Skip to content

TLS ​

Serve the chat server over HTTPS for anything beyond testing on your own machine:

  • The microphone and camera only work on secure pages. The chat window is a page on your chat server, so voice and the webcam need it on https:// (and your site too).
  • Mixed content. An https:// site can't load a script or a frame from an http:// server: the browser blocks the chat entirely.
  • The admin panel's session cookie is marked Secure when PUBLIC_URL starts with https://.

localhost counts as secure, so http://localhost:8800 works for local testing, microphone included. To test on a phone, which can't reach your localhost, you need a real certificate (or a tunnel that gives you an https address).

Getting a certificate ​

The server doesn't handle TLS itself: a reverse proxy in front of it does. The easiest options:

  • Caddy gets and renews Let's Encrypt certificates on its own. See Reverse proxy.
  • nginx with certbot (Let's Encrypt).
  • A CDN or load balancer that terminates TLS (Cloudflare, a cloud load balancer).

Then set PUBLIC_URL=https://chat.example.com and TRUST_PROXY=true, and restart the server.

A separate host name for the chat (chat.example.com) is simplest: it keeps the chat's cookies and storage apart from your main site, and the server needs to be the root of its host anyway.

Wireface Chat 0.1.0. These docs are served by your own server.