ascii-chat 0.11.33
Video chat in your terminal
Loading...
Searching...
No Matches
turn_credentials.h File Reference

TURN server credential generation for WebRTC. More...

Go to the source code of this file.

Data Structures

struct  turn_credentials_t
 TURN server credentials (username + password) More...
 

Functions

asciichat_error_t turn_generate_credentials (const char *session_id, const char *secret, uint32_t validity_seconds, turn_credentials_t *out_credentials)
 Generate time-limited TURN credentials.
 
bool turn_credentials_expired (const turn_credentials_t *credentials)
 Check if TURN credentials have expired.
 

Detailed Description

TURN server credential generation for WebRTC.

Implements time-limited HMAC-based TURN authentication as specified in RFC 5389 (STUN) and RFC 5766 (TURN).

Credential format:

  • Username: "{timestamp}:{session_id}"
  • Password: base64(HMAC-SHA1(secret, username))

The timestamp provides time-limited credentials that expire after a configurable duration (default 24 hours).

Definition in file turn_credentials.h.

Function Documentation

◆ turn_credentials_expired()

bool turn_credentials_expired ( const turn_credentials_t *  credentials)

Check if TURN credentials have expired.

Parameters
credentialsCredentials to check
Returns
true if expired, false if still valid

Definition at line 192 of file turn_credentials.c.

192 {
193 if (!credentials) {
194 return true;
195 }
196
197 time_t now = time(NULL);
198 return now >= credentials->expires_at;
199}

References turn_credentials_t::expires_at.

◆ turn_generate_credentials()

asciichat_error_t turn_generate_credentials ( const char *  session_id,
const char *  secret,
uint32_t  validity_seconds,
turn_credentials_t *  out_credentials 
)

Generate time-limited TURN credentials.

Creates TURN authentication credentials using HMAC-SHA1 with a shared secret. The username includes a timestamp for automatic expiration.

Parameters
session_idSession identifier (e.g., "swift-river-mountain")
secretShared secret configured on TURN server
validity_secondsHow long credentials remain valid (default: 86400 = 24 hours)
out_credentialsOutput credentials structure
Returns
ASCIICHAT_OK on success, error code on failure
Note
The secret must match the static-auth-secret configured on the TURN server

Example:

"swift-river-mountain",
"my-turn-secret",
86400, // 24 hours
&creds
);
if (result == ASCIICHAT_OK) {
printf("Username: %s\n", creds.username);
printf("Password: %s\n", creds.password);
}
asciichat_error_t
Error and exit codes - unified status values (0-255)
Definition error_codes.h:49
@ ASCIICHAT_OK
Definition error_codes.h:51
TURN server credentials (username + password)
asciichat_error_t turn_generate_credentials(const char *session_id, const char *secret, uint32_t validity_seconds, turn_credentials_t *out_credentials)
Generate time-limited TURN credentials.

Definition at line 142 of file turn_credentials.c.

143 {
144 if (!session_id || !secret || !out_credentials) {
145 return SET_ERRNO(ERROR_INVALID_PARAM, "TURN credentials: NULL parameter");
146 }
147
148 if (validity_seconds == 0) {
149 return SET_ERRNO(ERROR_INVALID_PARAM, "TURN credentials: validity_seconds must be > 0");
150 }
151
152 // Calculate expiration timestamp
153 time_t now = time(NULL);
154 time_t expires_at = now + (time_t)validity_seconds;
155
156 // Format username: "{timestamp}:{session_id}"
157 int username_len = safe_snprintf(out_credentials->username, sizeof(out_credentials->username), "%ld:%s",
158 (long)expires_at, session_id);
159 if (username_len < 0 || (size_t)username_len >= sizeof(out_credentials->username)) {
160 return SET_ERRNO(ERROR_BUFFER_OVERFLOW, "TURN credentials: username too long");
161 }
162
163 // Compute HMAC-SHA1(secret, username)
164 uint8_t hmac_result[SHA1_DIGEST_LENGTH];
165 unsigned int hmac_len = 0;
166
167 asciichat_error_t result = hmac_sha1((const uint8_t *)out_credentials->username, (size_t)username_len,
168 (const uint8_t *)secret, strlen(secret), hmac_result, &hmac_len);
169 if (result != ASCIICHAT_OK) {
170 return result;
171 }
172
173 if (hmac_len != SHA1_DIGEST_LENGTH) {
174 return SET_ERRNO(ERROR_CRYPTO, "TURN credentials: unexpected HMAC length %u (expected %u)", hmac_len,
176 }
177
178 // Base64-encode the HMAC to get the password
179 size_t encoded_len =
180 base64_encode(hmac_result, hmac_len, out_credentials->password, sizeof(out_credentials->password));
181 if (encoded_len == 0) {
182 return SET_ERRNO(ERROR_BUFFER_OVERFLOW, "TURN credentials: password encoding failed");
183 }
184
185 out_credentials->expires_at = expires_at;
186
187 log_debug("Generated TURN credentials: username=%s, expires_at=%ld", out_credentials->username, (long)expires_at);
188
189 return ASCIICHAT_OK;
190}
unsigned char uint8_t
Definition common.h:56
#define SET_ERRNO(code, context_msg,...)
Set error code with custom context message and log it, returning the error code.
@ ERROR_CRYPTO
Definition error_codes.h:96
@ ERROR_INVALID_PARAM
@ ERROR_BUFFER_OVERFLOW
#define log_debug(...)
Log a DEBUG message.
Definition log/log.h:548
int safe_snprintf(char *buffer, size_t buffer_size, const char *format,...)
Safe formatted string printing to buffer.
Definition system.c:148
#define SHA1_DIGEST_LENGTH
Definition sha1.h:17
uint8_t session_id[16]

References ASCIICHAT_OK, ERROR_BUFFER_OVERFLOW, ERROR_CRYPTO, ERROR_INVALID_PARAM, turn_credentials_t::expires_at, log_debug, turn_credentials_t::password, safe_snprintf(), session_id, SET_ERRNO, SHA1_DIGEST_LENGTH, and turn_credentials_t::username.

Referenced by database_session_join().