mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-04 04:42:57 +00:00
Compare commits
10 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9187173cae | |||
| 364bbf4f0b | |||
| a6a12ef586 | |||
| 2622d89f63 | |||
| f2d50770cf | |||
| 11e8470aa5 | |||
| 3bf78f0f5b | |||
| ddd5e3fce1 | |||
| 5a9e1cb012 | |||
| c49cee3ab4 |
+12
-1
@@ -12,6 +12,14 @@ and this project adheres to
|
||||
|
||||
- 🔒(backend) throttle meeting link generation
|
||||
- 🔒️(backend) add a daily cap on room creation
|
||||
- 🔧(summary) add setting to control Sentry traces sampling rate
|
||||
- ✨(frontend) let signed-out visitors start a meeting
|
||||
- ✨(backend) expose `allow_unregistered_rooms` in the frontend configuration
|
||||
|
||||
### Changed
|
||||
|
||||
- ✨(frontend) warn users when the connection falls back to TURN
|
||||
- 🔧(backend) configure the technical documentation url
|
||||
|
||||
### Fixed
|
||||
|
||||
@@ -19,6 +27,10 @@ and this project adheres to
|
||||
- 🔒️(agents) fix util-linux CVEs reported by Cyberwatch
|
||||
- 🔒️(backend) fix HIGH CVEs in Django and urllib3
|
||||
- 🔒️(agents) upgrade libpcre2-8-0 to fix CVE-2026-103111
|
||||
- 🔒️(frontend) upgrade pcre2 to fix CVE-2026-103111
|
||||
- 🐛(summary) disable default S3 checksums for GCS-compatible storage
|
||||
- 🔒️(summary) redact meeting content from Sentry events
|
||||
- 🐛(frontend) hide tooltips until they have a computed placement
|
||||
|
||||
## [1.33.0] - 2026-09-30
|
||||
|
||||
@@ -149,7 +161,6 @@ and this project adheres to
|
||||
### Added
|
||||
|
||||
- ✨(any) let any authenticated user manage the lobby on trusted rooms
|
||||
|
||||
### Changed
|
||||
|
||||
- 📱(frontend) collapse mobile control bar items on narrow viewports
|
||||
|
||||
@@ -153,6 +153,7 @@ services:
|
||||
target: frontend-production
|
||||
args:
|
||||
VITE_API_BASE_URL: "http://localhost:8071"
|
||||
VITE_MEDIA_BASE_URL: "http://localhost:8083"
|
||||
VITE_APP_TITLE: "LaSuite Meet"
|
||||
image: meet:frontend-development
|
||||
ports:
|
||||
|
||||
@@ -58,6 +58,7 @@ FROM nginxinc/nginx-unprivileged:1.30.4-alpine3.24 AS frontend-production
|
||||
|
||||
USER root
|
||||
RUN apk upgrade --no-cache libexpat && \
|
||||
apk add --no-cache --upgrade 'pcre2>=10.49-r0' && \
|
||||
apk del curl
|
||||
USER nginx
|
||||
|
||||
|
||||
@@ -4,6 +4,36 @@ server {
|
||||
server_name localhost;
|
||||
charset utf-8;
|
||||
|
||||
# Proxy auth for recordings (authorized by the recordings viewset)
|
||||
location /media/recordings/ {
|
||||
auth_request /media-auth-recordings;
|
||||
auth_request_set $authHeader $upstream_http_authorization;
|
||||
auth_request_set $authDate $upstream_http_x_amz_date;
|
||||
auth_request_set $authContentSha256 $upstream_http_x_amz_content_sha256;
|
||||
|
||||
proxy_set_header Authorization $authHeader;
|
||||
proxy_set_header X-Amz-Date $authDate;
|
||||
proxy_set_header X-Amz-Content-SHA256 $authContentSha256;
|
||||
|
||||
proxy_pass http://garage:9000/meet-media-storage/recordings/;
|
||||
proxy_set_header Host garage:9000;
|
||||
proxy_hide_header Content-Disposition;
|
||||
add_header Content-Disposition "attachment";
|
||||
}
|
||||
|
||||
location = /media-auth-recordings {
|
||||
internal;
|
||||
proxy_pass http://app-dev:8000/api/v1.0/recordings/media-auth/;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Original-URL $request_uri;
|
||||
|
||||
proxy_pass_request_body off;
|
||||
proxy_set_header Content-Length "";
|
||||
proxy_set_header X-Original-Method $request_method;
|
||||
}
|
||||
|
||||
# Proxy auth for media
|
||||
location /media/ {
|
||||
# Auth request configuration
|
||||
|
||||
@@ -347,6 +347,7 @@ These are the environmental options available on meet backend.
