Skip to content

v0.3.0 - Stream Canvas Security Hardening

Choose a tag to compare

@beastyrabbit beastyrabbit released this 26 Apr 10:56
· 44 commits to main since this release

Highlights

  • Hardened stream-canvas WebSocket access with short-lived signed room tickets instead of raw Clerk session tokens in query strings.
  • Added hashed-at-rest OBS secrets with one-time regeneration reveal, legacy backfill, stricter token exchange, and no-referrer OBS headers.
  • Locked down uploads with request size caps, magic-byte MIME sniffing, sanitized filenames, signed media access URLs, and refresh-aware canvas media loading.
  • Added server-side validation and rate limits for room settings, OBS access, upload flows, WebSocket auth, and repeated auth failures.
  • Reduced user/profile data exposure in Convex user queries and added bounded username resolution/search behavior.

Fixes

  • Split owner/settings room response data from collaborator/public room data.
  • Added DB-level filtering for accessible room lookup and consolidated upload access checks.
  • Improved WebM audio/video detection by inspecting EBML track metadata.
  • Kept auth-failure limiter state across successful requests and cleaned expired limiter entries from read checks.
  • Fixed the OBS missing-secret fallback so it remains readable despite the transparent OBS overlay layout.

Notes

  • Existing rooms with legacy plaintext OBS secrets are migrated to hashed secrets at startup. Users who need to copy a secret again should regenerate the OBS URL from settings.
  • External media URLs remain allowed; this release focuses on token, upload, room, and referrer hardening.

Verification

  • pnpm --dir backend/stream-canvas run typecheck
  • pnpm --dir backend/stream-canvas run test
  • pnpm run lint
  • pnpm run typecheck
  • pnpm run test
  • pnpm run build