- nginx serves the UI over HTTPS on 8090 with a self-signed cert
(browsers require a secure context for microphone access)
- added /token endpoint (tiny Python HTTP server) that signs LiveKit
JWTs server-side, keeping the API secret out of the browser
- app.js now fetches a signed token from /token and uses wss:// when
the page is served over HTTPS
- supervisord runs the token-server as a fourth process