Skip to content

API: Exposed for WebRTC without any access control #2684

@streamthing

Description

@streamthing

With WebRTC we need to expose http_api to public.
Why there isn't any access control for http_api?
User can send HTTP to /rtc/v1/play/ - which is OK.
But... there is also /api/v1/streams/ /api/v1/clients/ accessible for everyone in internet...

We need to setup reverse-proxy between client and SRS server?

Metadata

Metadata

Labels

BugIt might be a bug.EnglishNativeThis issue is conveyed exclusively in English.WebRTCWebRTC, RTC2RTMP or RTMP2RTC.

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions