Security Architecture & Access Control
Security is a foundational pillar of RUSEON Core. The server is engineered to protect IP video feeds, prevent unauthorized stream tampering, enforce granular access controls, and defend against network-based attacks.
1. Authentication & JWT Tokens
RUSEON Core uses stateless JSON Web Tokens (JWT) for API authentication:
- Algorithm: HMAC-SHA256 (
HS256) with a minimum 32-character secret key. - Token Expiry: Configurable access token lifetime (default: 24 hours).
- Header Format:
Authorization: Bearer <TOKEN>.
Configuration in config.yaml:
yaml
auth:
enabled: true
jwt_secret: "a_very_long_cryptographically_secure_random_string_here_32chars"
token_expiry: "24h"
bcrypt_cost: 122. Role-Based Access Control (RBAC)
RUSEON Core enforces strict permission hierarchies:
| Role | Permissions & Scope |
|---|---|
admin | Full system control: Add/remove cameras, manage users, modify retention, trigger backups |
operator | Operational control: View live streams, browse archive timeline, control PTZ, export MP4 clips |
viewer | Read-only access: View assigned live cameras and authorized HLS/WHEP feeds |
3. Cross-Origin Resource Sharing (CORS)
When integrating RUSEON video streams into third-party web portals or external dashboards, restrict allowed origins:
yaml
security:
cors_allowed_origins:
- "https://portal.company.com"
- "https://monitoring.internal"
cors_allowed_methods:
- "GET"
- "POST"
- "OPTIONS"
cors_allowed_headers:
- "Authorization"
- "Content-Type"
- "Range"4. Rate Limiting & Brute-Force Protection
Authentication endpoints (/api/v1/auth/login) enforce an in-memory token-bucket rate limiter:
- Restricts failed login attempts per client IP.
- Automatically throttles requests exceeding 5 attempts per minute.
5. TLS & Transport Encryption
- Supported Protocols: TLS 1.3 and TLS 1.2 (TLS 1.0 and 1.1 are permanently disabled).
- Strict HTTPS for WebRTC: Browsers enforce that WebRTC camera access and WHEP negotiation occur exclusively over secure HTTPS / WSS contexts.