summaryrefslogtreecommitdiffstats
path: root/packages/meshbay-node/src/meshbay_node/transport/__init__.py
blob: e423e35cbb4cd8359bf86697b4d99e8d8d91c7c2 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
"""
MeshBay Node transport layer — WebRTC DataChannel (primary), QUIC (direct/LAN).

Transport decision (2026-08-13, second security review):
  - WebRTC/ICE is the primary path for browser AND native clients. ICE/STUN is the
    only NAT traversal validated on this project (2 ISPs, IPv4 STUN + IPv6, 4G CGNAT).
  - QUIC is kept at parity for LAN, port-forwarded and hub-less `group://` access.
    `punch_nat()` is a direct-connection helper, not a traversal stack.
  - TCP+TLS (`server.py`/`client.py`) and the node HTTP file API (`http_server.py`)
    were REMOVED in Phase 11.5. The HTTP API served private group indexes and
    plaintext files with no authentication on 0.0.0.0 (finding C1); the TCP server
    accepted a bare JWT with no GEK proof (finding C6). Neither is coming back —
    every client path must go through the unified MNP handshake.
"""

# QUIC transport (MNP v2) — requires aioquic>=1.0
try:
    from .quic_server import QuicChunkServer, Denylist
    from .quic_client import QuicChunkClient
    QUIC_AVAILABLE = True
except ImportError:
    QuicChunkServer = None  # type: ignore[assignment,misc]
    QuicChunkClient = None  # type: ignore[assignment,misc]
    Denylist = None  # type: ignore[assignment,misc]
    QUIC_AVAILABLE = False

# WebRTC transport (browsers + native clients) — requires aiortc>=1.9
try:
    from .webrtc_server import WebRTCTransport, WebRTCPeerSession
    WEBRTC_AVAILABLE = True
except ImportError:
    WebRTCTransport = None  # type: ignore[assignment,misc]
    WebRTCPeerSession = None  # type: ignore[assignment,misc]
    WEBRTC_AVAILABLE = False

__all__ = [
    "QuicChunkServer", "QuicChunkClient", "Denylist", "QUIC_AVAILABLE",
    "WebRTCTransport", "WebRTCPeerSession", "WEBRTC_AVAILABLE",
]