Edit history

Earlier versions of Content-Security-Policy when hosting livekit on a different domain than FLUXER_DOMAIN, newest first.

Current version | Edited by Rex
Changes
{"level":"info","time":"2026-06-16T11:10:00.413Z","service":"fluxer-api","env":"production","method":"POST","path":"/internal/rpc","status":200,"durationMs":39,"msg":"Request completed"}`Removed: ### ChecksRemoved: Removed: - ☑ I searched existing issues.Removed: - ☑ I wrote this report in my own words, except for direct translation if needed.Removed:
Show

Content-Security-Policy when hosting livekit on a different domain than FLUXER_DOMAIN

Summary

In my setup i have Fluxer installed on a local server and I forward traffic using netbird to my VPS and expose it using Netbirds reverse proxy feature to the internet. When trying to connect to a voice chat the console throws the error: ` Content-Security-Policy: The page’s settings blocked the loading of a resource (connect-src) at wss://livekit-tcp.mydomain.com:7881/rtc/v1 because it violates the following directive: “connect-src 'self' data: https://*.fluxer.app/ wss://.fluxer.app https://.fluxer.media wss://.fluxer.media https://fluxer-uploads.ewr1.vultrobjects.com/ https://hcaptcha.com/ https://.hcaptcha.com https://fluxerstatus.com/ https://fluxer.media/ http://127.0.0.1:21863/ http://127.0.0.1:21864/ https://chat.mydomain.com/ https://chat.mydomain.com/media%E2%80%9D ` The reason for this issue is that Netbird doesnt allow multiple services of different type (TCP, UDP, HTTPS) exposed on the same subdomain, thus I am forced to put LiveKit's TCP and UDP ports on different subdomains. From my understanding, the fluxer code hardcodes the allowed address for connections to be only the FLUXER_DOMAIN. This is obviously also a Netbird issue but nontheless could be fixed by allowing extra domains via a new environment variable.

Steps to reproduce

  1. Default installation of selfhosted Fluxer
  2. .env with changes:FLUXER_PUBLIC_SCHEME=httpsFLUXER_PUBLIC_PORT=443FLUXER_CADDY_SITE_ADDRESS=:80
  3. livekit.yaml changes:use_external_ip: falsenode_ip: ip_of_netbird_vps
  4. Configured Voice region and voice server in admin panel. Endpoint was set to: wss://livekit-tcp.proxy.mydomain.com:7881. Other domain combinations (with and without port, direct ip adress of vps, just mydomain.com etc.) were all tried with no success.
  5. Netbird reverse proxy exposes fluxer http service under subdomain chat.mydomain.com and 7881/tcp and 7882/udp are exposed under livekit-tcp.mydomain.com and livekit-udp.mydomain.com respectivly

Environment

OS: Ubuntu 26.04 LXC on Proxmox Browser: Zen Browser (Firefox) Device: Windows 11

Logs or screenshots

`{"level":"info","time":"2026-06-16T11:09:29.811Z","service":"fluxer-api","env":"production","method":"POST","path":"/internal/rpc","status":200,"durationMs":14,"msg":"Request completed"} {"level":"info","time":"2026-06-16T11:09:59.869Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"} {"level":"error","time":"2026-06-16T11:10:00.413Z","service":"fluxer-api","env":"production","error":{"type":"TypeError","message":"fetch failed: connect ECONNREFUSED vps_ip_address:7881","stack":"TypeError: fetch failed\ncaused by: Error: connect ECONNREFUSED vps_ip_address:7881\n at TCPConnectWrap.afterConnect [as oncomplete] (node:net:1705:16)"},"msg":"Error disconnecting LiveKit participant"} {"level":"info","time":"2026-06-16T11:10:00.413Z","service":"fluxer-api","env":"production","method":"POST","path":"/internal/rpc","status":200,"durationMs":39,"msg":"Request completed"}`
Original by Rex
Show

Content-Security-Policy when hosting livekit on a different domain than FLUXER_DOMAIN

Summary

In my setup i have Fluxer installed on a local server and I forward traffic using netbird to my VPS and expose it using Netbirds reverse proxy feature to the internet. When trying to connect to a voice chat the console throws the error: ` Content-Security-Policy: The page’s settings blocked the loading of a resource (connect-src) at wss://livekit-tcp.mydomain.com:7881/rtc/v1 because it violates the following directive: “connect-src 'self' data: https://*.fluxer.app/ wss://.fluxer.app https://.fluxer.media wss://.fluxer.media https://fluxer-uploads.ewr1.vultrobjects.com/ https://hcaptcha.com/ https://.hcaptcha.com https://fluxerstatus.com/ https://fluxer.media/ http://127.0.0.1:21863/ http://127.0.0.1:21864/ https://chat.mydomain.com/ https://chat.mydomain.com/media%E2%80%9D ` The reason for this issue is that Netbird doesnt allow multiple services of different type (TCP, UDP, HTTPS) exposed on the same subdomain, thus I am forced to put LiveKit's TCP and UDP ports on different subdomains. From my understanding, the fluxer code hardcodes the allowed address for connections to be only the FLUXER_DOMAIN. This is obviously also a Netbird issue but nontheless could be fixed by allowing extra domains via a new environment variable.

Steps to reproduce

  1. Default installation of selfhosted Fluxer
  2. .env with changes:FLUXER_PUBLIC_SCHEME=httpsFLUXER_PUBLIC_PORT=443FLUXER_CADDY_SITE_ADDRESS=:80
  3. livekit.yaml changes:use_external_ip: falsenode_ip: ip_of_netbird_vps
  4. Configured Voice region and voice server in admin panel. Endpoint was set to: wss://livekit-tcp.proxy.mydomain.com:7881. Other domain combinations (with and without port, direct ip adress of vps, just mydomain.com etc.) were all tried with no success.
  5. Netbird reverse proxy exposes fluxer http service under subdomain chat.mydomain.com and 7881/tcp and 7882/udp are exposed under livekit-tcp.mydomain.com and livekit-udp.mydomain.com respectivly

Environment

OS: Ubuntu 26.04 LXC on Proxmox Browser: Zen Browser (Firefox) Device: Windows 11

Logs or screenshots

`{"level":"info","time":"2026-06-16T11:09:29.811Z","service":"fluxer-api","env":"production","method":"POST","path":"/internal/rpc","status":200,"durationMs":14,"msg":"Request completed"} {"level":"info","time":"2026-06-16T11:09:59.869Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"} {"level":"error","time":"2026-06-16T11:10:00.413Z","service":"fluxer-api","env":"production","error":{"type":"TypeError","message":"fetch failed: connect ECONNREFUSED vps_ip_address:7881","stack":"TypeError: fetch failed\ncaused by: Error: connect ECONNREFUSED vps_ip_address:7881\n at TCPConnectWrap.afterConnect [as oncomplete] (node:net:1705:16)"},"msg":"Error disconnecting LiveKit participant"} {"level":"info","time":"2026-06-16T11:10:00.413Z","service":"fluxer-api","env":"production","method":"POST","path":"/internal/rpc","status":200,"durationMs":39,"msg":"Request completed"}`

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.