Skip to content

rtlconsole polling kicks human web sessions on RTLPlayground switches (single-session firmware) #863

Description

@gnacho

The console poller (#639/#640) logs in on every poll with NETPULSE_RTL_PASS (default 1234 = factory firmware password). RTLPlayground firmware keeps a single global session_id and regenerates it on every successful login, so each poll invalidates any human browsing the web UI. The SPA redirects to login on any 401, so the user gets kicked to the login page every poll cycle.

Observed on a KP-9000-9XHML-X-V3_1 running a session-timeout backport build: a scripted session polling /information.json every 15 s with a valid cookie got a 401 after ~2 min, exactly when the next poll landed. Session_timeout on the device was 18000 s, ruling out server-side expiry. Switch and NetPulse both used password 1234.

Workaround applied on the home instance: NETPULSE_RTL_PASS set to an invalid value in the server .env so polls fail login and back off. Console-sourced fields (firmware version, uptime, MAC) go stale; uptime was already broken on this firmware line (#785, two-line time output). Beacon monitoring keeps working.

Possible real fixes:

  • Upstream firmware: support multiple concurrent sessions, or a read-only monitor token for status endpoints.
  • NetPulse: reuse the session cookie across polls and only re-login on 401 (still kicks humans on re-login with single-session firmware, but reduces the rate), and/or a per-agent toggle to disable console polling.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions