henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2012 The WebRTC Project Authors. All rights reserved. |
| 3 | * |
| 4 | * Use of this source code is governed by a BSD-style license |
| 5 | * that can be found in the LICENSE file in the root of the source |
| 6 | * tree. An additional intellectual property rights grant can be found |
| 7 | * in the file PATENTS. All contributing project authors may |
| 8 | * be found in the AUTHORS file in the root of the source tree. |
| 9 | */ |
| 10 | |
Steve Anton | 10542f2 | 2019-01-11 09:11:00 -0800 | [diff] [blame] | 11 | #ifndef P2P_BASE_TURN_SERVER_H_ |
| 12 | #define P2P_BASE_TURN_SERVER_H_ |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 13 | |
| 14 | #include <list> |
| 15 | #include <map> |
kwiberg | 3ec4679 | 2016-04-27 07:22:53 -0700 | [diff] [blame] | 16 | #include <memory> |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 17 | #include <set> |
| 18 | #include <string> |
Steve Anton | 6c38cc7 | 2017-11-29 10:25:58 -0800 | [diff] [blame] | 19 | #include <utility> |
deadbeef | 824f586 | 2016-08-24 15:06:53 -0700 | [diff] [blame] | 20 | #include <vector> |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 21 | |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 22 | #include "absl/strings/string_view.h" |
Artem Titov | d15a575 | 2021-02-10 14:31:24 +0100 | [diff] [blame] | 23 | #include "api/sequence_checker.h" |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 24 | #include "api/task_queue/pending_task_safety_flag.h" |
| 25 | #include "api/task_queue/task_queue_base.h" |
| 26 | #include "api/units/time_delta.h" |
Steve Anton | 10542f2 | 2019-01-11 09:11:00 -0800 | [diff] [blame] | 27 | #include "p2p/base/port_interface.h" |
Steve Anton | 10542f2 | 2019-01-11 09:11:00 -0800 | [diff] [blame] | 28 | #include "rtc_base/async_packet_socket.h" |
Steve Anton | 10542f2 | 2019-01-11 09:11:00 -0800 | [diff] [blame] | 29 | #include "rtc_base/socket_address.h" |
Niels Möller | ac9a288 | 2021-10-20 15:25:09 +0200 | [diff] [blame] | 30 | #include "rtc_base/ssl_adapter.h" |
Artem Titov | e41c433 | 2018-07-25 15:04:28 +0200 | [diff] [blame] | 31 | #include "rtc_base/third_party/sigslot/sigslot.h" |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 32 | |
| 33 | namespace rtc { |
jbauch | f1f8720 | 2016-03-30 06:43:37 -0700 | [diff] [blame] | 34 | class ByteBufferWriter; |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 35 | class PacketSocketFactory; |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 36 | } // namespace rtc |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 37 | |
| 38 | namespace cricket { |
| 39 | |
| 40 | class StunMessage; |
| 41 | class TurnMessage; |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 42 | class TurnServer; |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 43 | |
| 44 | // The default server port for TURN, as specified in RFC5766. |
| 45 | const int TURN_SERVER_PORT = 3478; |
| 46 | |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 47 | // Encapsulates the client's connection to the server. |
| 48 | class TurnServerConnection { |
| 49 | public: |
| 50 | TurnServerConnection() : proto_(PROTO_UDP), socket_(NULL) {} |
| 51 | TurnServerConnection(const rtc::SocketAddress& src, |
| 52 | ProtocolType proto, |
| 53 | rtc::AsyncPacketSocket* socket); |
| 54 | const rtc::SocketAddress& src() const { return src_; } |
| 55 | rtc::AsyncPacketSocket* socket() { return socket_; } |
| 56 | bool operator==(const TurnServerConnection& t) const; |
| 57 | bool operator<(const TurnServerConnection& t) const; |
| 58 | std::string ToString() const; |
| 59 | |
| 60 | private: |
| 61 | rtc::SocketAddress src_; |
| 62 | rtc::SocketAddress dst_; |
| 63 | cricket::ProtocolType proto_; |
| 64 | rtc::AsyncPacketSocket* socket_; |
| 65 | }; |
| 66 | |
| 67 | // Encapsulates a TURN allocation. |
| 68 | // The object is created when an allocation request is received, and then |
| 69 | // handles TURN messages (via HandleTurnMessage) and channel data messages |
| 70 | // (via HandleChannelData) for this allocation when received by the server. |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 71 | // The object informs the server when its lifetime timer expires. |
