1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
|
"""
MeshBay Node transport layer — WebRTC DataChannel (primary), QUIC (direct/LAN).
Transport decision (2026-08-13, second security review):
- WebRTC/ICE is the primary path for browser AND native clients. ICE/STUN is the
only NAT traversal validated on this project (2 ISPs, IPv4 STUN + IPv6, 4G CGNAT).
- QUIC is kept at parity for LAN, port-forwarded and hub-less `group://` access.
`punch_nat()` is a direct-connection helper, not a traversal stack.
- TCP+TLS (`server.py`/`client.py`) and the node HTTP file API (`http_server.py`)
were REMOVED in Phase 11.5. The HTTP API served private group indexes and
plaintext files with no authentication on 0.0.0.0 (finding C1); the TCP server
accepted a bare JWT with no GEK proof (finding C6). Neither is coming back —
every client path must go through the unified MNP handshake.
"""
# QUIC transport (MNP v2) — requires aioquic>=1.0
try:
from .quic_server import QuicChunkServer, Denylist
from .quic_client import QuicChunkClient
QUIC_AVAILABLE = True
except ImportError:
QuicChunkServer = None # type: ignore[assignment,misc]
QuicChunkClient = None # type: ignore[assignment,misc]
Denylist = None # type: ignore[assignment,misc]
QUIC_AVAILABLE = False
# WebRTC transport (browsers + native clients) — requires aiortc>=1.9
try:
from .webrtc_server import WebRTCTransport, WebRTCPeerSession
WEBRTC_AVAILABLE = True
except ImportError:
WebRTCTransport = None # type: ignore[assignment,misc]
WebRTCPeerSession = None # type: ignore[assignment,misc]
WEBRTC_AVAILABLE = False
__all__ = [
"QuicChunkServer", "QuicChunkClient", "Denylist", "QUIC_AVAILABLE",
"WebRTCTransport", "WebRTCPeerSession", "WEBRTC_AVAILABLE",
]
|