|
||||
| FRONTEND_IS_SILENT_LOGIN_ENABLED | Enable silent login feature | true |
|
||||
| FRONTEND_FEEDBACK | Frontend feedback configuration | {} |
|
||||
| FRONTEND_DOCUMENTATION_URL | URL of the documentation opened from the room options menu. If unset, the documentation menu item is hidden | |
|
||||
| FRONTEND_TECHNICAL_DOCUMENTATION_URL | URL of the technical documentation (network prerequisites) linked from the footer and the connection test. If unset, both links are hidden | |
|
||||
| FRONTEND_USE_FRENCH_GOV_FOOTER | Show the French government footer in the homepage | false |
|
||||
| FRONTEND_USE_PROCONNECT_BUTTON | Show a "Login with ProConnect" button in the homepage instead of a "Login" button | false |
|
||||
| DJANGO_EMAIL_BACKEND | Email backend library | django.core.mail.backends.smtp.EmailBackend |
|
||||
|
||||
@@ -88,7 +88,7 @@ RECORDING_DOWNLOAD_BASE_URL=http://localhost:3000/recording
|
||||
# RECORDING_ENCODING_DEFAULT_RESOLUTION=720p
|
||||
# RECORDING_ENCODING_DEFAULT_PROFILE=full
|
||||
|
||||
# Default encoding values independant of resolution/profile
|
||||
# Default encoding values independent of resolution/profile
|
||||
# RECORDING_ENCODING_AUDIO_BITRATE_KBPS=128
|
||||
# RECORDING_ENCODING_KEY_FRAME_INTERVAL_S=4.0
|
||||
|
||||
|
||||
@@ -73,6 +73,7 @@ def get_frontend_configuration(request):
|
||||
"default_sources": settings.LIVEKIT_DEFAULT_SOURCES,
|
||||
"default_video_codec": settings.LIVEKIT_DEFAULT_VIDEO_CODEC,
|
||||
},
|
||||
"allow_unregistered_rooms": settings.ALLOW_UNREGISTERED_ROOMS,
|
||||
"authenticated_users_can_edit_display_name": (
|
||||
settings.AUTHENTICATED_PARTICIPANTS_CAN_EDIT_DISPLAY_NAME
|
||||
),
|
||||
|
||||
@@ -466,6 +466,11 @@ class Base(Configuration):
|
||||
"documentation_url": values.Value(
|
||||
None, environ_name="FRONTEND_DOCUMENTATION_URL", environ_prefix=None
|
||||
),
|
||||
"technical_documentation_url": values.Value(
|
||||
None,
|
||||
environ_name="FRONTEND_TECHNICAL_DOCUMENTATION_URL",
|
||||
environ_prefix=None,
|
||||
),
|
||||
"external_home_url": values.Value(
|
||||
None, environ_name="FRONTEND_EXTERNAL_HOME_URL", environ_prefix=None
|
||||
),
|
||||
|
||||
@@ -39,6 +39,9 @@ ENV VITE_API_BASE_URL=${VITE_API_BASE_URL}
|
||||
ARG VITE_APP_TITLE
|
||||
ENV VITE_APP_TITLE=${VITE_APP_TITLE}
|
||||
|
||||
ARG VITE_MEDIA_BASE_URL
|
||||
ENV VITE_MEDIA_BASE_URL=${VITE_MEDIA_BASE_URL}
|
||||
|
||||
RUN npm run build
|
||||
|
||||
# ---- Front-end image ----
|
||||
@@ -46,6 +49,7 @@ FROM nginxinc/nginx-unprivileged:1.30.4-alpine3.24 AS frontend-production
|
||||
|
||||
USER root
|
||||
RUN apk upgrade --no-cache libexpat && \
