Skip to content

[UE5.7] Issue TURN credentials per connection (#956) - #977

Merged
mcottontensor merged 1 commit into
UE5.7from
backport/UE5.7/pr-956
Aug 12, 2026
Merged

[UE5.7] Issue TURN credentials per connection (#956)#977
mcottontensor merged 1 commit into
UE5.7from
backport/UE5.7/pr-956

Conversation

@mcottontensor

Copy link
Copy Markdown
Collaborator

Relevant components:

  • Signalling server
  • Common library
  • Frontend library
  • Frontend UI library
  • Matchmaker
  • Platform scripts
  • SFU

Problem statement:

Backport of #956 from master to UE5.7. The automatic backport failed on this branch because #912 was missing; that is now in via #974, so the cherry-pick applies cleanly.

peerOptions is built once in the SignallingServer constructor and sent verbatim to every peer, so a TURN username and credential written there is shared by every session for the life of the deployment — the weakness tip 3 of Docs/Security-Guidelines.md already warns about. See #956 for the full rationale.

Solution

Cherry-pick of fab376e9, which applied with zero conflicts against the current UE5.7 tip. One line changed on top:

  • SignallingWebServer/src/turnCredentials.ts — the new file imports IPeerOptionsRequest and PeerOptionsProvider from @epicgames-ps/lib-pixelstreamingsignalling-ue5.8. Because it is a new file the cherry-pick does not flag it, but that package does not exist on this branch. Corrected to -ue5.7, amended into the commit.

Nothing else was adapted; the diff is otherwise identical to master.

.changeset/turn-ephemeral-credentials.md still names -ue5.8; .github/scripts/version-with-normalized-suffixes.sh rewrites suffixes at release time, so it is left as the cherry-pick produced it.

Documentation

Docs/Security-Guidelines.md gains the "Issuing per-connection TURN credentials" section and tip 3 now points at it. SignallingWebServer/README.md gains --turn_secret, --turn_secret_file and --turn_ttl. Both applied clean on top of the #921 auth-hooks section this branch already had.

Test Plan and Compatibility

npm run build, npm run lint and npm test pass in Common, Signalling and SignallingWebServer on Node 22.14.0 — 4 tests in Signalling, 18 in SignallingWebServer, the same 22 as on master.

Confirmed no -ue5.8 references remain under Signalling/src or SignallingWebServer/src.

Functional verification of the feature itself (coturn 4.6.1 in use-auth-secret mode, relayed stream through symmetric NAT, retired static credential refused with 401) was done against master in #956 and is not repeated here — this branch carries that code unmodified.

Default behaviour is unchanged: with no --turn_secret, peerOptionsProvider is undefined and peers receive peerOptions exactly as before.

peerOptions is built once at startup and sent verbatim to every peer, so a
TURN username and credential written there is shared by every session that
ever connects and cannot be rotated without a redeploy. This is the weakness
tip 3 of Docs/Security-Guidelines.md already warns about.

- Add IServerConfig.peerOptionsProvider, consulted once per connecting peer,
  returning the peer options to send to that peer. It receives the peer type
  and id; a provider that throws falls back to the static peerOptions, so a
  failing credential service cannot leave a peer waiting for a config message
  that never arrives.
- On top of that hook, the signalling server gains --turn_secret (or
  --turn_secret_file) and --turn_ttl. With a secret set, every turn:/turns:
  entry in the peer options is given a freshly minted username and credential
  per connection, in the form coturn's use-auth-secret mode expects. Entries
  that name no TURN server are left alone, and the configured peer options are
  copied rather than modified.

Default behaviour is unchanged when no secret is supplied. The secret is
redacted from the --log_config dump, and --turn_secret_file keeps it out of
the process command line entirely.

(cherry picked from commit fab376e)
@changeset-bot

changeset-bot Bot commented Aug 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2df643e

The changes in this PR will be included in the next version bump.

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@mcottontensor
mcottontensor marked this pull request as ready for review August 12, 2026 06:53
@mcottontensor
mcottontensor merged commit 818a5d1 into UE5.7 Aug 12, 2026
8 checks passed
@mcottontensor
mcottontensor deleted the backport/UE5.7/pr-956 branch August 12, 2026 06:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants