Direct-to-Bunny resumable uploads, encoding webhooks and short-lived signed playback URLs — video never passes through the application servers.
Les fichiers lourds ne traversent jamais les serveurs web.
POST /api/videos/create-upload-sessionSeuls les créateurs vérifiés (registres 18 U.S.C. § 2257) peuvent ouvrir une session.
🎬 Bunny.net Stream Media Pipeline
Orochia is engineered to provide adult-compliant, ultra-fast 4K video streaming with zero server bandwidth overhead by offloading ingest and delivery to Bunny.net Stream.
1. Direct-to-Bunny Tus Resumable Upload Flow
Rather than streaming heavy video files through application server instances, Orochia uses direct-to-edge resumable uploads via the open Tus protocol.
2. Tokenized Playback Security (HMAC-SHA256)
To protect paywalled and private videos against hotlinking, URL scraping, and unauthorized downloading:
- Videos are stored in a Bunny Video Library with Token Authentication Enabled.
- Unsigned direct URLs return HTTP 403 Forbidden at Bunny's edge CDN.
- When an authorized viewer requests a stream, Orochia generates an expiring HMAC-SHA256 token:
$$\text = \text + \text + \text + [\text]$$ $$\text = \text(\text(\text))$$
The player requests:
Bunny edge servers verify the hash before serving .m3u8 manifests and .ts / .m4s video segments.
3. Webhook Transcoding Lifecycle
When Bunny completes encoding:
- Dispatches webhook to
POST /api/webhooks/bunny. - Orochia verifies the HMAC signature header against
BUNNY_WEBHOOK_SECRET. - Updates resolutions list (
2160p,1080p,720p,480p), duration, and thumbnail preview URLs.