Alessandro Ros and GitHub
7418e51031
prevent directory traversal attacks ( #5602 )
...
Path names are used as part of paths in several components: in the
recorder, in the playback server and in every HTTP-based component
(WebRTC, HLS, API). Special characters that allow to escape from the
intended directory are now forbidden in order to prevent directory
traversal attacks.
2026-03-23 20:16:12 +01:00
f98c9c59ca
rtsp: support unwrapping MPEG-TS tracks ( #5476 )
...
this allows to use MPEG-TS tracks with other protocols and with the recording system.
---------
Co-authored-by: aler9 <46489434+aler9@users.noreply.github.com >
2026-03-17 19:14:04 +01:00
Alessandro Ros and GitHub
3bad7045c1
api: add missing enums and move all enums in dedicated components ( #5576 )
2026-03-15 22:09:00 +01:00
Alessandro Ros and GitHub
c6bb332664
api: add deprecated fields to the OpenAPI definition ( #5575 )
2026-03-15 19:28:06 +01:00
Roman Sirokov and GitHub
9b36d50b8d
optionally validate JWT iss and aud claims ( #5569 )
2026-03-13 22:38:40 +01:00
Alessandro Ros and GitHub
3f1ff994b7
revert to Go 1.25 ( #5521 ) ( #5538 )
...
It seems like Go 1.26 is causing segmentation faults, related to
channels, on Windows.
2026-03-01 10:09:11 +01:00
Alessandro Ros and GitHub
549300cbd4
prevent using alwaysAvailableFile and alwaysAvailableTracks together ( #5529 )
2026-02-28 18:31:41 +01:00
Alessandro Ros and GitHub
13551f0d98
fix panic when setting writeQueueSize to zero ( #5360 ) ( #5527 )
2026-02-28 09:18:42 +01:00
Alessandro Ros and GitHub
3568c54a02
improve JSON decoder performance ( #5526 )
...
avoid decoding JSON twice.
2026-02-27 23:25:04 +01:00
Alessandro Ros and GitHub
35e1f486c9
add integrated packet dumper ( #5488 )
...
this allows to dump any incoming and outgoing packet, to disk, in
pcapng format.
2026-02-22 13:34:05 +01:00
bluenviron-bot and GitHub
a07526d57c
bump Golang to 1.26 ( #5460 )
2026-02-21 14:48:53 +01:00
Alessandro Ros and GitHub
87fbfebf06
webrtc: add whepBearerTokenParameter ( #3796 ) ( #5486 )
...
this allows to pass Authorization: Bearer to servers that require it.
2026-02-19 11:57:39 +01:00
Alessandro Ros and GitHub
3c46bfd337
warn when alwaysAvailableFile is not MP4 ( #5483 )
2026-02-18 21:29:42 +01:00
Alessandro Ros and GitHub
f991821a5f
webrtc: allow tuning WHEP timeouts ( #5027 ) ( #5479 )
...
add whepHandshakeTimeout, whepTrackGatherTimeout, whepSTUNGatherTimeout
2026-02-18 16:29:25 +01:00
Alessandro Ros and GitHub
cb69d64fac
deprecate unix+rtp ( #5318 ) ( #4999 ) ( #5351 ) ( #5470 )
...
Unix socket are stream-based connections, while RTP requires
packet-based connections. While packet-based Unix sockets exist
(unixgram), no client supports them. Consequently we are forced to
deprecate unix+rtp.
2026-02-15 13:02:18 +01:00
Alessandro Ros and GitHub
a0bbdd9655
replace YAML parser ( #5461 )
...
switch from the unmaintained gopkg.in/yaml to goccy/go-yaml
2026-02-12 15:51:14 +01:00
4a559338ae
improve JSON error message ( #5412 ) ( #5433 )
...
Co-authored-by: Zaphkiel <duambi123@gmail.com >
2026-02-07 19:52:27 +01:00
Alessandro Ros and GitHub
4f859fb40b
add authHTTPFingerprint ( #5413 ) ( #5422 )
2026-02-05 16:51:29 +01:00
Alessandro Ros and GitHub
4dc09e1d51
set default udpMaxPayloadSize to an IPv6 compatible value ( #4882 ) ( #5402 )
...
When using IPv6, there are 20 bytes less available for UDP payload,
which has been adjusted accordingly.
2026-02-05 16:32:02 +01:00
Dimitri Pappas and GitHub
9ffbdbdc1f
fix typo in error message ('alwaysAvailableVideo' -> 'alwaysAvailableFile') ( #5417 )
2026-02-03 11:59:20 +01:00
Alessandro Ros and GitHub
74eaa11d3a
rtsp: add rtspUDPSourcePortRange param ( #5363 ) ( #5397 )
2026-01-31 16:21:53 +01:00
Alessandro Ros and GitHub
92f9ee7b78
deprecate fallback ( #5388 )
...
The fallback feature worked with RTSP only and did not allow readers to
resume the original stream. It has been replaced by alwaysAvailable.
2026-01-31 15:29:24 +01:00
Alessandro Ros and GitHub
a56408db19
add always available streams ( #5335 )
...
When the publisher or source of a stream is offline, the server can be
configured to fill gaps in the stream with a video that is played on
repeat until a publisher comes back online. This allows readers to stay
connected regardless of the state of the stream. The offline video and
any future online stream are concatenated without decoding or
re-encoding packets, using the original codec.
