Hacker News new | ask | show | jobs
by cookie_monsta 445 days ago
> * Your TURN server should provide APIs that allow you to verify that allocations/permissions are only created for your users.

coturn provides these APIs, they're not covered in the writeup, though

> * Use an auth mechanism that has an expiry time. Like [0]

This is how the credentials server in the write up works