(sip) add a sip software simulator to test unified encrypted flow

This commit is contained in:
Thomas Ramé
2026-05-11 17:33:58 +02:00
parent 8bdca048f4
commit 80c9620368
9 changed files with 3809 additions and 2 deletions
+6
View File
@@ -125,10 +125,16 @@ run-summary: ## start only the summary application and all needed services
@$(COMPOSE) up --force-recreate -d celery-summary-summarize
.PHONY: run-summary
run-sip: ## start the SIP gateway and the browser-based softphone (Janus + nginx)
@$(COMPOSE) up --force-recreate -d sip
@$(COMPOSE) up --force-recreate -d sip-web-janus sip-web
.PHONY: run-sip
run:
run: ## start the wsgi (production) and development server
@$(MAKE) run-backend
@$(MAKE) run-summary
@$(MAKE) run-sip
@$(COMPOSE) up --force-recreate -d frontend
.PHONY: run
+55 -2
View File
@@ -168,8 +168,7 @@ services:
- "3000:8080"
dockerize:
image: jwilder/dockerize
platform: linux/x86_64
image: powerman/dockerize:0.19.0
crowdin:
image: crowdin/cli:4.0.0
@@ -246,6 +245,60 @@ services:
depends_on:
- redis
# SIP gateway. Built from the sibling livekit-sip checkout so any dev
# cloning both repos gets a working `docker compose up`. TODO: replace
# the build: block with `image: livekit/sip` once upstream ships an
# image with the team's video bridging.
sip:
build:
context: ../livekit-sip
dockerfile: build/sip/Dockerfile
ports:
- "5060:5060/udp"
- "5060:5060/tcp"
- "10000-10020:10000-10020/udp"
environment:
SIP_CONFIG_BODY: |
api_key: 'devkey'
api_secret: 'secret'
ws_url: 'ws://livekit:7880'
redis:
address: 'redis:6379'
sip_port: 5060
rtp_port: 10000-10020
use_external_ip: false
logging:
level: debug
depends_on:
- livekit
- redis
# Janus WebRTC gateway with the SIP plugin. Bridges a browser SIP demo
# tab to the SIP gateway above. ICE-TCP enabled (janus.jcfg) so media
# works under Lima port-forwarding without vmnet.
sip-web-janus:
build: ./docker/janus
ports:
- "10100-10120:10100-10120/tcp"
volumes:
- ./docker/janus/conf/janus.jcfg:/usr/local/etc/janus/janus.jcfg:ro
- ./docker/janus/conf/janus.transport.http.jcfg:/usr/local/etc/janus/janus.transport.http.jcfg:ro
- ./docker/janus/conf/janus.plugin.sip.jcfg:/usr/local/etc/janus/janus.plugin.sip.jcfg:ro
depends_on:
- sip
# Serves docker/janus/web/{index.html,janus.js} and proxies /janus to
# the Janus container so the demo is single-origin.
sip-web:
image: nginx:alpine
ports:
- "8088:80"
volumes:
- ./docker/janus/web:/usr/share/nginx/html:ro
- ./docker/janus/conf/nginx.conf:/etc/nginx/conf.d/default.conf:ro
depends_on:
- sip-web-janus
redis-summary:
image: redis
ports:
+58
View File
@@ -0,0 +1,58 @@
# Build Janus from source so ICE-TCP support is present (the canyan image
# was compiled against libnice 0.1.16, which lacks the runtime ICE-TCP
# capability Janus 1.1.x feature-detects at startup). Debian 13 ships
# libnice 0.1.21+ which has ICE-TCP. Also: builds natively on arm64, so
# no QEMU emulation overhead.
FROM debian:13-slim AS builder
ARG JANUS_VERSION=v1.1.4
RUN apt-get update && apt-get install -y --no-install-recommends \
build-essential ca-certificates git pkg-config \
autoconf automake libtool gengetopt \
libssl-dev libsrtp2-dev libglib2.0-dev libopus-dev libogg-dev \
libcurl4-openssl-dev libconfig-dev libnice-dev \
libmicrohttpd-dev libjansson-dev libsofia-sip-ua-dev \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
RUN git clone --depth 1 --branch ${JANUS_VERSION} \
https://github.com/meetecho/janus-gateway.git janus
WORKDIR /src/janus
RUN ./autogen.sh && \
./configure \
--prefix=/opt/janus \
--disable-rabbitmq --disable-mqtt --disable-nanomsg --disable-unix-sockets \
--disable-data-channels \
--disable-all-plugins \
--enable-plugin-sip \
--disable-all-handlers \
--disable-all-transports --enable-rest && \
make -j$(nproc) && \
make install && \
make configs
FROM debian:13-slim
# Debian 13 (trixie) renamed several libs in the time_t-64 transition:
# libglib2.0-0t64, libcurl4t64. libconfig9 → libconfig11.
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates libssl3 libsrtp2-1 libglib2.0-0t64 libopus0 libogg0 \
libcurl4t64 libconfig11 libnice10 libmicrohttpd12 libjansson4 \
libsofia-sip-ua0 \
&& rm -rf /var/lib/apt/lists/*
COPY --from=builder /opt/janus /opt/janus
# Make paths match canyan's so the rest of the compose mounts (configs, demos)
# Just-Work without changes. The configs we mount in docker/janus/conf/ assume
# /usr/local/etc/janus and /usr/local/lib/janus.
RUN ln -s /opt/janus/bin/janus /usr/local/bin/janus && \
ln -s /opt/janus/etc/janus /usr/local/etc/janus && \
ln -s /opt/janus/lib/janus /usr/local/lib/janus && \
ln -s /opt/janus/share/janus /usr/local/share/janus
EXPOSE 8088 10100-10120/tcp 10100-10120/udp
CMD ["/usr/local/bin/janus"]
+42
View File
@@ -0,0 +1,42 @@
// Minimal Janus config for browser-↔-SIP demo. Trimmed from the upstream
// sample to the bits we actually need.
general: {
configs_folder = "/usr/local/etc/janus"
plugins_folder = "/usr/local/lib/janus/plugins"
transports_folder = "/usr/local/lib/janus/transports"
events_folder = "/usr/local/lib/janus/events"
log_to_stdout = true
debug_level = 4
server_name = "meet-sip-demo"
}
media: {
// Janus ↔ Browser media (WebRTC over TCP — Lima only forwards TCP).
rtp_port_range = "10100-10120"
ipv6 = false
}
nat: {
// The whole reason this works without vmnet — Janus offers TCP ICE
// candidates the Mac browser can actually connect to.
ice_tcp = true
// libnice quirk: ICE-TCP needs ICE Lite mode on the server side or
// the connectivity check state machine deadlocks. Janus warns about
// this at startup if Lite is off while TCP is on.
ice_lite = true
// Janus advertises this IP in ICE candidates. From the Mac browser's
// perspective, the Janus daemon lives at 127.0.0.1:<port> (Lima
// forwards Mac:127.0.0.1:<port> → VM → docker port-map → container).
nat_1_1_mapping = "127.0.0.1"
keep_private_host = true
}
plugins: {
// Only keep the SIP plugin. Everything else trimmed for boot time.
disable = "libjanus_audiobridge.so,libjanus_videoroom.so,libjanus_streaming.so,libjanus_textroom.so,libjanus_recordplay.so,libjanus_voicemail.so,libjanus_echotest.so,libjanus_videocall.so,libjanus_nosip.so,libjanus_duktape.so,libjanus_lua.so"
}
transports: {
// Only HTTP. WS is overkill for the demo and adds another port.
disable = "libjanus_websockets.so,libjanus_mqtt.so,libjanus_nanomsg.so,libjanus_rabbitmq.so,libjanus_pfunix.so"
}
+8
View File
@@ -0,0 +1,8 @@
// SIP plugin defaults. RTP range for the SIP leg (Janus ↔ livekit/sip)
// is kept separate from WebRTC range — both legs are inside the docker
// bridge network, so any UDP range works.
general: {
local_ip = "0.0.0.0"
rtp_port_range = "20000-20100"
events = true
}
@@ -0,0 +1,24 @@
// HTTP transport: bind 0.0.0.0:8088 inside the container, served to the
// browser through the nginx sidecar that also hosts the demo HTML.
general: {
json = "indented"
base_path = "/janus"
http = true
port = 8088
https = false
mhd_connection_limit = 1020
}
admin: {
admin_base_path = "/admin"
admin_http = false
admin_https = false
}
certificates: {
}
cors: {
// Same-origin via nginx proxy; demo page and API share a host.