2026-01-31 14:44:58 +01:00
Alessandro Ros and GitHub
69fdd18d86
docs: update ( #5308 )
2026-01-28 11:52:42 +01:00
Alessandro Ros and GitHub
8a4f2f5f3f
simplify configuration definitions ( #5376 )
2026-01-25 20:24:41 +01:00
Alessandro Ros and GitHub
a4561a8339
prevent setting slices to null ( #5375 )
...
In Golang, slices can be set to nil, while in most other languages they
cannot. This causes compatibility issues, especially because the
OpenAPI definition of the API does not allow slices to be nil. This
prevents slices from being set to nil through JSON/YAML, and
also sets default slices to an empty list instead of nil.
2026-01-25 19:49:39 +01:00
Alessandro Ros and GitHub
1a53e40bdc
switch to reflect.Pointer ( #5377 )
2026-01-25 13:51:49 +01:00
Alessandro Ros and GitHub
719ca2ae39
fix panic with environment variables ( #5374 )
...
this happened when loading deprecated slices of structs with
environment variables.
2026-01-25 10:27:36 +01:00
Alessandro Ros and GitHub
40cb857dd9
prevent setting empty usernames with environment variables ( #5373 )
2026-01-24 19:44:17 +01:00
Alessandro Ros and GitHub
0d95459f7b
fix overriding default user with environment variables ( #5371 )
...
MTX_AUTHINTERNALUSERS_0_USER and MTX_AUTHINTERNALUSERS_0_PASS are now working even when the configuration file is present.
2026-01-24 19:38:59 +01:00
Alessandro Ros and GitHub
f4f795a2a6
simplify configuration parsing ( #5372 )
...
work around golang/go#21092 globally
2026-01-24 19:33:47 +01:00
Alessandro Ros and GitHub
e2ac32177b
prevent several configuration errors ( #5368 )
2026-01-22 19:35:44 +01:00
9e9fae9a10
add structured logging ( #5219 )
...
Co-authored-by: aler9 <46489434+aler9@users.noreply.github.com >
2025-12-27 20:42:06 +01:00
ade0cddeb3
support multiple CORS origins ( #5150 )
...
Co-authored-by: aler9 <46489434+aler9@users.noreply.github.com >
2025-11-21 02:00:46 +01:00
Alessandro Ros and GitHub
ff187b6d8a
update golangci-lint configuration ( #5182 )
2025-11-11 23:57:52 +01:00
Alessandro Ros and GitHub
8858bf1db9
simplify code with ptrOf ( #5179 )
2025-11-11 12:01:03 +01:00
Alessandro Ros and GitHub
adc4a6ceb6
add udpReadBufferSize parameter ( #5129 )
...
this allows to set a global UDP read buffer, applied to every UDP socket.
2025-10-29 11:28:22 +01:00
Alessandro Ros and GitHub
f81c50ee68
rtsp: support reading streams tunneled with HTTP or WebSocket ( #4986 )
2025-09-17 22:31:20 +02:00
Alessandro Ros and GitHub
e3b8af8933
switch to gortsplib/v5 ( #4978 )
2025-09-16 13:10:34 +02:00
Alessandro Ros and GitHub
e0f4748839
modernize code ( #4947 )
2025-09-07 16:08:47 +02:00
Alessandro Ros and GitHub
03623799f5
use slices.Contains when possible ( #4859 )
2025-08-12 12:28:20 +02:00
Alessandro Ros and GitHub
462fb2bd0f
allow setting UDP read buffer size ( #3308 ) ( #4846 )
...
new parameters: rtspUDPReadBufferSize, rtpUDPReadBufferSize, mpegtsUDPReadBufferSize
2025-08-11 12:21:00 +02:00
Alessandro Ros and GitHub
d0430d8ea5
support ingesting RTP streams ( #1515 ) ( #4843 )
2025-08-09 16:12:10 +02:00
Alessandro Ros and GitHub
7feff1d1dc
support MPEG-TS over unix sockets ( #4388 ) ( #4389 ) ( #4828 )
2025-08-08 18:03:38 +02:00
Alessandro Ros and GitHub
d423a71aaa
update linter settings ( #4790 )
2025-07-26 16:44:32 +02:00
Alessandro Ros and GitHub
7ac752097b
rpi: allow setting software H264 profile and level ( #3965 ) ( #4786 )
2025-07-25 13:40:15 +02:00
Alessandro Ros and GitHub
0fe12f8bf6
rpi: rename rpiCameraProfile into rpiCameraH264Profile, rpiCameraLevel into rpiCameraH264Level ( #3965 ) ( #4785 )
2025-07-25 11:44:55 +02:00
Alessandro Ros and GitHub
1cabc382b0
rpi: rename rpiCameraJPEGQuality in rpiCameraMJPEGQuality ( #4784 )
2025-07-25 11:40:09 +02:00
Alessandro Ros and GitHub
94e001e736
rpi: add validity checks on rpiCameraProfile and rpiCameraLevel ( #4783 )
2025-07-25 11:36:40 +02:00
Alessandro Ros and GitHub
9ddcbf5c97
recorder: limit maximum part size ( #4674 ) ( #4760 )
...
this prevents RAM exhaustion.
2025-07-20 19:16:33 +02:00