| 72 | class TurnServerAllocation : public sigslot::has_slots<> { |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 73 | public: |
| 74 | TurnServerAllocation(TurnServer* server_, |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 75 | webrtc::TaskQueueBase* thread, |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 76 | const TurnServerConnection& conn, |
| 77 | rtc::AsyncPacketSocket* server_socket, |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 78 | absl::string_view key); |
Steve Anton | f2737d2 | 2017-10-31 16:27:34 -0700 | [diff] [blame] | 79 | ~TurnServerAllocation() override; |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 80 | |
| 81 | TurnServerConnection* conn() { return &conn_; } |
| 82 | const std::string& key() const { return key_; } |
| 83 | const std::string& transaction_id() const { return transaction_id_; } |
| 84 | const std::string& username() const { return username_; } |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 85 | const std::string& last_nonce() const { return last_nonce_; } |
Tommi | e83500e | 2022-06-03 14:28:59 +0200 | [diff] [blame] | 86 | void set_last_nonce(absl::string_view nonce) { |
| 87 | last_nonce_ = std::string(nonce); |
| 88 | } |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 89 | |
| 90 | std::string ToString() const; |
| 91 | |
| 92 | void HandleTurnMessage(const TurnMessage* msg); |
| 93 | void HandleChannelData(const char* data, size_t size); |
| 94 | |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 95 | private: |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 96 | struct Channel { |
| 97 | webrtc::ScopedTaskSafety pending_delete; |
| 98 | int id; |
| 99 | rtc::SocketAddress peer; |
| 100 | }; |
| 101 | struct Permission { |
| 102 | webrtc::ScopedTaskSafety pending_delete; |
| 103 | rtc::IPAddress peer; |
| 104 | }; |
| 105 | using PermissionList = std::list<Permission>; |
| 106 | using ChannelList = std::list<Channel>; |
| 107 | |
| 108 | void PostDeleteSelf(webrtc::TimeDelta delay); |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 109 | |
| 110 | void HandleAllocateRequest(const TurnMessage* msg); |
| 111 | void HandleRefreshRequest(const TurnMessage* msg); |
| 112 | void HandleSendIndication(const TurnMessage* msg); |
| 113 | void HandleCreatePermissionRequest(const TurnMessage* msg); |
| 114 | void HandleChannelBindRequest(const TurnMessage* msg); |
| 115 | |
| 116 | void OnExternalPacket(rtc::AsyncPacketSocket* socket, |
Niels Möller | e693381 | 2018-11-05 13:01:41 +0100 | [diff] [blame] | 117 | const char* data, |
| 118 | size_t size, |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 119 | const rtc::SocketAddress& addr, |
Niels Möller | e693381 | 2018-11-05 13:01:41 +0100 | [diff] [blame] | 120 | const int64_t& packet_time_us); |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 121 | |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 122 | static webrtc::TimeDelta ComputeLifetime(const TurnMessage& msg); |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 123 | bool HasPermission(const rtc::IPAddress& addr); |
| 124 | void AddPermission(const rtc::IPAddress& addr); |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 125 | PermissionList::iterator FindPermission(const rtc::IPAddress& addr); |
| 126 | ChannelList::iterator FindChannel(int channel_id); |
| 127 | ChannelList::iterator FindChannel(const rtc::SocketAddress& addr); |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 128 | |
| 129 | void SendResponse(TurnMessage* msg); |
| 130 | void SendBadRequestResponse(const TurnMessage* req); |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 131 | void SendErrorResponse(const TurnMessage* req, |
| 132 | int code, |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 133 | absl::string_view reason); |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 134 | void SendExternal(const void* data, |
| 135 | size_t size, |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 136 | const rtc::SocketAddress& peer); |
| 137 | |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 138 | TurnServer* const server_; |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 139 | webrtc::TaskQueueBase* const thread_; |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 140 | TurnServerConnection conn_; |
