🐛(backend) allow any string as sub in the API serializer

The API serializer was too restrictive on the `sub` field, expecting
a UUID. This worked in our development and production setups because
our Keycloak is configured to emit UUID subs, but it broke for other
providers.

Per the OIDC spec and the DB model, `sub` can be any string. Align
the serializer with this and accept arbitrary string values.

Fixes #1525.
This commit is contained in:
lebaudantoine
2026-07-27 19:29:42 +02:00
parent 200bcc2655
commit 12eba9dcb8
3 changed files with 6 additions and 5 deletions
+1
View File
@@ -30,6 +30,7 @@ and this project adheres to
- 🐛(summary) extend tasks auto retry logic
- 🐛(summary) properly detect when failure webhook should be sent
- 🐛(backend) preserve recording metadata when updating room access
- 🐛(backend) allow any string as sub in the API serializer
## [1.24.0] - 2026-07-21
+2 -2
View File
@@ -297,8 +297,8 @@ class RoomInviteSerializer(serializers.Serializer):
class BaseParticipantsManagementSerializer(BaseValidationOnlySerializer):
"""Base serializer for participant management operations."""
participant_identity = serializers.UUIDField(
help_text="LiveKit participant identity (UUID format)"
participant_identity = serializers.CharField(
help_text="LiveKit participant identity (matching the user's sub format)"
)
@@ -719,13 +719,13 @@ def test_update_participant_invalid_payload():
)
client.force_authenticate(user=user)
payload = {"participant_identity": "invalid-uuid"}
payload = {"participant_identity": ["test"]}
url = reverse("rooms-update-participant", kwargs={"pk": room.id})
response = client.post(url, payload, format="json")
assert response.status_code == status.HTTP_400_BAD_REQUEST
assert "Must be a valid UUID." in str(response.data)
assert "Not a valid string." in str(response.data)
def test_update_participant_no_update_fields():
@@ -918,7 +918,7 @@ def test_remove_participant_invalid_payload():
)
client.force_authenticate(user=user)
payload = {"participant_identity": "invalid-uuid"}
payload = {"participant_identity": ["invalid-uuid"]}
url = reverse("rooms-remove-participant", kwargs={"pk": room.id})
response = client.post(url, payload, format="json")