Skip to content

Security Architecture & Access Control ​

Security is a foundational pillar of RUSEON Core. The server is engineered to protect IP video feeds, prevent unauthorized stream tampering, enforce granular access controls, and defend against network-based attacks.


1. Authentication & JWT Tokens ​

RUSEON Core uses stateless JSON Web Tokens (JWT) for API authentication:

  • Algorithm: HMAC-SHA256 (HS256) with a minimum 32-character secret key.
  • Token Expiry: Configurable access token lifetime (default: 24 hours).
  • Header Format: Authorization: Bearer <TOKEN>.

Configuration in config.yaml: ​

yaml
auth:
  enabled: true
  jwt_secret: "a_very_long_cryptographically_secure_random_string_here_32chars"
  token_expiry: "24h"
  bcrypt_cost: 12

2. Role-Based Access Control (RBAC) ​

RUSEON Core enforces strict permission hierarchies:

RolePermissions & Scope
adminFull system control: Add/remove cameras, manage users, modify retention, trigger backups
operatorOperational control: View live streams, browse archive timeline, control PTZ, export MP4 clips
viewerRead-only access: View assigned live cameras and authorized HLS/WHEP feeds

3. Cross-Origin Resource Sharing (CORS) ​

When integrating RUSEON video streams into third-party web portals or external dashboards, restrict allowed origins:

yaml
security:
  cors_allowed_origins:
    - "https://portal.company.com"
    - "https://monitoring.internal"
  cors_allowed_methods:
    - "GET"
    - "POST"
    - "OPTIONS"
  cors_allowed_headers:
    - "Authorization"
    - "Content-Type"
    - "Range"

4. Rate Limiting & Brute-Force Protection ​

Authentication endpoints (/api/v1/auth/login) enforce an in-memory token-bucket rate limiter:

  • Restricts failed login attempts per client IP.
  • Automatically throttles requests exceeding 5 attempts per minute.

5. TLS & Transport Encryption ​

  • Supported Protocols: TLS 1.3 and TLS 1.2 (TLS 1.0 and 1.1 are permanently disabled).
  • Strict HTTPS for WebRTC: Browsers enforce that WebRTC camera access and WHEP negotiation occur exclusively over secure HTTPS / WSS contexts.

Released under the MIT License.