kwiberg | 3ec4679 | 2016-04-27 07:22:53 -0700 | [diff] [blame] | 141 | std::unique_ptr<rtc::AsyncPacketSocket> external_socket_; |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 142 | std::string key_; |
| 143 | std::string transaction_id_; |
| 144 | std::string username_; |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 145 | std::string last_nonce_; |
| 146 | PermissionList perms_; |
| 147 | ChannelList channels_; |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 148 | webrtc::ScopedTaskSafety safety_; |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 149 | }; |
| 150 | |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 151 | // An interface through which the MD5 credential hash can be retrieved. |
| 152 | class TurnAuthInterface { |
| 153 | public: |
| 154 | // Gets HA1 for the specified user and realm. |
| 155 | // HA1 = MD5(A1) = MD5(username:realm:password). |
| 156 | // Return true if the given username and realm are valid, or false if not. |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 157 | virtual bool GetKey(absl::string_view username, |
| 158 | absl::string_view realm, |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 159 | std::string* key) = 0; |
Henrik Kjellander | 3fe372d | 2016-05-12 08:10:52 +0200 | [diff] [blame] | 160 | virtual ~TurnAuthInterface() = default; |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 161 | }; |
| 162 | |
| 163 | // An interface enables Turn Server to control redirection behavior. |
| 164 | class TurnRedirectInterface { |
| 165 | public: |
| 166 | virtual bool ShouldRedirect(const rtc::SocketAddress& address, |
| 167 | rtc::SocketAddress* out) = 0; |
| 168 | virtual ~TurnRedirectInterface() {} |
| 169 | }; |
| 170 | |
Jonas Oreland | bdcee28 | 2017-10-10 14:01:40 +0200 | [diff] [blame] | 171 | class StunMessageObserver { |
| 172 | public: |
| 173 | virtual void ReceivedMessage(const TurnMessage* msg) = 0; |
| 174 | virtual void ReceivedChannelData(const char* data, size_t size) = 0; |
| 175 | virtual ~StunMessageObserver() {} |
| 176 | }; |
| 177 | |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 178 | // The core TURN server class. Give it a socket to listen on via |
| 179 | // AddInternalServerSocket, and a factory to create external sockets via |
| 180 | // SetExternalSocketFactory, and it's ready to go. |
| 181 | // Not yet wired up: TCP support. |
| 182 | class TurnServer : public sigslot::has_slots<> { |
| 183 | public: |
deadbeef | 9794366 | 2016-07-12 11:04:50 -0700 | [diff] [blame] | 184 | typedef std::map<TurnServerConnection, std::unique_ptr<TurnServerAllocation>> |
| 185 | AllocationMap; |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 186 | |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 187 | explicit TurnServer(webrtc::TaskQueueBase* thread); |
Steve Anton | f2737d2 | 2017-10-31 16:27:34 -0700 | [diff] [blame] | 188 | ~TurnServer() override; |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 189 | |
| 190 | // Gets/sets the realm value to use for the server. |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 191 | const std::string& realm() const { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 192 | RTC_DCHECK_RUN_ON(thread_); |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 193 | return realm_; |
| 194 | } |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 195 | void set_realm(absl::string_view realm) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 196 | RTC_DCHECK_RUN_ON(thread_); |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 197 | realm_ = std::string(realm); |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 198 | } |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 199 | |
| 200 | // Gets/sets the value for the SOFTWARE attribute for TURN messages. |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 201 | const std::string& software() const { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 202 | RTC_DCHECK_RUN_ON(thread_); |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 203 | return software_; |
