Repository navigation
feat: @profullstack/pairux-embed, E2EE calls for partner apps - #133
Merged
Merged
Conversation
A framework-agnostic library any web app can drop in for voice, video and screen sharing on PairUX's SFU, end-to-end encrypted with LiveKit E2EE: - packages/embed: PairuxCall (key set + E2EE on BEFORE connect; refuses a browser that cannot encrypt instead of downgrading to plaintext; rotateKey, mic/camera/screen, participants with per-participant encryption status) and mountCall, a plain-DOM tile grid + controls, themeable via CSS vars. - POST /api/v1/partner/token: a partner's server (Bearer pux_pk_…) mints a 6h LiveKit token for one of its users in its own namespace (partner-<id>-<room>, identity <id>:<user>). Partners are configured in PAIRUX_PARTNERS with only a SHA-256 of each key; constant-time compare. The media key never reaches PairUX. Recording, restreaming and call analysis only act on session-* rooms, so partner rooms are never touched. First partner: qrypt.chat, which will share the media key ML-KEM-1024 encrypted to each participant. Gates run by hand (the pre-commit hook OOMs on this box): embed + web typecheck, eslint on changed files (0 errors), repo-wide format:check, vitest (embed 5, partner token 5). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ThreatCrush Security Scan47 finding(s) HIGH/CRITICAL: 4 | MEDIUM: 27 | LOW: 16
Snippets are redacted; ThreatCrush never prints matched credential material. |
…gitleaks Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This adds
@profullstack/pairux-embed, a framework-agnostic library any web app can drop in for voice, video and screen sharing on PairUX's SFU, with end-to-end encryption via LiveKit E2EE. It also adds the partner token endpoint that lets another app's server use it. The first partner is qrypt.chat.The library (
packages/embed)PairuxCallE2EEUnsupportedError) rather than downgraded to a plaintext call.setMic,setCamera,setScreen,rotateKey,leave.participants(each participant carries anencryptedflag from LiveKit's encryption status),track,state,error.mountCall(el, call)Other:
newMediaKey()returns 32 random bytes.The E2EE worker: it defaults to
livekit-client/e2ee-worker, which Vite, webpack 5 and Next resolve. Apps can pass their own.Partner tokens (
POST /api/v1/partner/token)Authorization: Bearer pux_pk_…with{ room, identity, name }.url,iceServersande2ee: true.partner-<id>-<room>; the room id is restricted to[A-Za-z0-9_-], so it can't escape the namespace.<id>:<user>.PAIRUX_PARTNERS, which holds only a SHA-256 of each key, compared in constant time. No database migration.session-*rooms, so partner rooms are never recorded or analysed.Not in this PR
NEXT_PUBLIC_*), so this endpoint exposes nothing new. Switching coturn to time-limited credentials (use-auth-secret) is a separate infra change.Gates
I ran these by hand, because the pre-commit hook OOMs on this box:
pnpm --filter @pairux/web typechecktscfor the embed packagepnpm format:check🤖 Generated with Claude Code