|
||||
apk add --no-cache --upgrade 'pcre2>=10.49-r0' && \
|
||||
apk del curl
|
||||
USER nginx
|
||||
|
||||
|
||||
Generated
+33
-32
@@ -31,11 +31,11 @@
|
||||
"livekit-client": "2.21.0",
|
||||
"posthog-js": "1.418.10",
|
||||
"react": "18.3.1",
|
||||
"react-aria": "3.50.0",
|
||||
"react-aria-components": "1.19.0",
|
||||
"react-aria": "3.51.0",
|
||||
"react-aria-components": "1.20.0",
|
||||
"react-dom": "18.3.1",
|
||||
"react-i18next": "17.0.12",
|
||||
"react-stately": "3.48.0",
|
||||
"react-stately": "3.49.0",
|
||||
"use-sound": "5.0.0",
|
||||
"valtio": "2.3.2",
|
||||
"wouter": "3.10.0"
|
||||
@@ -883,9 +883,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@internationalized/date": {
|
||||
"version": "3.12.2",
|
||||
"resolved": "https://registry.npmjs.org/@internationalized/date/-/date-3.12.2.tgz",
|
||||
"integrity": "sha512-FY1Y+H64NDs+HAF6omlnWxm3mEpfgaCSWtL5l551ZZfImA+kGjPFgrnJrGjH6lfmLL0g8Z/mBu1R3kufeCp6Jw==",
|
||||
"version": "3.12.3",
|
||||
"resolved": "https://registry.npmjs.org/@internationalized/date/-/date-3.12.3.tgz",
|
||||
"integrity": "sha512-fuLX+3ZKLsxI73y8b01EG/WjHb6gE6weCqlfawPO27kBWGMh9G1yH6Csv1uU7/cac9H2GHmOMt6CjmuQ1aia4Q==",
|
||||
"license": "Apache-2.0",
|
||||
"dependencies": {
|
||||
"@swc/helpers": "^0.5.0"
|
||||
@@ -901,9 +901,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@internationalized/string": {
|
||||
"version": "3.2.9",
|
||||
"resolved": "https://registry.npmjs.org/@internationalized/string/-/string-3.2.9.tgz",
|
||||
"integrity": "sha512-kzP/M/mbQxODlmOt4bIQZ2SBVUWUSqMLXooXixnX7noche8WHaQcA+nwFN1K2KCF/cp+LDUhcJsCicwkvhD1pg==",
|
||||
"version": "3.2.10",
|
||||
"resolved": "https://registry.npmjs.org/@internationalized/string/-/string-3.2.10.tgz",
|
||||
"integrity": "sha512-PDx6//vHSpRnHfxqMqto11zQvhsaU74O3mKv2F/0eicGZcl9NLjQmGlbHz/LsJh5tLKp4A4L7ZVTzN1/MmMTvA==",
|
||||
"license": "Apache-2.0",
|
||||
"dependencies": {
|
||||
"@swc/helpers": "^0.5.0"
|
||||
@@ -1819,9 +1819,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@react-types/shared": {
|
||||
"version": "3.36.0",
|
||||
"resolved": "https://registry.npmjs.org/@react-types/shared/-/shared-3.36.0.tgz",
|
||||
"integrity": "sha512-DkP/H0C2YjjS7gZWKNqOmU8a16qHPjQNdzMwmTq9SzplM6Iw0kVMTZ0OIoe6FOgGqa+FwMsE2QbPjh/n3g/jXQ==",
|
||||
"version": "3.36.1",
|
||||
"resolved": "https://registry.npmjs.org/@react-types/shared/-/shared-3.36.1.tgz",
|
||||
"integrity": "sha512-AzsuD9OfxTOZMMvTRhlN3oHBwOmFN7tDh27LzqmHt4+uOgPhJT7ZM7/kVs/8/o0WxayMUIk3hBmCFRHv1FUoag==",
|
||||
"license": "Apache-2.0",
|
||||
"peerDependencies": {
|
||||
