I don't know anything about STUN or TURN servers. I saw some credentials in the script.js file. Is it dummy or is it okay to make this public?
There's now support for third-party auth (i.e. oauth). It's not really fool-proof on its own, however you can at least then disable access to those who abuse the system. However, for this to work you need to have an oauth provider i.e. sign-in, which may be non-desirable.
Might just be an example.