mirror of
https://github.com/livekit/livekit.git
synced 2026-09-14 06:45:35 +00:00
* turn: accept PROXY protocol on the TCP listener Behind a TLS-terminating or reverse proxy that dials from its own address, the embedded TURN server reports the proxy's address to the client as XOR-MAPPED-ADDRESS. Firefox rejects a loopback or wildcard mapped address and abandons the allocation, so relay-only clients never get a relay candidate (#4851). Add turn.proxy_protocol. When set, the TCP listener requires a PROXY protocol v1/v2 header on every connection and uses the client address it carries; connections without the header are rejected. The header is read before TLS, so it works with both the built-in TLS listener and external_tls. * turn: only trust PROXY headers from configured proxies A PROXY header from any peer that can reach the port would let a direct client claim an arbitrary source address. Add turn.proxy_protocol_trusted_cidrs, defaulting to loopback, and close connections from any other address before reading the header.