# allow_origin = "*"
}
+33
View File
@@ -0,0 +1,33 @@
server {
listen 80;
server_name _;
# Docker's embedded DNS (127.0.0.11). Without this, nginx resolves
# upstreams once at startup and breaks the moment a peer container is
# recreated with a new bridge IP. The `valid=10s` plus a variable in
# proxy_pass forces per-request re-resolution.
resolver 127.0.0.11 valid=10s ipv6=off;
# Serve the Janus demo HTML/JS extracted from the canyan image.
root /usr/share/nginx/html;
index index.html;
# Janus HTTP API — same origin as the demo pages so the default
# settings.js URL ("http://<host>:8088/janus") just works. Regex so
# /janus and /janus/<session>/... proxy, but /janus.js still hits
# the static file root.
location ~ ^/janus(/|$) {
# Variable upstream + the resolver above = re-DNS on each request.
# Plain `proxy_pass http://sip-web-janus:8088` would cache the IP
# for the lifetime of the worker process.
set $janus_upstream sip-web-janus;
proxy_pass http://$janus_upstream:8088;
proxy_http_version 1.1;
proxy_buffering off;
proxy_read_timeout 120s;
}
location / {
try_files $uri $uri/ =404;
}
}
+405
View File
@@ -0,0 +1,405 @@
<!DOCTYPE html>
<!--
Minimal SIP-via-Janus demo. Replaces the upstream siptest.html bundle with
a single self-contained page. Everything is auto-driven: page load creates
the Janus session, attaches to the SIP plugin, registers as guest, places
the call. The user just needs to type the room PIN on the dialpad.
Co-located only with janus.js (vendor lib, ~113KB) — no settings.js, no
navbar/footer, no shared CSS, no logos. nginx serves these two files.
-->
<html lang="en">
<head>
<meta charset="utf-8">
<title>SIP Demo</title>
<style>
* { box-sizing: border-box; }
html, body { margin: 0; padding: 0; height: 100%; background: #1b1b1f; color: #e8e8e8;
font: 14px/1.4 -apple-system, BlinkMacSystemFont, "Segoe UI", sans-serif; }
#app { display: flex; flex-direction: column; height: 100vh; max-width: 720px; margin: 0 auto; padding: 16px; gap: 12px; }
h1 { margin: 0; font-size: 18px; font-weight: 600; }
#status { padding: 8px 12px; border-radius: 6px; background: #2c2c33; font-family: ui-monospace, monospace; font-size: 13px; }
#video-wrap { position: relative; flex: 1; background: #000; border-radius: 8px; overflow: hidden; min-height: 240px; }
#remoteVideo { width: 100%; height: 100%; object-fit: contain; }
#noVideo { position: absolute; inset: 0; display: flex; align-items: center; justify-content: center; color: #555; font-size: 14px; }
.row { display: flex; gap: 8px; flex-wrap: wrap; }
button { font: inherit; padding: 8px 14px; border: 0; border-radius: 6px; background: #4a90e2; color: #fff; cursor: pointer; }
button:hover:not(:disabled) { background: #357ec0; }
button:disabled { opacity: 0.4; cursor: not-allowed; }
button.danger { background: #dc3545; }
button.danger:hover:not(:disabled) { background: #b62733; }
button.success { background: #28a745; }
button.success:hover:not(:disabled) { background: #1f8035; }
.dialpad { display: grid; grid-template-columns: repeat(4, 1fr); gap: 6px; }
.dialpad button { padding: 14px 0; font-size: 16px; background: #3a3a44; }
.dialpad button:hover:not(:disabled) { background: #4a4a55; }
#pin-row input { flex: 1; padding: 8px 12px; border: 1px solid #444; border-radius: 6px; background: #2c2c33; color: #fff; font: inherit; font-family: ui-monospace, monospace; letter-spacing: 0.2em; }
#log { font-family: ui-monospace, monospace; font-size: 11px; max-height: 120px; overflow-y: auto; background: #15151a; padding: 8px; border-radius: 6px; color: #888; }
.log-line { white-space: pre-wrap; word-break: break-word; }
.log-err { color: #ff7373; }
.disabled { opacity: 0.35; pointer-events: none; transition: opacity 0.2s; }
</style>
</head>
<body>
<div id="app">
<h1>SIP demo (browser → Janus → livekit-sip → room)</h1>
<div id="status">Loading…</div>
<div id="video-wrap">
<video id="remoteVideo" autoplay playsinline muted></video>
<audio id="remoteAudio" autoplay></audio>
<div id="noVideo">No remote video yet</div>
</div>
