mirror of
https://github.com/suitenumerique/meet.git
synced 2026-08-05 16:37:43 +00:00
🔒️(backend) rely on backend to allow participant update their metadata
Introduce toggle-hand and rename endpoints in RoomViewSet, secured with LiveKit token authentication. Remove direct permission for clients to update their own metadata via LiveKit tokens to prevent spoofing (e.g. faking admin status). Proxy participant metadata updates through the backend to enforce proper validation and authorization. Signed-off-by: lebaudantoine <lebaud.antoine131@gmail.com>
This commit is contained in:
@@ -526,3 +526,15 @@ class CreateFileSerializer(ListFileSerializer):
|
||||
|
||||
def update(self, instance, validated_data):
|
||||
raise NotImplementedError("Update method can not be used.")
|
||||
|
||||
|
||||
class RaiseHandSerializer(BaseValidationOnlySerializer):
|
||||
"""Serializer for raising or lowering a participant's hand in a room."""
|
||||
|
||||
raised = serializers.BooleanField()
|
||||
|
||||
|
||||
class RenameParticipantSerializer(BaseValidationOnlySerializer):
|
||||
"""Serializer for renaming a participant in a room."""
|
||||
|
||||
name = serializers.CharField(min_length=1, max_length=255, allow_blank=False)
|
||||
|
||||
@@ -10,6 +10,7 @@ from django.core.files.storage import default_storage
|
||||
from django.db.models import Q
|
||||
from django.http import Http404
|
||||
from django.shortcuts import get_object_or_404
|
||||
from django.utils import timezone
|
||||
from django.utils.text import slugify
|
||||
from django.utils.translation import gettext_lazy as _
|
||||
|
||||
@@ -678,6 +679,82 @@ class RoomViewSet(
|
||||
{"status": "success"}, status=drf_status.HTTP_200_OK
|
||||
)
|
||||
|
||||
@decorators.action(
|
||||
detail=True,
|
||||
methods=["post"],
|
||||
url_path="toggle-hand",
|
||||
url_name="toggle-hand",
|
||||
permission_classes=[permissions.HasLiveKitRoomAccess],
|
||||
authentication_classes=[LiveKitTokenAuthentication],
|
||||
)
|
||||
def toggle_hand(self, request, pk=None): # pylint: disable=unused-argument
|
||||
"""Raise or lower the current participant's hand in the room."""
|
||||
room = self.get_object()
|
||||
|
||||
serializer = serializers.RaiseHandSerializer(data=request.data)
|
||||
serializer.is_valid(raise_exception=True)
|
||||
|
||||
identity = request.auth.identity
|
||||
|
||||
# LiveKit uses the handRaisedAt participant attribute to signal hand state.
|
||||
# An empty string means the hand is lowered; a non-empty ISO 8601 timestamp
|
||||
# means the hand is raised. The timestamp is used by clients to determine
|
||||
# the order in which participants raised their hands.
|
||||
hand_raised_at = (
|
||||
timezone.now().isoformat() if serializer.validated_data["raised"] else ""
|
||||
)
|
||||
|
||||
try:
|
||||
ParticipantsManagement().update(
|
||||
room_name=str(room.pk),
|
||||
identity=identity,
|
||||
attributes={"handRaisedAt": hand_raised_at},
|
||||
)
|
||||
except ParticipantsManagementException:
|
||||
return drf_response.Response(
|
||||
{"error": "Failed to update participant hand state"},
|
||||
status=drf_status.HTTP_500_INTERNAL_SERVER_ERROR,
|
||||
)
|
||||
|
||||
return drf_response.Response(
|
||||
{"status": "success"},
|
||||
status=drf_status.HTTP_200_OK,
|
||||
)
|
||||
|
||||
@decorators.action(
|
||||
detail=True,
|
||||
methods=["post"],
|
||||
url_path="rename",
|
||||
url_name="rename",
|
||||
permission_classes=[permissions.HasLiveKitRoomAccess],
|
||||
authentication_classes=[LiveKitTokenAuthentication],
|
||||
)
|
||||
def rename(self, request, pk=None): # pylint: disable=unused-argument
|
||||
"""Rename the current participant in the room."""
|
||||
room = self.get_object()
|
||||
|
||||
serializer = serializers.RenameParticipantSerializer(data=request.data)
|
||||
serializer.is_valid(raise_exception=True)
|
||||
|
||||
identity = request.auth.identity
|
||||
|
||||
try:
|
||||
ParticipantsManagement().update(
|
||||
room_name=str(room.pk),
|
||||
identity=identity,
|
||||
name=serializer.validated_data["name"],
|
||||
)
|
||||
except ParticipantsManagementException:
|
||||
return drf_response.Response(
|
||||
{"error": "Failed to rename participant"},
|
||||
status=drf_status.HTTP_500_INTERNAL_SERVER_ERROR,
|
||||
)
|
||||
|
||||
return drf_response.Response(
|
||||
{"status": "success"},
|
||||
status=drf_status.HTTP_200_OK,
|
||||
)
|
||||
|
||||
|
||||
class ResourceAccessViewSet(
|
||||
mixins.CreateModelMixin,
|
||||
|
||||
Reference in New Issue
Block a user