| 204 | } |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 205 | void set_software(absl::string_view software) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 206 | RTC_DCHECK_RUN_ON(thread_); |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 207 | software_ = std::string(software); |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 208 | } |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 209 | |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 210 | const AllocationMap& allocations() const { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 211 | RTC_DCHECK_RUN_ON(thread_); |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 212 | return allocations_; |
| 213 | } |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 214 | |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 215 | // Sets the authentication callback; does not take ownership. |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 216 | void set_auth_hook(TurnAuthInterface* auth_hook) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 217 | RTC_DCHECK_RUN_ON(thread_); |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 218 | auth_hook_ = auth_hook; |
| 219 | } |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 220 | |
| 221 | void set_redirect_hook(TurnRedirectInterface* redirect_hook) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 222 | RTC_DCHECK_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 223 | redirect_hook_ = redirect_hook; |
| 224 | } |
| 225 | |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 226 | void set_enable_otu_nonce(bool enable) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 227 | RTC_DCHECK_RUN_ON(thread_); |
Seth Hampson | aed7164 | 2018-06-11 07:41:32 -0700 | [diff] [blame] | 228 | enable_otu_nonce_ = enable; |
| 229 | } |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 230 | |
deadbeef | 376e123 | 2015-11-25 09:00:08 -0800 | [diff] [blame] | 231 | // If set to true, reject CreatePermission requests to RFC1918 addresses. |
| 232 | void set_reject_private_addresses(bool filter) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 233 | RTC_DCHECK_RUN_ON(thread_); |
deadbeef | 376e123 | 2015-11-25 09:00:08 -0800 | [diff] [blame] | 234 | reject_private_addresses_ = filter; |
| 235 | } |
| 236 | |
Taylor Brandstetter | ef18470 | 2016-06-23 17:35:47 -0700 | [diff] [blame] | 237 | void set_enable_permission_checks(bool enable) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 238 | RTC_DCHECK_RUN_ON(thread_); |
Taylor Brandstetter | ef18470 | 2016-06-23 17:35:47 -0700 | [diff] [blame] | 239 | enable_permission_checks_ = enable; |
| 240 | } |
| 241 | |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 242 | // Starts listening for packets from internal clients. |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 243 | void AddInternalSocket(rtc::AsyncPacketSocket* socket, ProtocolType proto); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 244 | // Starts listening for the connections on this socket. When someone tries |
| 245 | // to connect, the connection will be accepted and a new internal socket |
| 246 | // will be added. |
Niels Möller | ac9a288 | 2021-10-20 15:25:09 +0200 | [diff] [blame] | 247 | void AddInternalServerSocket( |
| 248 | rtc::Socket* socket, |
| 249 | ProtocolType proto, |
| 250 | std::unique_ptr<rtc::SSLAdapterFactory> ssl_adapter_factory = nullptr); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 251 | // Specifies the factory to use for creating external sockets. |
| 252 | void SetExternalSocketFactory(rtc::PacketSocketFactory* factory, |
| 253 | const rtc::SocketAddress& address); |
honghaiz | c463e20 | 2016-02-01 15:19:08 -0800 | [diff] [blame] | 254 | // For testing only. |
honghaiz | 34b11eb | 2016-03-16 08:55:44 -0700 | [diff] [blame] | 255 | std::string SetTimestampForNextNonce(int64_t timestamp) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 256 | RTC_DCHECK_RUN_ON(thread_); |
honghaiz | c463e20 | 2016-02-01 15:19:08 -0800 | [diff] [blame] | 257 | ts_for_next_nonce_ = timestamp; |
| 258 | return GenerateNonce(timestamp); |
| 259 | } |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 260 | |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 261 | void SetStunMessageObserver(std::unique_ptr<StunMessageObserver> observer) { |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 262 | RTC_DCHECK_RUN_ON(thread_); |
Jonas Oreland | bdcee28 | 2017-10-10 14:01:40 +0200 | [diff] [blame] | 263 | stun_message_observer_ = std::move(observer); |
| 264 | } |
