnet WebSocket API returns400, code-1102,Mandatory parameter 'apiKey' was not sent.Expected
The re-logon carries the same
apiKey,timestampandsignatureas the first logon, andis_session_log_ononly becomesTruewhen the server answers with status 200.Suggested fix
Build the re-logon payload with
api_key=True, skip_auth=False(new timestamp and signature), wait for the response, and setis_session_log_onfrom its status. On failure, leave itFalseso later requests keep being signed individually.