soli-sfu

Security model

What soli-sfu protects, what it leaves to your app, and the limits it enforces. Read this before you rely on groups for privacy.

What the server enforces

  • Rooms. A session's room comes from a signed token, never from the request body. Nobody joins a room they were not given a token for.
  • Ownership. Changing, dropping or inspecting a session needs a token for the same user and the same room.
  • Media encryption. Every session is DTLS-SRTP. The SFU forwards encrypted packets between legs it terminates itself.
  • Stats. A token only reveals its own room's head count, plus the server-wide total.

Groups are chosen by the listener

peers decides who a person hears, and it is set by whoever holds that person's token. If the browser talks to the SFU directly, a user can widen their own set, or send null, and hear everyone in the room.

For a circle that must stay private, do one of these: keep the token on your server and have the app make the PATCH calls, or give the private circle its own room. Rooms are signed into the token, so the second is enforced by the SFU itself.

Limits

LimitValueWhy
Request body256 KiBAn offer is about 30 KiB; larger bodies are refused with 413.
peers entries256The set is consulted for every forwarded packet.
Receive slots8 audio, 4 videoExtra m-lines in an offer are ignored, so one offer cannot inflate memory.
Connect deadline30 sAn offer that never completes ICE and DTLS does not hold a session forever.
Keyframe requests1 per 500 ms per trackOne listener cannot make a speaker send keyframes nonstop.
Engine reply5 sIf the media thread is wedged, requests fail with 503 instead of piling up.

Offers are parsed on the HTTP side, so a malformed or oversized offer never reaches the media thread.

Deployment checklist

  • Set a dedicated SOLI_SFU_SECRET, and keep allow_unauthenticated off.
  • Bind control_addr to loopback and reach it only through soli-proxy over TLS.
  • Mint tokens with short lifetimes. A token is a bearer credential until it expires.
  • Install with the script or check the published SHA-256; the installer refuses an unverifiable download.

Reporting a problem

Open a private security advisory on GitHub rather than a public issue.