The hosted viewer for raptor's WebRTC share feature: viewer.thingino.com/share.html, the page a thingino camera hands out when you share a live stream.
The camera and the viewer never talk to any server of ours. rwd (raptor's WebRTC daemon) and this page meet at public WebTorrent trackers:
- The share key rides in the URL fragment (
share.html#key=…), so it is never sent to the web server, any tracker, or anyone else. - The page derives
info_hash = SHA-256("raptor:" + key)and announces a WebRTC offer under it at the trackers. The SDP is stripped to H264 + Opus first, because public trackers silently drop large messages. - The camera, announcing under the same hash, answers. Media then flows peer-to-peer (STUN-assisted); the trackers only ever see the offer/answer.
- If the camera answers with an audio backchannel, the Talk button appears and the microphone (asked for only then) is sent back over the same connection.
?debug in the URL turns on verbose console logging, including SDP dumps and
periodic RTP stats.
This page lived in the raptor repo as rwd/share.html until it moved here
(last raptor commit touching it:
7f829d5ea341a16e4ead6e43f08bafb24b54b965). rwd still points cameras at it:
its config default is
webtorrent.viewer_url = https://viewer.thingino.com/share.html
so only self-hosters ever need to change anything camera-side. The on-camera
LAN page (rwd/webrtc.html, served by the daemon itself at /webrtc) stays
in raptor; it is a different page for a different network position.
Changes made on the way out of raptor, beyond the split into share.html +
share.js:
- No CDNs, no Google Fonts. Bootstrap, Bootstrap Icons and Montserrat are
vendored, same builds as thingino-verify ships. Opening a share link now
tells nobody but the trackers anything at all, and the page carries a CSP
(
default-src 'self',connect-srcpinned to exactly the two trackers the script dials). - The Bootstrap JS bundle is gone: the page used none of it.
- The theme is the shared thingino/theme
(
web/vendor/thingino-theme.css, updated via that repo'ssync.mjs; the banner line names the exact theme commit). Connect wears.btn-thinginoinstead of Bootstrap's blue. - The family footer line, stamped with the deployed commit.
Every push to main deploys to GitHub Pages via .github/workflows/deploy.yml:
stamp the commit into the footer, gate that the page references only files
that exist and no CDN hosts, publish web/. The custom domain is a repository
setting (Settings > Pages) plus a DNS CNAME for viewer.thingino.com pointing
at thingino.github.io; there is deliberately no CNAME file in the artifact.
No build. Serve web/ with anything static:
python3 -m http.server -d web 8080The footer says v0.1.0-dev locally; the deploy stamps the real commit.
GPL-3.0, inherited with the page from raptor.