[UE5.7] Issue TURN credentials per connection (#956) - #977
Merged
Conversation
peerOptions is built once at startup and sent verbatim to every peer, so a TURN username and credential written there is shared by every session that ever connects and cannot be rotated without a redeploy. This is the weakness tip 3 of Docs/Security-Guidelines.md already warns about. - Add IServerConfig.peerOptionsProvider, consulted once per connecting peer, returning the peer options to send to that peer. It receives the peer type and id; a provider that throws falls back to the static peerOptions, so a failing credential service cannot leave a peer waiting for a config message that never arrives. - On top of that hook, the signalling server gains --turn_secret (or --turn_secret_file) and --turn_ttl. With a secret set, every turn:/turns: entry in the peer options is given a freshly minted username and credential per connection, in the form coturn's use-auth-secret mode expects. Entries that name no TURN server are left alone, and the configured peer options are copied rather than modified. Default behaviour is unchanged when no secret is supplied. The secret is redacted from the --log_config dump, and --turn_secret_file keeps it out of the process command line entirely. (cherry picked from commit fab376e)
🦋 Changeset detectedLatest commit: 2df643e The changes in this PR will be included in the next version bump. Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Relevant components:
Problem statement:
Backport of #956 from
mastertoUE5.7. The automatic backport failed on this branch because #912 was missing; that is now in via #974, so the cherry-pick applies cleanly.peerOptionsis built once in theSignallingServerconstructor and sent verbatim to every peer, so a TURN username and credential written there is shared by every session for the life of the deployment — the weakness tip 3 ofDocs/Security-Guidelines.mdalready warns about. See #956 for the full rationale.Solution
Cherry-pick of
fab376e9, which applied with zero conflicts against the current UE5.7 tip. One line changed on top:SignallingWebServer/src/turnCredentials.ts— the new file importsIPeerOptionsRequestandPeerOptionsProviderfrom@epicgames-ps/lib-pixelstreamingsignalling-ue5.8. Because it is a new file the cherry-pick does not flag it, but that package does not exist on this branch. Corrected to-ue5.7, amended into the commit.Nothing else was adapted; the diff is otherwise identical to
master..changeset/turn-ephemeral-credentials.mdstill names-ue5.8;.github/scripts/version-with-normalized-suffixes.shrewrites suffixes at release time, so it is left as the cherry-pick produced it.Documentation
Docs/Security-Guidelines.mdgains the "Issuing per-connection TURN credentials" section and tip 3 now points at it.SignallingWebServer/README.mdgains--turn_secret,--turn_secret_fileand--turn_ttl. Both applied clean on top of the #921 auth-hooks section this branch already had.Test Plan and Compatibility
npm run build,npm run lintandnpm testpass inCommon,SignallingandSignallingWebServeron Node 22.14.0 — 4 tests inSignalling, 18 inSignallingWebServer, the same 22 as onmaster.Confirmed no
-ue5.8references remain underSignalling/srcorSignallingWebServer/src.Functional verification of the feature itself (coturn 4.6.1 in
use-auth-secretmode, relayed stream through symmetric NAT, retired static credential refused with 401) was done againstmasterin #956 and is not repeated here — this branch carries that code unmodified.Default behaviour is unchanged: with no
--turn_secret,peerOptionsProvideris undefined and peers receivepeerOptionsexactly as before.