hub library

The WebSocket relay hub.

Server-side only. This library imports dart:io, so it is deliberately not exported from package:peer_coordinator/peer_coordinator.dart — that barrel has to stay web-safe. Browser clients connect to a hub; they never host one.

Security posture

This is research software. Every peer that authenticates is inside one trust domain: it can see every other peer, and subscribe to every stream. The secret is the whole boundary, so hand it only to people you would let run code in your session, and put the hub behind a reverse proxy rather than on a public interface — see deploy/ for a compose stack that does that.

What the hub does guarantee:

  • nothing happens on a connection before it proves knowledge of the shared secret, and an unauthenticated socket holds a nonce and a timer, no more;
  • a peer cannot publish, relay or signal under another peer's identity, because every endpoint id is checked against the nodeUId it authenticated as;
  • no single frame can make the hub allocate without bound;
  • ending a session disconnects everyone and invalidates every outstanding credential, so participants cannot rejoin afterwards.

Classes

CoordinationHub
A role-blind relay.
HubAdminServer
Session control over HTTP, on its own port.
HubCloseCode
WebSocket close codes the hub uses to say why it hung up.
HubCredentials
The shared secret for one hub session.
WsLimits
What a hub will accept before it stops being polite.

Enums

HubSessionStatus
Whether a hub is currently admitting peers.