[UE5.8] feat(signalling): issue TURN credentials per connection (#956) - #973
Merged
Conversation
peerOptions is built once at startup and sent verbatim to every peer, so a TURN username and credential written there is shared by every session that ever connects and cannot be rotated without a redeploy. This is the weakness tip 3 of Docs/Security-Guidelines.md already warns about. - Add IServerConfig.peerOptionsProvider, consulted once per connecting peer, returning the peer options to send to that peer. It receives the peer type and id; a provider that throws falls back to the static peerOptions, so a failing credential service cannot leave a peer waiting for a config message that never arrives. - On top of that hook, the signalling server gains --turn_secret (or --turn_secret_file) and --turn_ttl. With a secret set, every turn:/turns: entry in the peer options is given a freshly minted username and credential per connection, in the form coturn's use-auth-secret mode expects. Entries that name no TURN server are left alone, and the configured peer options are copied rather than modified. Default behaviour is unchanged when no secret is supplied. The secret is redacted from the --log_config dump, and --turn_secret_file keeps it out of the process command line entirely. (cherry picked from commit fab376e)
7 tasks
🦋 Changeset detectedLatest commit: 60edd5a The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport
This will backport the following commits from
mastertoUE5.8:Questions ?
Please refer to the Backport tool documentation