| 265 | |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 266 | private: |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 267 | // All private member functions and variables should have access restricted to |
| 268 | // thread_. But compile-time annotations are missing for members access from |
| 269 | // TurnServerAllocation (via friend declaration), and the On* methods, which |
| 270 | // are called via sigslot. |
| 271 | std::string GenerateNonce(int64_t now) const RTC_RUN_ON(thread_); |
Niels Möller | e693381 | 2018-11-05 13:01:41 +0100 | [diff] [blame] | 272 | void OnInternalPacket(rtc::AsyncPacketSocket* socket, |
| 273 | const char* data, |
| 274 | size_t size, |
| 275 | const rtc::SocketAddress& address, |
| 276 | const int64_t& packet_time_us); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 277 | |
Niels Möller | d0b8879 | 2021-08-12 10:32:30 +0200 | [diff] [blame] | 278 | void OnNewInternalConnection(rtc::Socket* socket); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 279 | |
| 280 | // Accept connections on this server socket. |
Niels Möller | d0b8879 | 2021-08-12 10:32:30 +0200 | [diff] [blame] | 281 | void AcceptConnection(rtc::Socket* server_socket) RTC_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 282 | void OnInternalSocketClose(rtc::AsyncPacketSocket* socket, int err); |
| 283 | |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 284 | void HandleStunMessage(TurnServerConnection* conn, |
| 285 | const char* data, |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 286 | size_t size) RTC_RUN_ON(thread_); |
| 287 | void HandleBindingRequest(TurnServerConnection* conn, const StunMessage* msg) |
| 288 | RTC_RUN_ON(thread_); |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 289 | void HandleAllocateRequest(TurnServerConnection* conn, |
| 290 | const TurnMessage* msg, |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 291 | absl::string_view key) RTC_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 292 | |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 293 | bool GetKey(const StunMessage* msg, std::string* key) RTC_RUN_ON(thread_); |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 294 | bool CheckAuthorization(TurnServerConnection* conn, |
Harald Alvestrand | 07d83c8 | 2021-03-02 08:09:53 +0000 | [diff] [blame] | 295 | StunMessage* msg, |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 296 | const char* data, |
| 297 | size_t size, |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 298 | absl::string_view key) RTC_RUN_ON(thread_); |
Tommi | e83500e | 2022-06-03 14:28:59 +0200 | [diff] [blame] | 299 | bool ValidateNonce(absl::string_view nonce) const RTC_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 300 | |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 301 | TurnServerAllocation* FindAllocation(TurnServerConnection* conn) |
| 302 | RTC_RUN_ON(thread_); |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 303 | TurnServerAllocation* CreateAllocation(TurnServerConnection* conn, |
| 304 | int proto, |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 305 | absl::string_view key) |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 306 | RTC_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 307 | |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 308 | void SendErrorResponse(TurnServerConnection* conn, |
| 309 | const StunMessage* req, |
| 310 | int code, |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 311 | absl::string_view reason); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 312 | |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 313 | void SendErrorResponseWithRealmAndNonce(TurnServerConnection* conn, |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 314 | const StunMessage* req, |
| 315 | int code, |
Ali Tofigh | de2ac5a | 2022-06-30 11:58:26 +0200 | [diff] [blame] | 316 | absl::string_view reason) |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 317 | RTC_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 318 | |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 319 | void SendErrorResponseWithAlternateServer(TurnServerConnection* conn, |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 320 | const StunMessage* req, |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 321 | const rtc::SocketAddress& addr) |
