Webcam Proxy
SSRF-guarded passthrough for public camera streams, with HLS playlist rewriting.
GET /webcam/proxy?url=… is a narrow passthrough the adapter performs on
behalf of map clients. It exists because many public camera streams ship
HLS playlists with absolute URLs to mixed-content origins — fine for the
adapter to reach, problematic for an HTTPS browser session.
Behaviour
- Validate
urlis absolute and on the proxy host allowlist. - Fetch the upstream resource through the adapter's HTTP client (10 s timeout).
- Stream the response back to the client, preserving
Content-Type. - If the response is an HLS playlist (
.m3u8,application/vnd.apple.mpegurl), rewrite every segment URI to also flow through/webcam/proxy?url=…so the browser never has to leave the HTTPS adapter origin.
Route
| Method | Path | Purpose |
|---|---|---|
GET | /webcam/proxy?url= | Proxy and rewrite. |
Responses
| Status | Meaning |
|---|---|
200 | Proxied content (HLS playlists rewritten). |
400 | Missing or malformed url. |
403 | Host not on the proxy allowlist. |
504 | Upstream timed out. |
Allowlist
The allowlist is maintained server-side; submit additions via the operator catalog rather than as ad-hoc query params. The point of the gate is to keep the adapter from being used as a generic open relay.
Status
Live on the deployed system. Pairs with the webcams static layer
(GET /layers/webcams) which carries the catalog of known camera locations
and their stream URLs.