You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hardened stream-canvas WebSocket access with short-lived signed room tickets instead of raw Clerk session tokens in query strings.
Added hashed-at-rest OBS secrets with one-time regeneration reveal, legacy backfill, stricter token exchange, and no-referrer OBS headers.
Locked down uploads with request size caps, magic-byte MIME sniffing, sanitized filenames, signed media access URLs, and refresh-aware canvas media loading.
Added server-side validation and rate limits for room settings, OBS access, upload flows, WebSocket auth, and repeated auth failures.
Reduced user/profile data exposure in Convex user queries and added bounded username resolution/search behavior.
Fixes
Split owner/settings room response data from collaborator/public room data.
Added DB-level filtering for accessible room lookup and consolidated upload access checks.
Improved WebM audio/video detection by inspecting EBML track metadata.
Kept auth-failure limiter state across successful requests and cleaned expired limiter entries from read checks.
Fixed the OBS missing-secret fallback so it remains readable despite the transparent OBS overlay layout.
Notes
Existing rooms with legacy plaintext OBS secrets are migrated to hashed secrets at startup. Users who need to copy a secret again should regenerate the OBS URL from settings.
External media URLs remain allowed; this release focuses on token, upload, room, and referrer hardening.