mirror of
https://github.com/signalwire/freeswitch.git
synced 2026-10-04 02:03:59 +00:00
A client message can select which chat proto handles it, and the `api` proto runs the address as a FreeSWITCH API command. That route does not pass through `verto.fsapi`, so the per-user fsapi permission does not apply to it. The new per-profile `enable-chat-api-proto` param controls the route and is off unless set; a message selecting the proto without it is refused and logged. The proto compare is case-insensitive, matching the chat interface registry, which is created with `switch_core_hash_init_nocase()`. Only the `api` proto is gated. A message carrying no proto selector, or one naming any other chat proto, routes exactly as before. The param ships commented out in both vanilla verto profiles.
70 lines
3.5 KiB
XML
70 lines
3.5 KiB
XML
<configuration name="verto.conf" description="HTML5 Verto Endpoint">
|
|
|
|
<settings>
|
|
<param name="debug" value="0"/>
|
|
<!-- <param name="kslog" value="true"/> -->
|
|
<!-- seconds to wait before hanging up a disconnected channel -->
|
|
<!-- <param name="detach-timeout-sec" value="120"/> -->
|
|
<!-- enable broadcasting all FreeSWITCH events in Verto -->
|
|
<!-- <param name="enable-fs-events" value="false"/> -->
|
|
<!-- enable broadcasting FreeSWITCH presence events in Verto -->
|
|
<!-- <param name="enable-presence" value="true"/> -->
|
|
</settings>
|
|
|
|
<profiles>
|
|
<profile name="default-v4">
|
|
<param name="bind-local" value="$${local_ip_v4}:8081"/>
|
|
<param name="bind-local" value="$${local_ip_v4}:8082" secure="true"/>
|
|
<param name="force-register-domain" value="$${domain}"/>
|
|
<param name="secure-combined" value="$${certs_dir}/wss.pem"/>
|
|
<param name="secure-chain" value="$${certs_dir}/wss.pem"/>
|
|
<param name="userauth" value="true"/>
|
|
<!-- setting this to true will allow anyone to register even with no account so use with care -->
|
|
<param name="blind-reg" value="false"/>
|
|
<!-- lets a client message to api+<command> run FreeSWITCH API commands. Not
|
|
recommended: it is all or nothing and bypasses the per-user fsapi permission.
|
|
Prefer the fsapi method with jsonrpc-allowed-fsapi, which allow-lists commands
|
|
per user. This param is here for clients that already use api+<command>. -->
|
|
<!-- <param name="enable-chat-api-proto" value="true"/> -->
|
|
<param name="mcast-ip" value="224.1.1.1"/>
|
|
<param name="mcast-port" value="1337"/>
|
|
<param name="rtp-ip" value="$${local_ip_v4}"/>
|
|
<param name="ext-rtp-ip" value="$${external_rtp_ip}"/>
|
|
<param name="local-network" value="localnet.auto"/>
|
|
<param name="outbound-codec-string" value="opus,h264,vp8"/>
|
|
<param name="inbound-codec-string" value="opus,h264,vp8"/>
|
|
|
|
<param name="apply-candidate-acl" value="localnet.auto"/>
|
|
<param name="apply-candidate-acl" value="wan_v4.auto"/>
|
|
<param name="apply-candidate-acl" value="rfc1918.auto"/>
|
|
<param name="apply-candidate-acl" value="any_v4.auto"/>
|
|
<param name="timer-name" value="soft"/>
|
|
|
|
</profile>
|
|
|
|
<profile name="default-v6">
|
|
<param name="bind-local" value="[$${local_ip_v6}]:8081"/>
|
|
<param name="bind-local" value="[$${local_ip_v6}]:8082" secure="true"/>
|
|
<param name="force-register-domain" value="$${domain}"/>
|
|
<param name="secure-combined" value="$${certs_dir}/wss.pem"/>
|
|
<param name="secure-chain" value="$${certs_dir}/wss.pem"/>
|
|
<param name="userauth" value="true"/>
|
|
<!-- setting this to true will allow anyone to register even with no account so use with care -->
|
|
<param name="blind-reg" value="false"/>
|
|
<!-- <param name="enable-chat-api-proto" value="true"/> -->
|
|
<param name="rtp-ip" value="$${local_ip_v6}"/>
|
|
<!-- <param name="ext-rtp-ip" value=""/> -->
|
|
<param name="outbound-codec-string" value="opus,h264,vp8"/>
|
|
<param name="inbound-codec-string" value="opus,h264,vp8"/>
|
|
|
|
<param name="apply-candidate-acl" value="wan_v6.auto"/>
|
|
<param name="apply-candidate-acl" value="rfc1918.auto"/>
|
|
<param name="apply-candidate-acl" value="any_v6.auto"/>
|
|
<param name="apply-candidate-acl" value="wan_v4.auto"/>
|
|
<param name="apply-candidate-acl" value="any_v4.auto"/>
|
|
<param name="timer-name" value="soft"/>
|
|
|
|
</profile>
|
|
</profiles>
|
|
</configuration>
|