| 322 | RTC_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 323 | |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 324 | void SendStun(TurnServerConnection* conn, StunMessage* msg); |
jbauch | f1f8720 | 2016-03-30 06:43:37 -0700 | [diff] [blame] | 325 | void Send(TurnServerConnection* conn, const rtc::ByteBufferWriter& buf); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 326 | |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 327 | void DestroyAllocation(TurnServerAllocation* allocation) RTC_RUN_ON(thread_); |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 328 | void DestroyInternalSocket(rtc::AsyncPacketSocket* socket) |
| 329 | RTC_RUN_ON(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 330 | |
Jonas Olsson | a4d8737 | 2019-07-05 19:08:33 +0200 | [diff] [blame] | 331 | typedef std::map<rtc::AsyncPacketSocket*, ProtocolType> InternalSocketMap; |
Niels Möller | ac9a288 | 2021-10-20 15:25:09 +0200 | [diff] [blame] | 332 | struct ServerSocketInfo { |
| 333 | ProtocolType proto; |
| 334 | // If non-null, used to wrap accepted sockets. |
| 335 | std::unique_ptr<rtc::SSLAdapterFactory> ssl_adapter_factory; |
| 336 | }; |
| 337 | typedef std::map<rtc::Socket*, ServerSocketInfo> ServerSocketMap; |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 338 | |
Danil Chapovalov | e51918f | 2022-08-16 19:41:38 +0200 | [diff] [blame] | 339 | webrtc::TaskQueueBase* const thread_; |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 340 | const std::string nonce_key_; |
| 341 | std::string realm_ RTC_GUARDED_BY(thread_); |
| 342 | std::string software_ RTC_GUARDED_BY(thread_); |
| 343 | TurnAuthInterface* auth_hook_ RTC_GUARDED_BY(thread_); |
| 344 | TurnRedirectInterface* redirect_hook_ RTC_GUARDED_BY(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 345 | // otu - one-time-use. Server will respond with 438 if it's |
| 346 | // sees the same nonce in next transaction. |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 347 | bool enable_otu_nonce_ RTC_GUARDED_BY(thread_); |
deadbeef | 376e123 | 2015-11-25 09:00:08 -0800 | [diff] [blame] | 348 | bool reject_private_addresses_ = false; |
Taylor Brandstetter | ef18470 | 2016-06-23 17:35:47 -0700 | [diff] [blame] | 349 | // Check for permission when receiving an external packet. |
| 350 | bool enable_permission_checks_ = true; |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 351 | |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 352 | InternalSocketMap server_sockets_ RTC_GUARDED_BY(thread_); |
| 353 | ServerSocketMap server_listen_sockets_ RTC_GUARDED_BY(thread_); |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 354 | std::unique_ptr<rtc::PacketSocketFactory> external_socket_factory_ |
| 355 | RTC_GUARDED_BY(thread_); |
| 356 | rtc::SocketAddress external_addr_ RTC_GUARDED_BY(thread_); |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 357 | |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 358 | AllocationMap allocations_ RTC_GUARDED_BY(thread_); |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 359 | |
honghaiz | c463e20 | 2016-02-01 15:19:08 -0800 | [diff] [blame] | 360 | // For testing only. If this is non-zero, the next NONCE will be generated |
| 361 | // from this value, and it will be reset to 0 after generating the NONCE. |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 362 | int64_t ts_for_next_nonce_ RTC_GUARDED_BY(thread_) = 0; |
honghaiz | c463e20 | 2016-02-01 15:19:08 -0800 | [diff] [blame] | 363 | |
Jonas Oreland | bdcee28 | 2017-10-10 14:01:40 +0200 | [diff] [blame] | 364 | // For testing only. Used to observe STUN messages received. |
Niels Möller | 76b51e2 | 2021-03-18 15:44:24 +0100 | [diff] [blame] | 365 | std::unique_ptr<StunMessageObserver> stun_message_observer_ |
| 366 | RTC_GUARDED_BY(thread_); |
Jonas Oreland | bdcee28 | 2017-10-10 14:01:40 +0200 | [diff] [blame] | 367 | |
pthatcher@webrtc.org | 0ba1533 | 2015-01-10 00:47:02 +0000 | [diff] [blame] | 368 | friend class TurnServerAllocation; |
henrike@webrtc.org | 269fb4b | 2014-10-28 22:20:11 +0000 | [diff] [blame] | 369 | }; |
| 370 | |
| 371 | } // namespace cricket |
| 372 | |
Steve Anton | 10542f2 | 2019-01-11 09:11:00 -0800 | [diff] [blame] | 373 | #endif // P2P_BASE_TURN_SERVER_H_ |