Security model
What soli-sfu protects, what it leaves to your app, and the limits it enforces. Read this before you rely on groups for privacy.
What the server enforces
- Rooms. A session's room comes from a signed token, never from the request body. Nobody joins a room they were not given a token for.
- Ownership. Changing, dropping or inspecting a session needs a token for the same user and the same room.
- Media encryption. Every session is DTLS-SRTP. The SFU forwards encrypted packets between legs it terminates itself.
- Stats. A token only reveals its own room's head count, plus the server-wide total.
Groups are chosen by the listener
peers decides who a person hears, and it is set by whoever
holds that person's token. If the browser talks to the SFU directly, a
user can widen their own set, or send null, and hear
everyone in the room.
For a circle that must stay private, do one of these: keep the token on
your server and have the app make the PATCH calls, or give
the private circle its own room. Rooms are signed into the token, so
the second is enforced by the SFU itself.
Limits
| Limit | Value | Why |
|---|---|---|
| Request body | 256 KiB | An offer is about 30 KiB; larger bodies are refused with 413. |
peers entries | 256 | The set is consulted for every forwarded packet. |
| Receive slots | 8 audio, 4 video | Extra m-lines in an offer are ignored, so one offer cannot inflate memory. |
| Connect deadline | 30 s | An offer that never completes ICE and DTLS does not hold a session forever. |
| Keyframe requests | 1 per 500 ms per track | One listener cannot make a speaker send keyframes nonstop. |
| Engine reply | 5 s | If the media thread is wedged, requests fail with 503 instead of piling up. |
Offers are parsed on the HTTP side, so a malformed or oversized offer never reaches the media thread.
Deployment checklist
- Set a dedicated
SOLI_SFU_SECRET, and keepallow_unauthenticatedoff. - Bind
control_addrto loopback and reach it only through soli-proxy over TLS. - Mint tokens with short lifetimes. A token is a bearer credential until it expires.
- Install with the script or check the published SHA-256; the installer refuses an unverifiable download.
Reporting a problem
Open a private security advisory on GitHub rather than a public issue.