<div id="pin-row" class="row" style="display:none">
<input type="text" id="pin" placeholder="Enter PIN then press # on the pad" inputmode="numeric" pattern="[0-9]*">
<button id="sendPin" class="success">Send PIN</button>
</div>
<div id="dialpad" class="dialpad" style="display:none">
<button data-d="1">1</button><button data-d="2">2</button><button data-d="3">3</button><button data-d="A">A</button>
<button data-d="4">4</button><button data-d="5">5</button><button data-d="6">6</button><button data-d="B">B</button>
<button data-d="7">7</button><button data-d="8">8</button><button data-d="9">9</button><button data-d="C">C</button>
<button data-d="*">*</button><button data-d="0">0</button><button data-d="#">#</button><button data-d="D">D</button>
</div>
<div id="controls" class="row">
<button id="muteBtn" class="danger">🔇 Mic muted</button>
<button id="cameraBtn" class="success">📷 Camera on</button>
<button id="speakerBtn" class="success">🔊 Speaker on</button>
<button id="hangupBtn" class="danger" disabled>Hangup</button>
<button id="rejoinBtn" style="display:none">Re-join</button>
</div>
<details><summary style="cursor:pointer; opacity:0.7; font-size:12px">debug log</summary>
<div id="log"></div>
</details>
</div>
<!-- webrtc-adapter is required by janus.js (cross-browser WebRTC API
normalizer). The upstream siptest pulls it from CDN; we do the same.
Without it Janus.init() silently fails. -->
<script src="https://cdn.jsdelivr.net/npm/webrtc-adapter@9.0.1/out/adapter.min.js"></script>
<script src="janus.js"></script>
<script>
// ============================================================================
// Configuration (hard-coded; this is a dev demo)
// ============================================================================
const JANUS_SERVER = location.origin + "/janus"; // nginx proxies to janus
const SIP_PROXY = "sip:sip:5060"; // docker service name
const SIP_IDENTITY = "sip:demo@example.invalid"; // no registrar, guest
const SIP_PEER = "sip:phone@sip:5060"; // user-part irrelevant
// (Direct+PIN rule)
const DISPLAY_NAME = "test-user";
const ICE_SERVERS = []; // ICE-TCP via janus.jcfg
// ============================================================================
// UI helpers
// ============================================================================
const $ = id => document.getElementById(id);
function setStatus(text) { $("status").textContent = text; log(text); }
function log(msg, isErr = false) {
const line = document.createElement("div");
line.className = "log-line" + (isErr ? " log-err" : "");
line.textContent = "[" + new Date().toLocaleTimeString() + "] " + msg;
$("log").appendChild(line);
$("log").scrollTop = $("log").scrollHeight;
}
// ============================================================================
// Janus state
// ============================================================================
let janus = null;
let sipcall = null;
let inCall = false;
// ============================================================================
// Init: create Janus → session → SIP handle → register → call
// ============================================================================
Janus.init({
debug: false,
callback: () => {
if (!Janus.isWebrtcSupported()) {
setStatus("WebRTC not supported in this browser.");
return;
}
createSession();
}
});
function createSession() {
setStatus("Connecting to Janus…");
janus = new Janus({
server: JANUS_SERVER,
iceServers: ICE_SERVERS,
success: () => {
setStatus("Connected. Attaching SIP plugin…");
attachSip();
},
error: (err) => setStatus("Janus error: " + err),
destroyed: () => setStatus("Janus session destroyed."),
});
}
function attachSip() {
janus.attach({
plugin: "janus.plugin.sip",
opaqueId: "sip-demo-" + Janus.randomString(8),
success: (handle) => {
sipcall = handle;
window.sipcall = handle; // for ad-hoc console debugging
registerAsGuest();
},
error: (err) => setStatus("Plugin attach error: " + err),
onmessage: handleMessage,
onlocaltrack: (track, on) => {
// We don't render local preview — Meet tab is already showing it.
},
onremotetrack: (track, mid, on, meta) => {
if (!on) return;
const stream = new MediaStream([track]);
if (track.kind === "audio") {
$("remoteAudio").srcObject = stream;
} else if (track.kind === "video") {
$("remoteVideo").srcObject = stream;
$("noVideo").style.display = "none";
}
},
oncleanup: () => { setStatus("Call cleaned up."); endCallUi(); },
});
}
function registerAsGuest() {
setStatus("Registering as guest…");
sipcall.send({
message: {
request: "register",
type: "guest",
proxy: SIP_PROXY,
username: SIP_IDENTITY,
display_name: DISPLAY_NAME,
},
});
}
function placeCall() {
setStatus("Calling " + SIP_PEER + "…");
const tracks = [
{ type: "audio", capture: true, recv: true },
{ type: "video", capture: true, recv: true },
];
sipcall.createOffer({
tracks: tracks,
success: (jsep) => {
sipcall.send({
message: { request: "call", uri: SIP_PEER, autoaccept_reinvites: false },
jsep: jsep,
});
},
error: (err) => setStatus("createOffer failed: " + err),
});
}
// ============================================================================
// Plugin event router
// ============================================================================
function handleMessage(msg, jsep) {
const result = msg && msg.result;
const event = result && result.event;
if (event) log("event: " + event);
if (event === "registered") {
setStatus("Registered. Placing call…");
// Small delay to settle the registration
setTimeout(placeCall, 100);
}
else if (event === "calling") {
setStatus("Calling…");
}
else if (event === "accepted") {
setStatus("Call accepted. You should hear the IVR — enter PIN on the dialpad.");
startCallUi();
if (jsep) sipcall.handleRemoteJsep({ jsep: jsep });
}
else if (event === "hangup") {
setStatus("Call ended: " + (result.reason || result.code || ""));
endCallUi();
}
else if (event === "missed_call") {
setStatus("Missed call.");
endCallUi();
}
else if (event === "registration_failed") {
setStatus("Registration failed: " + result.code + " " + result.reason, true);
}
else if (msg && msg.error) {
setStatus("Plugin error: " + msg.error, true);
}
if (jsep && event !== "accepted") {
sipcall.handleRemoteJsep({ jsep: jsep });
}
}
// ============================================================================
// In-call UI: mute, hangup, dialpad, PIN entry
// ============================================================================
function startCallUi() {
inCall = true;
$("pin-row").style.display = "flex";
$("pin-row").classList.remove("disabled");
$("dialpad").style.display = "grid";
$("dialpad").classList.remove("disabled");
$("hangupBtn").disabled = false;
$("rejoinBtn").style.display = "none";
// Auto-mute mic so two tabs on the same Mac don't feedback-howl.
if (sipcall.isAudioMuted && !sipcall.isAudioMuted()) {
sipcall.muteAudio();
}
updateMuteButton();
updateCameraButton();
updateSpeakerButton();
}
function endCallUi() {
inCall = false;
$("pin-row").style.display = "none";
$("pin-row").classList.remove("disabled");
$("dialpad").style.display = "none";
$("dialpad").classList.remove("disabled");
$("hangupBtn").disabled = true;
$("rejoinBtn").style.display = "inline-block";
$("remoteVideo").srcObject = null;
$("remoteAudio").srcObject = null;
$("noVideo").style.display = "flex";
}
function updateMuteButton() {
const b = $("muteBtn");
if (!sipcall || !sipcall.isAudioMuted) return;
if (sipcall.isAudioMuted()) {
b.textContent = "🔇 Mic muted";
b.className = "danger";
} else {
b.textContent = "🎤 Mic on";
b.className = "success";
}
}
function updateCameraButton() {
const b = $("cameraBtn");
if (!sipcall || !sipcall.isVideoMuted) return;
if (sipcall.isVideoMuted()) {
b.textContent = "📷 Camera off";
b.className = "danger";
} else {
b.textContent = "📷 Camera on";
b.className = "success";
}
}
function updateSpeakerButton() {
const b = $("speakerBtn");
const audio = $("remoteAudio");
if (audio.muted) {
b.textContent = "🔇 Speaker off";
b.className = "danger";
} else {
b.textContent = "🔊 Speaker on";
b.className = "success";
}
}
$("muteBtn").addEventListener("click", () => {
if (!sipcall) return;
if (sipcall.isAudioMuted()) sipcall.unmuteAudio();
else sipcall.muteAudio();
setTimeout(updateMuteButton, 50);
});
$("cameraBtn").addEventListener("click", () => {
if (!sipcall || !sipcall.muteVideo) return;
if (sipcall.isVideoMuted()) sipcall.unmuteVideo();
else sipcall.muteVideo();
setTimeout(updateCameraButton, 50);
});
$("speakerBtn").addEventListener("click", () => {
const audio = $("remoteAudio");
audio.muted = !audio.muted;
updateSpeakerButton();
});
$("hangupBtn").addEventListener("click", () => {
if (!sipcall) return;
sipcall.send({ message: { request: "hangup" } });
sipcall.hangup();
});
$("rejoinBtn").addEventListener("click", () => location.reload());
// ============================================================================
// DTMF — try the in-band RTP-event path first (RFC 4733 via the handle's
// dtmf() method), which is what livekit-sip's IVR actually listens for.
// Fall back to SIP INFO if RTP DTMF isn't available (older Janus, no
// telephone-event in SDP, etc.).
// ============================================================================
function sendDtmf(digit) {
if (!sipcall || !inCall) return;
log("DTMF → " + digit);
let sent = false;
try {
if (typeof sipcall.dtmf === "function") {
sipcall.dtmf({
dtmf: { tones: String(digit), duration: 200, gap: 70 },
success: () => {},
error: (err) => log("dtmf() error: " + err, true),
});
sent = true;
}
} catch (e) {
log("dtmf() threw: " + e, true);
}
if (!sent) {
// Fallback: SIP INFO method
sipcall.send({
message: { request: "dtmf_info", digit: String(digit) },
});
}
}
document.querySelectorAll(".dialpad button").forEach(b => {
b.addEventListener("click", () => sendDtmf(b.dataset.d));
});
$("sendPin").addEventListener("click", () => {
const pin = $("pin").value.replace(/[^\d#*]/g, "");
if (!pin) return;
const tones = (pin.endsWith("#") ? pin : pin + "#");
log("DTMF batch → " + tones);
// Send all tones in ONE call. Per-digit looping with setTimeout races
// the WebRTC DTMF sender's internal queue and drops digits (we lost
// the trailing "0" before "#" doing it digit-by-digit). The browser's
// RTCDTMFSender paces them itself given duration/gap.
try {
sipcall.dtmf({
dtmf: { tones: tones, duration: 400, gap: 100 },
success: () => log("DTMF batch sent"),
error: (err) => log("dtmf() error: " + err, true),
});
} catch (e) {
log("dtmf() threw, falling back to SIP INFO per digit: " + e, true);
for (const ch of tones) {
sipcall.send({ message: { request: "dtmf_info", digit: String(ch) } });
}
}
$("pin").value = "";
// PIN + dialpad are no longer needed once you've submitted. Gateway
// either bridges you in (correct PIN) or hangs up with wrong-pin
// (the hangup event re-resets everything via endCallUi).
$("pin-row").classList.add("disabled");
$("dialpad").classList.add("disabled");
});
</script>
</body>
</html>
File diff suppressed because it is too large Load Diff