Farsight Feeds

Webcam Proxy

SSRF-guarded passthrough for public camera streams, with HLS playlist rewriting.

GET /webcam/proxy?url=… is a narrow passthrough the adapter performs on behalf of map clients. It exists because many public camera streams ship HLS playlists with absolute URLs to mixed-content origins — fine for the adapter to reach, problematic for an HTTPS browser session.

Behaviour

  1. Validate url is absolute and on the proxy host allowlist.
  2. Fetch the upstream resource through the adapter's HTTP client (10 s timeout).
  3. Stream the response back to the client, preserving Content-Type.
  4. If the response is an HLS playlist (.m3u8, application/vnd.apple.mpegurl), rewrite every segment URI to also flow through /webcam/proxy?url=… so the browser never has to leave the HTTPS adapter origin.

Route

MethodPathPurpose
GET/webcam/proxy?url=Proxy and rewrite.

Responses

StatusMeaning
200Proxied content (HLS playlists rewritten).
400Missing or malformed url.
403Host not on the proxy allowlist.
504Upstream timed out.

Allowlist

The allowlist is maintained server-side; submit additions via the operator catalog rather than as ad-hoc query params. The point of the gate is to keep the adapter from being used as a generic open relay.

Status

Live on the deployed system. Pairs with the webcams static layer (GET /layers/webcams) which carries the catalog of known camera locations and their stream URLs.

On this page