Description: Avoid privacy breach of hardcoded default STUN server Author: Jonas Smedegaard Bug-Debian: https://bugs.debian.org/867293 Last-Update: 2018-05-07 --- This patch header follows DEP-3: http://dep.debian.net/deps/dep3/ --- a/html/janus.js +++ b/html/janus.js @@ -588,7 +588,9 @@ Janus.log("Using REST API to contact Janus: " + server); } } - let iceServers = gatewayCallbacks.iceServers || [{urls: "stun:stun.l.google.com:19302"}]; ++ let iceServers = gatewayCallbacks.iceServers; ++ if(iceServers === undefined || iceServers === null) ++ Janus.error("Error: No iceServers defined"); let iceTransportPolicy = gatewayCallbacks.iceTransportPolicy; let bundlePolicy = gatewayCallbacks.bundlePolicy; // Whether we should enable the withCredentials flag for XHR requests