hub library
The WebSocket relay hub.
Server-side only. This library imports dart:io, so it is deliberately
not exported from package:peer_coordinator/peer_coordinator.dart — that
barrel has to stay web-safe. Browser clients connect to a hub; they never
host one.
Security posture
This is research software. Every peer that authenticates is inside one trust
domain: it can see every other peer, and subscribe to every stream. The
secret is the whole boundary, so hand it only to people you would let run
code in your session, and put the hub behind a reverse proxy rather than on
a public interface — see deploy/ for a compose stack that does that.
What the hub does guarantee:
- nothing happens on a connection before it proves knowledge of the shared secret, and an unauthenticated socket holds a nonce and a timer, no more;
- a peer cannot publish, relay or signal under another peer's identity,
because every endpoint id is checked against the
nodeUIdit authenticated as; - no single frame can make the hub allocate without bound;
- ending a session disconnects everyone and invalidates every outstanding credential, so participants cannot rejoin afterwards.
Classes
- CoordinationHub
- A role-blind relay.
- HubAdminServer
- Session control over HTTP, on its own port.
- HubCloseCode
- WebSocket close codes the hub uses to say why it hung up.
- HubCredentials
- The shared secret for one hub session.
- WsLimits
- What a hub will accept before it stops being polite.
Enums
- HubSessionStatus
- Whether a hub is currently admitting peers.