# .stream file as http url for web player

**URL:** <https://community.wowza.com/t/stream-file-as-http-url-for-web-player/41841>\
**Category:** Wowza Streaming Engine\
**Created:** [January 26, 2014, 11:28pm UTC](https://community.wowza.com/t/stream-file-as-http-url-for-web-player/41841 "2014-01-26T23:28:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![iiiyx\_iiiyx](https://avatars.discourse-cdn.com/v4/letter/i/e480ec/32.png) [@iiiyx\_iiiyx](https://community.wowza.com/u/iiiyx_iiiyx)\
**Post date:** [January 26, 2014, 11:28pm UTC](https://community.wowza.com/t/stream-file-as-http-url-for-web-player/41841/1 "2014-01-26T23:28:19Z")

</div>

Hello.

As far as I know, .stream files contain rtsp-path to the video, then we can tell this file to wowza media server, for example (flowplayer):

```auto
clip: {
      live: true,
      url: '5.stream',
      provider: 'rtmp',
    },
plugins: {
      rtmp: {
        url: "/scripts/flowplayer/flowplayer.rtmp-3.2.13.swf",
        netConnectionUrl: 'rtmp://host1/rtplive',
      },

```

So complete path to the clip will be _rtmp://host1/rtplive/5.stream_

5.stream contains this:

```auto
rtsp://some_cam_path

```

So wowza reads content of the file and recieves stream described there. But what if we will tell wowza not just a file name from _content_ directory, but complete http url to some destination which also contains just rtsp-path (just text), it could be even the same 5.stream file - this will give us great opportunity to completely hide real video source from user (security reason and requirement in my project). Particulary, such url will be a path to some php/jsp/what\_ever page which will send back text rtsp-path after making some logic (user authorization/session vars/user cookies), for example it will be _[http://host1/get\_cam\_by\_user\_id.php](http://host1/get_cam_by_user_id.php)_:

```auto
<?php
  if ($_SESSION['user_id'] == 1) {
    echo "rtsp://cam1"
  }
  else {
    echo "rtsp://cam0"
  }
?>

```

flowplayer’s code will be:

```auto
clip: {
      live: true,
      url: '[B]http://host1/get_cam_by_user_id.php[/B]',
      provider: 'rtmp',
    },
plugins: {
      rtmp: {
        url: "/scripts/flowplayer/flowplayer.rtmp-3.2.13.swf",
        netConnectionUrl: 'rtmp://host1/rtplive',
      },

```

Is there any way to make wowza server work like I describe?

Thaks in advance.

---

<div class="post-metadata">

**Author:** ![Matt\_Young](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/matt_young/32/389_2.png) [@Matt\_Young](https://community.wowza.com/u/Matt_Young)\
**Post date:** [January 27, 2014, 10:17am UTC](https://community.wowza.com/t/stream-file-as-http-url-for-web-player/41841/2 "2014-01-27T10:17:29Z")

</div>

I think the best course of action here would be to modify the player such that it does this http query prior to stream resolution. This way the player would get the stream url internally and then play it back. For JWPlayer, you could try [utilizing their existing api](http://www.longtailvideo.com/support/jw-player/28851/javascript-api-reference). However, in doing this, you won’t be really adding much more security other than a thin layer of obfuscation.

---

<div class="post-metadata">

**Author:** ![sal\_jefferson](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@sal\_jefferson](https://community.wowza.com/u/sal_jefferson)\
**Post date:** [January 30, 2014, 2:11pm UTC](https://community.wowza.com/t/stream-file-as-http-url-for-web-player/41841/3 "2014-01-30T14:11:03Z")

</div>

You may wish to hire a consultant to help you with this implementation:

[find a consultant](http://community.wowza.com/c/-/7)

Salvadore

---

<div class="post-metadata">

**Author:** ![iiiyx\_iiiyx](https://avatars.discourse-cdn.com/v4/letter/i/e480ec/32.png) [@iiiyx\_iiiyx](https://community.wowza.com/u/iiiyx_iiiyx)\
**Post date:** [January 27, 2014, 8:33pm UTC](https://community.wowza.com/t/stream-file-as-http-url-for-web-player/41841/4 "2014-01-27T20:33:06Z")

</div>

> … However, in doing this, you won’t be really adding much more security other than a thin layer of obfuscation.

Yes. This is not what I want. I want to make wowza send http query to the host configured to allow queries only from wowza server. There it will recieve rtsp-url based on user id from query. So, user will never know real video source.

I have 10 cams, some users with their own access levels, web-site with Flowplayer/JWPlayer. Some users have access to all cams, others to just few of them. If some user will somehow know the address of restricted cam (see it on his friend’s computer) then he can just modify web page code in debugger to view the video from this cam. This is bad. And I can’t make users enter their login/password each time they start watching another cam, because this is not user friendly.

Maybe there is some possibility to make such functionality by implementing some custom module in IDE. if so, can you direct me to the right path?
