Skip to content

[Bug] WebSocket API: session re-logon after reconnect is sent without apiKey and signature #569

Description

@Amadeus-22

Summary

After a WebSocket API connection is renewed (scheduled reconnect or serverShutdown), session_re_log_on re-sends session.logon without apiKey and signature, then marks the connection as logged on without waiting for the reply. The server rejects that logon, and every signed request sent afterwards is also unsigned, because the client believes the session is authenticated.

This affects Ed25519 users who call session_logon; session_re_logon is enabled by default.

Where

common/src/binance_common/websocket.py, session_re_log_on:

websocket_options = WebsocketApiOptions(
    signer=signer, api_key=False, is_signed=True, skip_auth=True
)
payload = ws_api_payload(self.configuration, data, websocket_options)
...
await WebSocketCommon.send_message(self, payload, connection)
connection.is_session_log_on = True

With api_key=False and skip_auth=True, ws_api_payload only adds timestamp. The initial logon goes through send_signed_message(..., session_logon=True), which adds apiKey and signature.

Reproduce

Self-contained: a local aiohttp WebSocket server records what the client sends. binance-common==4.5.1 (same as master at 43f19a9), Python 3.13.

import asyncio, json, logging
from aiohttp import web
from Crypto.PublicKey import ECC
from binance_common.configuration import ConfigurationWebSocketAPI
from binance_common.models import WebsocketApiUserDataEndpoints
from binance_common.signature import Signers
from binance_common.websocket import WebSocketAPIBase
logging.disable(logging.CRITICAL)
received = []
async def handler(request):
    ws = web.WebSocketResponse(); await ws.prepare(request)
    async for msg in ws:
        d = json.loads(msg.data); received.append(d)
        p = d.get("params", {})
        if d["method"] == "session.logon" and not ("apiKey" in p and "signature" in p):
            await ws.send_json({"id": d["id"], "status": 400, "error": {"code": -1102, "msg": "Mandatory parameter 'apiKey' was not sent"}})
        else:
            await ws.send_json({"id": d["id"], "status": 200, "result": {}, "rateLimits": []})
    return ws
async def main():
    app = web.Application(); app.router.add_get("/ws", handler)
    r = web.AppRunner(app); await r.setup(); await web.TCPSite(r, "127.0.0.1", 18765).start()
    pem = ECC.generate(curve="ed25519").export_key(format="PEM")
    cfg = ConfigurationWebSocketAPI(api_key="KEY", private_key=pem, stream_url="ws://127.0.0.1:18765/ws", reconnect_delay=100)
    api = WebSocketAPIBase(cfg, WebsocketApiUserDataEndpoints(user_data_stream_subscribe="userDataStream.subscribe", user_data_stream_logout="session.logout"))
    signer = Signers.get_signer(pem)
    await api.create_connection()
    await api.send_signed_message({"method": "session.logon", "params": {}}, signer=signer, session_logon=True)
    print("1 initial logon   params keys:", sorted(received[-1]["params"]))
    await api.reconnect(api.connections[0], cfg)      # what the 23h auto-reconnect / serverShutdown does
    await asyncio.sleep(0.3)
    relog = [m for m in received if m["method"] == "session.logon"][-1]
    print("2 re-logon        params keys:", sorted(relog["params"]))
    print("  connection.is_session_log_on =", api.connections[0].is_session_log_on)
    await api.send_signed_message({"method": "order.place", "params": {"symbol": "BTCUSDT"}}, signer=signer, api_key=True)
    print("3 order after rec params keys:", sorted(received[-1]["params"]))
    await api.close_connection()
    await r.cleanup()
asyncio.run(main())

Output:

1 initial logon   params keys: ['apiKey', 'signature', 'timestamp']
2 re-logon        params keys: ['timestamp']
  connection.is_session_log_on = True
3 order after rec params keys: ['symbol', 'timestamp']

Sending a session.logon with only timestamp to the Spot testnet WebSocket API returns 400, code -1102, Mandatory parameter 'apiKey' was not sent.

Expected

The re-logon carries the same apiKey, timestamp and signature as the first logon, and is_session_log_on only becomes True when the server answers with status 200.

Suggested fix

Build the re-logon payload with api_key=True, skip_auth=False (new timestamp and signature), wait for the response, and set is_session_log_on from its status. On failure, leave it False so later requests keep being signed individually.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions