Skip to content

[UE5.8] feat(signalling): issue TURN credentials per connection (#956) - #973

Merged
mcottontensor merged 1 commit into
UE5.8from
backport/UE5.8/pr-956
Aug 12, 2026
Merged

[UE5.8] feat(signalling): issue TURN credentials per connection (#956)#973
mcottontensor merged 1 commit into
UE5.8from
backport/UE5.8/pr-956

Conversation

@mcottontensor

Copy link
Copy Markdown
Collaborator

Backport

This will backport the following commits from master to UE5.8:

Questions ?

Please refer to the Backport tool documentation

peerOptions is built once at startup and sent verbatim to every peer, so a
TURN username and credential written there is shared by every session that
ever connects and cannot be rotated without a redeploy. This is the weakness
tip 3 of Docs/Security-Guidelines.md already warns about.

- Add IServerConfig.peerOptionsProvider, consulted once per connecting peer,
  returning the peer options to send to that peer. It receives the peer type
  and id; a provider that throws falls back to the static peerOptions, so a
  failing credential service cannot leave a peer waiting for a config message
  that never arrives.
- On top of that hook, the signalling server gains --turn_secret (or
  --turn_secret_file) and --turn_ttl. With a secret set, every turn:/turns:
  entry in the peer options is given a freshly minted username and credential
  per connection, in the form coturn's use-auth-secret mode expects. Entries
  that name no TURN server are left alone, and the configured peer options are
  copied rather than modified.

Default behaviour is unchanged when no secret is supplied. The secret is
redacted from the --log_config dump, and --turn_secret_file keeps it out of
the process command line entirely.

(cherry picked from commit fab376e)
@changeset-bot

changeset-bot Bot commented Aug 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 60edd5a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@epicgames-ps/lib-pixelstreamingsignalling-ue5.8 Minor
@epicgames-ps/wilbur Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@mcottontensor
mcottontensor merged commit c8cd21a into UE5.8 Aug 12, 2026
8 of 9 checks passed
@mcottontensor
mcottontensor deleted the backport/UE5.8/pr-956 branch August 12, 2026 06:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants