From 698fef580e75264ebf02f5c203cda3574ff98e74 Mon Sep 17 00:00:00 2001 From: neuronori Date: Tue, 30 Jun 2026 20:15:04 +0000 Subject: [PATCH] docs(wbstream): explain datachannel needs moderator token in auth.token - expand auth.token entry with canPublishData effect on datachannel - note in compatibility matrix and transport table - add moderator-grant screenshots and ru sync - record future auto-grant idea as a docs note --- docs/asset/wbstream-moderator/menu.png | Bin 0 -> 220 bytes .../wbstream-moderator/moderator-button.png | Bin 0 -> 2459 bytes .../asset/wbstream-moderator/participants.png | Bin 0 -> 1494 bytes docs/settings.md | 21 ++++++++++++++++-- docs/settings.ru.md | 20 ++++++++++++++++- 5 files changed, 38 insertions(+), 3 deletions(-) create mode 100644 docs/asset/wbstream-moderator/menu.png create mode 100644 docs/asset/wbstream-moderator/moderator-button.png create mode 100644 docs/asset/wbstream-moderator/participants.png diff --git a/docs/asset/wbstream-moderator/menu.png b/docs/asset/wbstream-moderator/menu.png new file mode 100644 index 0000000000000000000000000000000000000000..b4f852b9740f7d256bfb9b7dc22f224b5e8cb962 GIT binary patch literal 220 zcmeAS@N?(olHy`uVBq!ia0vp^Qb26R!3HF6s&qC3sl}cyjv*Cu-cEDmI%FW=TEDcN zBX-Aza!ompld+ptZJ(gmDz|uDG51nd<~)N^qGBy*C>QpugOZdC`!WR8pWJD8uJO6yp$ T|H((7a~V8c{an^LB{Ts58I)G^ literal 0 HcmV?d00001 diff --git a/docs/asset/wbstream-moderator/moderator-button.png b/docs/asset/wbstream-moderator/moderator-button.png new file mode 100644 index 0000000000000000000000000000000000000000..274f90ff4de462deff31459bcb53aab13893d925 GIT binary patch literal 2459 zcmV;M31s$(P)$oxaYg}A#L;rx(SU-ZvW)vi z2FZw1?lUfcL`0p48{mSXXiQm(Km#fu3gn&x{p=P{KrOrBepOxF@4ow%?&|;k=bZcA zGq$m@D}zKL(F+%o3szk2|Uf_ysbv_1u3-4^zf{}D+}sSQ zsh4p4cnlL zDJjBL-7BpdI`q#X^fkx9gNG`ub8v9Lu3b?a7N0x!AFNsPE!wncqtj>c;)NVqzx?Xk z_m3}5*2oA`rg$JW_9(7iP2~`qmZ_a+(V{tT^W~RQ5E=PT<#;Pr1aere!PvMFX3q3M zLP9*QTuDJp%u%?yj#JiCTUF<>fBzm{Pv!E76DQ!vk)OFQ?Z?k=7Me9{rtD+RoZ0yC z$7sx$;e*7)6Ws5>fqnctN$QR|?@6WQR|&VrNA0xcT@4rGTK32G?GaeHG7#3**0^`? zp3+Vs@u5RMAuB6Or+@$cA7k_84cN11FM@);g^9^;;N|6ssHpEnzB>~6`T5+>%*+fY zPo6|@@M>PRw6ws+jq7#xHEWhHMvinA`w135RE^=kR@d>(;&K>+S7{B}@D< zZJHOXtgH|aupC>qY{r-|E_nX@Ii^niN_-wI^6q80bLYS4*|P`c&;JGw9y~x?+;NN= zHHO7V?TZ#Iz@$lEAU8Kpi59%Qy?B5K2?;||(plKqwHHG574NouObrx$6ciMQ-)1uZ zF3!%*ShXsMFAqC%((vdlvjCKBVY|JTecK} znFwEBKjlxJoSe+}>`}Kj4iU>B<0PVq(G~4Gj%f&i(xPi^$B(#HLLf(4$9p zT)cRR+n+sq1|Odp$jMRj@{S!5=+^BIVxXEPg<1txmMsx5*9CpL+u`=zEChz{Lv49k zxb=lv7n8`5A|s>V;xY!!n>Xh+3We#X~pNr7# zG01;h2#@hjXvk0sR_7bX)#^O#-MgO)DibES;o-xFBBZPw%26(snwknnM@OA@D(sN+ zPzX%4Zf(hqO3qgu*RNk^$Li3bJv)`=_4Mge;gBXeIS7Tg+E8dt`%g(pWhd*><@eaO zZMz7`&+tAnGBR`?d+{pL($Y{|TwLipIXLuZVP3d!QE9WawdI#KLxv3I??MBMM4K{X z+CmgwW5%-NjTO>+%{ zjz>9~TCEn&94(4HtvP&s^ym@ijFjUM6wVSII&=_X%3!zMvSlkgJw3Ud@?IO8cAPKA z#>R1;sNu8EhH-96`KYyZ8{xt;IV`7emClnK*~!TX$BxCa3sZ5ZZQI|93h}wueQnO2 zDL18p6%7vO&Yeg5_O{{}zM^^@EAr+Pr7w+!l(()~vzE`FA`lX^r>8e0l?e#lhp=Un z*hxvGk{8rjsPt#2yo_=?5?pnVYk7D~5z`dYMFD3cJ77Y>Ng>=7EKU!PFSr6rL`6kb z+McSeh|V@4A))Bkub&u5#&V^W1RE3-qzoqB z-ahd6Un26wL~#y}MFA;}bH|zz7WN(I)1QAnK@^L;#W`h*>8EJX9^#|6Q*-*ge( z7;$makm&pI0Q_<)K|daDR#H-0ZP;AC{y9%rOBwc^FGbq;;s78It^t2!JV8+O&Np`m&7$gvZtnC%~lpapI)H~lr%e;4Nqz;_^2PuF002ovPDHLkV1j(6x+VYs literal 0 HcmV?d00001 diff --git a/docs/asset/wbstream-moderator/participants.png b/docs/asset/wbstream-moderator/participants.png new file mode 100644 index 0000000000000000000000000000000000000000..447d4d2dc51bf0d21f39a190a8e480aceffb5c09 GIT binary patch literal 1494 zcmV;{1u6Q8P)E>ilASNxO{SHsJ1~q7zAxi zZJJt4q!nrk8fa@xiys>kOAS-Ch9O89D9W(Sl-+l(9Wn#+wwZa4*?!674fj3Zoc}xb z-gD2pFFY|(H;(`&6ah|900cNe0TAE>1weok6aWEEPyhrt;qU;Vp`nP5UWq8}3TQNu z2n&ngK4DOT+1Xj{GmXi~DcrSMFflQXxw$#GN{Bm)p~%Qc#Kqr-n3z~BCu3uy7%~5g zsi`T*#bp5!bxDYeOMo{qGBS*RhVIDv9ob!g?s{@cDtC;6w?Q{VtJPv~z$7^uWDSB* zQCh6hXLzOaHpn)zk!+QMWC7^Tr=;o?8{9kz*+{mM&08-!O z=Zl~Kl-v6Ye7*=~g0!&l7x;V;6o6KB{sNybyj@^^e%_}NA2G-m@@X-_iVy;vU`Y%r z6A=-Cy?gf{XZN29NJVH1RsCwQFd%X7=4^?7@zrU7XV;IC=6E zx0H>=p68!~lBgyCg*(yRZCrBh&p&RlV_SPWW@cvC_peSjU}$Iv8#X)vB~eX)>6vME z3=dyA?1Y3mh9!k5b-~`=zmb|MUeFNLXfAg@}p`8ZI!9jU- zez~Y7K$oG59ckKIOkqJjJKCm4ih!)FEKaNxbar+^NmLWy+O=QUJimMQE{Ez2MZ}sl z53^@}d3n!p1792yprWFToxgIW14^Ra7%)AJGiSeL$x!7Rud_CdMuYd?dzU$UzNMAj z@e^Nuf%>{yE>m332FzctUx$*YnhCDFSC%R&+JWrsY-pl1xPSF()^^iy6Q3AA#cQvY zBPl6~MGK7q@$vC6o6S%P)gnNzPsJ84eE=b^T?jz!3^qxIOivq;iY9#>F26V&N+C@VXF?c27pzF&3dBV4}xlfyM-FCRc@ zX)*WAe-e$2XYozr8Cb1WE*dJ>xIllSudk0KNbcY)6I4`yefvsKT2jnbfL&b%e17y8 zZru3I>9w1=RJpvoY#{}%tN#p_F8#yKd=V6Ywxan9e7*<@V6{xZU*PkFcMzn}k~Sgw3*^h<8GsOs z04i6}CPZI{eBj$nD!LY+9hkn3kPm_aP{>ezPCGDt6|$Xta2EcAq}AZiok4E(b{D<| z*-W+zAu51PIof{eONkNLN;VUGcb|}451=p_Fx~bE5y(cem24J6k^nXZtyT;AZ})n2 zcOcuyMzWO^fIo zm{`2m#`emLc15(Rugp+->+F>osm`-&-Faok*`}lAM2_P&+$xCJ{^4>9;fmunJW>&| wH$W{h+;Q3-kC((eWtdt7x5**E33vhi106;UHpB65EdT%j07*qoM6N<$f+91%AOHXW literal 0 HcmV?d00001 diff --git a/docs/settings.md b/docs/settings.md index fa9ae72..2a798f4 100644 --- a/docs/settings.md +++ b/docs/settings.md @@ -30,7 +30,7 @@ **Telemost:** only vp8channel passes stably. DataChannel was removed from Telemost. seichannel is not supported. videochannel is slow. -**WBStream:** all transports except datachannel work. DataChannel does not work in the normal guest flow without being granted moderator - WB Stream issues tokens with `canPublishData=false`, and DC does not route data. +**WBStream:** all transports except datachannel work. DataChannel does not work in the normal guest flow without being granted moderator - WB Stream issues tokens with `canPublishData=false`, and DC does not route data. To use `datachannel` over `wbstream`, set `auth.token` to an account/moderator token (`canPublishData=true`); see `auth.token` in the optional fields below. **Jitsi:** datachannel passes stably - it is implemented on top of the colibri-ws bridge channel and sends bytes via an `EndpointMessage{raw}` broadcast. It fits self-hosted and public Jitsi Meet instances without authentication (`https://meet.small-dm.ru/...`, `https://meet1.arbitr.ru/...`, `https://meet.handyweb.org/...`, `https://meet.jit.si/...`, etc.). Check in a browser which of the servers is reachable in your network. Video transports (vp8channel, seichannel, videochannel) expose a sendable VideoTrack through the pion PeerConnection after the Jingle session-accept, but Jicofo requires additional protocol steps (LastN, ReceiverVideoConstraints, source-add) to route video - that is why they are marked `~`. @@ -61,7 +61,7 @@ Speed in descending order: `datachannel` > `vp8channel` > `seichannel` > `videoc | YAML field | Description | |-----------|----------| | `debug` | `true` for verbose connection logs | -| `auth.token` | Pre-issued account token for `wbstream`. When set, the session joins as that account instead of an anonymous guest; empty uses the guest flow. In the guest flow the obtained token is logged once so it can be copied back into this field to keep the same identity | +| `auth.token` | Pre-issued account token for `wbstream`. When set, the session joins as that account instead of an anonymous guest; empty uses the guest flow. In the guest flow the obtained token is logged once so it can be copied back into this field to keep the same identity. Practical effect for `datachannel`: a guest token carries `canPublishData=false`, so the SCTP data channel opens but routes no bytes (the tunnel is up and silent); an account token with moderator rights carries `canPublishData=true` and routes data normally. So `datachannel` over `wbstream` requires an `auth.token` with publish rights; on the guest flow use `vp8channel`, `seichannel` or `videochannel` instead. To grant moderator: open the participants list, then the three dots next to the client/server entry, then the `Moderator` button (needed on both sides) | | `profiles` | List of failover profiles for `srv`/`cnc` | | `failover.retry_delay` | Pause before the next profile, e.g. `2s` | | `failover.max_cycles` | How many full passes over the profiles to make; `0` = unlimited | @@ -197,6 +197,23 @@ For codec `tile` exactly `1080x1080` is required. WB Stream DataChannel **does not work** in the normal guest flow - WB Stream issues tokens with `canPublishData=false`, and DC does not route data. This mode is marked as expected fail in E2E tests. For normal use pick `vp8channel`, `seichannel` or `videochannel`. +To make `datachannel` work you need an account/moderator token in `auth.token` (`canPublishData=true`) on both sides. To grant moderator in the WB Stream UI: open the participants list + +![participants list](asset/wbstream-moderator/participants.png) + +click the three dots next to the client/server entry + +![entry menu](asset/wbstream-moderator/menu.png) + +then press the `Moderator` button + +![moderator button](asset/wbstream-moderator/moderator-button.png) + +> Future work: when joining with a ghost/account token that already holds +> moderator rights, the client could be auto-promoted to moderator so +> `datachannel` works without manual promotion. Not implemented yet; +> moderator is still required on both sides manually. + ```yaml # the room ID must be created manually via https://stream.wb.ru diff --git a/docs/settings.ru.md b/docs/settings.ru.md index 5ccf543..6269d50 100644 --- a/docs/settings.ru.md +++ b/docs/settings.ru.md @@ -30,7 +30,7 @@ **Telemost:** только vp8channel стабильно проходит. DataChannel удалён из Telemost. seichannel не поддерживается. videochannel - медленно. -**WBStream:** все транспорты кроме datachannel работают. DataChannel в обычном guest flow без выдавания модератора не работает - WB Stream выдаёт токены с `canPublishData=false`, и DC не маршрутизирует данные. +**WBStream:** все транспорты кроме datachannel работают. DataChannel в обычном guest flow без выдавания модератора не работает - WB Stream выдаёт токены с `canPublishData=false`, и DC не маршрутизирует данные. Чтобы использовать `datachannel` поверх `wbstream`, задай `auth.token` с токеном аккаунта/модератора (`canPublishData=true`); см. `auth.token` в необязательных полях ниже. **Jitsi:** datachannel стабильно проходит - реализован поверх colibri-ws bridge channel и шлёт байты через `EndpointMessage{raw}` broadcast. Подходит для self-hosted и публичных Jitsi Meet инстансов без аутентификации (`https://meet.small-dm.ru/...`, `https://meet1.arbitr.ru/...`, `https://meet.handyweb.org/...`, `https://meet.jit.si/...` и т.п.). Проверьте в браузере, какой из серверов доступен в вашей сети. Видео-транспорты (vp8channel, seichannel, videochannel) экспонируют sendable VideoTrack через pion PeerConnection после Jingle session-accept, но Jicofo требует дополнительных протокольных шагов (LastN, ReceiverVideoConstraints, source-add) для маршрутизации видео - поэтому они помечены `~` . @@ -61,6 +61,7 @@ | YAML поле | Описание | |-----------|----------| | `debug` | `true` для подробных логов соединений | +| `auth.token` | Заранее выданный токен аккаунта для `wbstream`. Если задан, сессия подключается под этим аккаунтом, а не анонимным гостем; пустое значение использует guest flow. В guest flow полученный токен один раз пишется в лог, чтобы его можно было вставить в это поле и сохранить ту же личность. Практическое следствие для `datachannel`: guest-токен несёт `canPublishData=false`, поэтому SCTP data channel поднимается, но байты не возит (туннель установлен и молчит); токен аккаунта с правами модератора несёт `canPublishData=true` и возит данные нормально. Значит `datachannel` поверх `wbstream` требует `auth.token` с правами на публикацию; в guest flow используй `vp8channel`, `seichannel` или `videochannel`. Как выдать модератора: открой список участников, потом три точки рядом с записью клиента/сервера, потом кнопку `Модератор` (нужно с обеих сторон) | | `profiles` | Список профилей failover для `srv`/`cnc` | | `failover.retry_delay` | Пауза перед следующим профилем, например `2s` | | `failover.max_cycles` | Сколько полных проходов по профилям сделать; `0` = бесконечно | @@ -197,6 +198,23 @@ transport. Используй одинаковые traffic-настройки н WB Stream DataChannel **не работает** в обычном guest flow - WB Stream выдаёт токены с `canPublishData=false`, и DC не маршрутизирует данные. Этот режим помечен как expected fail в E2E тестах. Для обычного использования выбирай `vp8channel`, `seichannel` или `videochannel`. +Чтобы `datachannel` заработал, нужен токен аккаунта/модератора в `auth.token` (`canPublishData=true`) с обеих сторон. Как выдать модератора в UI WB Stream: открой список участников + +![список участников](asset/wbstream-moderator/participants.png) + +нажми три точки рядом с записью клиента/сервера + +![меню записи](asset/wbstream-moderator/menu.png) + +потом нажми кнопку `Модератор` + +![кнопка модератора](asset/wbstream-moderator/moderator-button.png) + +> На будущее: когда подключаемся с ghost/account токеном, у которого уже +> есть права модератора, клиента можно было бы авто-повышать до модератора, +> чтобы `datachannel` работал без ручной выдачи. Пока не реализовано; +> модератор всё ещё нужно выдавать вручную с обеих сторон. + ```yaml # room ID нужно создать вручную через https://stream.wb.ru