From 1ab28b86daa094c7f26b14ea5a8e246ab0612133 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 12 Aug 2026 06:53:54 +0000 Subject: [PATCH] Updated NPM changelogs --- .changeset/player-forced-subscribe-crash.md | 6 ------ .changeset/turn-ephemeral-credentials.md | 6 ------ Signalling/CHANGELOG.md | 10 ++++++++++ Signalling/package.json | 2 +- SignallingWebServer/CHANGELOG.md | 14 +++++++++++++- SignallingWebServer/package.json | 2 +- 6 files changed, 25 insertions(+), 15 deletions(-) delete mode 100644 .changeset/player-forced-subscribe-crash.md delete mode 100644 .changeset/turn-ephemeral-credentials.md diff --git a/.changeset/player-forced-subscribe-crash.md b/.changeset/player-forced-subscribe-crash.md deleted file mode 100644 index 2d3bc2a13..000000000 --- a/.changeset/player-forced-subscribe-crash.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -'@epicgames-ps/lib-pixelstreamingsignalling-ue5.8': patch -'@epicgames-ps/wilbur': patch ---- - -Stop an unsubscribed player from crashing the signalling server. When a player sends a message without being subscribed, `sendToStreamer` force-subscribes it to the first available streamer and then forwards through `this.subscribedStreamer!`. `subscribe()` can decline — most commonly because `maxSubscribers` is already reached — and reports that only by leaving `subscribedStreamer` unset, so the non-null assertions throw a TypeError out of a websocket message handler and take the process down, disconnecting every other player. It now checks the subscription took, and disconnects just that player if it did not. diff --git a/.changeset/turn-ephemeral-credentials.md b/.changeset/turn-ephemeral-credentials.md deleted file mode 100644 index f078541dd..000000000 --- a/.changeset/turn-ephemeral-credentials.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -'@epicgames-ps/lib-pixelstreamingsignalling-ue5.8': minor -'@epicgames-ps/wilbur': minor ---- - -Allow TURN credentials to be issued per connection rather than shared by every session. `peerOptions` is static, so a credential written there is sent to every peer that ever connects and cannot be changed without a redeploy — the weakness noted in tip 3 of the security guidelines. `IServerConfig.peerOptionsProvider` is consulted once per connecting peer and returns the peer options for that peer, falling back to `peerOptions` if it throws. On top of it the signalling server adds `--turn_secret` (or `--turn_secret_file`) and `--turn_ttl`, which give every `turn:`/`turns:` entry a time limited username and credential in the form coturn's `use-auth-secret` mode expects. Default behaviour is unchanged when no secret is supplied. See `Docs/Security-Guidelines.md`. diff --git a/Signalling/CHANGELOG.md b/Signalling/CHANGELOG.md index c263a833d..da3614056 100644 --- a/Signalling/CHANGELOG.md +++ b/Signalling/CHANGELOG.md @@ -1,5 +1,15 @@ # @epicgames-ps/lib-pixelstreamingsignalling-ue5.6 +## 0.2.0 + +### Minor Changes + +- c8cd21a: Allow TURN credentials to be issued per connection rather than shared by every session. `peerOptions` is static, so a credential written there is sent to every peer that ever connects and cannot be changed without a redeploy — the weakness noted in tip 3 of the security guidelines. `IServerConfig.peerOptionsProvider` is consulted once per connecting peer and returns the peer options for that peer, falling back to `peerOptions` if it throws. On top of it the signalling server adds `--turn_secret` (or `--turn_secret_file`) and `--turn_ttl`, which give every `turn:`/`turns:` entry a time limited username and credential in the form coturn's `use-auth-secret` mode expects. Default behaviour is unchanged when no secret is supplied. See `Docs/Security-Guidelines.md`. + +### Patch Changes + +- e9cd872: Stop an unsubscribed player from crashing the signalling server. When a player sends a message without being subscribed, `sendToStreamer` force-subscribes it to the first available streamer and then forwards through `this.subscribedStreamer!`. `subscribe()` can decline — most commonly because `maxSubscribers` is already reached — and reports that only by leaving `subscribedStreamer` unset, so the non-null assertions throw a TypeError out of a websocket message handler and take the process down, disconnecting every other player. It now checks the subscription took, and disconnects just that player if it did not. + ## 0.2.1 ### Patch Changes diff --git a/Signalling/package.json b/Signalling/package.json index 21e3140af..f174f7b9a 100644 --- a/Signalling/package.json +++ b/Signalling/package.json @@ -1,6 +1,6 @@ { "name": "@epicgames-ps/lib-pixelstreamingsignalling-ue5.8", - "version": "0.1.0", + "version": "0.2.0", "description": "Basic signalling library for developers wishing to build applications that signal a Pixel Streaming application.", "main": "dist/cjs/pixelstreamingsignalling.js", "module": "dist/esm/pixelstreamingsignalling.js", diff --git a/SignallingWebServer/CHANGELOG.md b/SignallingWebServer/CHANGELOG.md index 94c7ec41e..9d252de22 100644 --- a/SignallingWebServer/CHANGELOG.md +++ b/SignallingWebServer/CHANGELOG.md @@ -1,11 +1,23 @@ # @epicgames-ps/wilbur +## 3.1.0 + +### Minor Changes + +- c8cd21a: Allow TURN credentials to be issued per connection rather than shared by every session. `peerOptions` is static, so a credential written there is sent to every peer that ever connects and cannot be changed without a redeploy — the weakness noted in tip 3 of the security guidelines. `IServerConfig.peerOptionsProvider` is consulted once per connecting peer and returns the peer options for that peer, falling back to `peerOptions` if it throws. On top of it the signalling server adds `--turn_secret` (or `--turn_secret_file`) and `--turn_ttl`, which give every `turn:`/`turns:` entry a time limited username and credential in the form coturn's `use-auth-secret` mode expects. Default behaviour is unchanged when no secret is supplied. See `Docs/Security-Guidelines.md`. + +### Patch Changes + +- e9cd872: Stop an unsubscribed player from crashing the signalling server. When a player sends a message without being subscribed, `sendToStreamer` force-subscribes it to the first available streamer and then forwards through `this.subscribedStreamer!`. `subscribe()` can decline — most commonly because `maxSubscribers` is already reached — and reports that only by leaving `subscribedStreamer` unset, so the non-null assertions throw a TypeError out of a websocket message handler and take the process down, disconnecting every other player. It now checks the subscription took, and disconnects just that player if it did not. +- Updated dependencies [e9cd872] +- Updated dependencies [c8cd21a] + - @epicgames-ps/lib-pixelstreamingsignalling-ue5.8@0.2.0 + ## 2.3.0 ### Minor Changes - 3bb3101: Updates to platform_scripts to fix argument passing to Wilbur. - - Added separator between script parameters and signalling server parameters when using platform scripts - From now on, anything after the `--` marker on the command line is passed directly to Wilbur. - Parameters before this marker are intended for the scripts. These parameters are validated and unknown parameters will cause an error. diff --git a/SignallingWebServer/package.json b/SignallingWebServer/package.json index 6aa5aa10c..ff63ab410 100644 --- a/SignallingWebServer/package.json +++ b/SignallingWebServer/package.json @@ -1,6 +1,6 @@ { "name": "@epicgames-ps/wilbur", - "version": "3.0.0", + "version": "3.1.0", "description": "A basic signalling server application for Unreal Engine's Pixel Streaming applications.", "main": "dist/index.js", "private": true,