"react": "^16.8.0 || ^17.0.0-rc.1 || ^18.0.0 || ^19.0.0-rc.1"
|
||||
@@ -9384,19 +9384,19 @@
|
||||
}
|
||||
},
|
||||
"node_modules/react-aria": {
|
||||
"version": "3.50.0",
|
||||
"resolved": "https://registry.npmjs.org/react-aria/-/react-aria-3.50.0.tgz",
|
||||
"integrity": "sha512-S0Os6QZk33fzUAKu1QLT9afoUaCBt1ZNdoiq0n2YMVgKIdNIQS8zxiZ8O9hYE6QyDkHKjD6q39LQZ+qaSAIgjw==",
|
||||
"version": "3.51.0",
|
||||
"resolved": "https://registry.npmjs.org/react-aria/-/react-aria-3.51.0.tgz",
|
||||
"integrity": "sha512-AyWLw0XR38cFPwBu/ErgGaVrc5dupLEKmRlMXTGvFKOtbaGRQ2+yQJkjVhpdHhoRhU4+G+tJDFeHDTS8tK3bfQ==",
|
||||
"license": "Apache-2.0",
|
||||
"dependencies": {
|
||||
"@internationalized/date": "^3.12.2",
|
||||
"@internationalized/date": "^3.12.3",
|
||||
"@internationalized/number": "^3.6.7",
|
||||
"@internationalized/string": "^3.2.9",
|
||||
"@react-types/shared": "^3.36.0",
|
||||
"@internationalized/string": "^3.2.10",
|
||||
"@react-types/shared": "^3.36.1",
|
||||
"@swc/helpers": "^0.5.0",
|
||||
"aria-hidden": "^1.2.3",
|
||||
"clsx": "^2.0.0",
|
||||
"react-stately": "3.48.0",
|
||||
"react-stately": "3.49.0",
|
||||
"use-sync-external-store": "^1.6.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
@@ -9405,17 +9405,18 @@
|
||||
}
|
||||
},
|
||||
"node_modules/react-aria-components": {
|
||||
"version": "1.19.0",
|
||||
"resolved": "https://registry.npmjs.org/react-aria-components/-/react-aria-components-1.19.0.tgz",
|
||||
"integrity": "sha512-2smSS5nqJ8cGYMQezuUXveZm7eMyHCqTN6mDpylQBYLYbdF5dxCCuW1DHn1VKLe1DybSfPvX/cZtJlDmvFfn8A==",
|
||||
"version": "1.20.0",
|
||||
"resolved": "https://registry.npmjs.org/react-aria-components/-/react-aria-components-1.20.0.tgz",
|
||||
"integrity": "sha512-BMbpIgoV9aELeBrB0Y120NgoigHb5OdcJwc+4e7uSnbTbamea6lo+gqcc4LAxzMaK3Jf+7LI1oCDE6yANsmxIQ==",
|
||||
"license": "Apache-2.0",
|
||||
"dependencies": {
|
||||
"@internationalized/date": "^3.12.2",
|
||||
"@react-types/shared": "^3.36.0",
|
||||
"@internationalized/date": "^3.12.3",
|
||||
"@internationalized/string": "^3.2.10",
|
||||
"@react-types/shared": "^3.36.1",
|
||||
"@swc/helpers": "^0.5.0",
|
||||
"client-only": "^0.0.1",
|
||||
"react-aria": "3.50.0",
|
||||
"react-stately": "3.48.0"
|
||||
"react-aria": "3.51.0",
|
||||
"react-stately": "3.49.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"react": "^16.8.0 || ^17.0.0-rc.1 || ^18.0.0 || ^19.0.0-rc.1",
|
||||
@@ -9469,15 +9470,15 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/react-stately": {
|
||||
"version": "3.48.0",
|
||||
"resolved": "https://registry.npmjs.org/react-stately/-/react-stately-3.48.0.tgz",
|
||||
"integrity": "sha512-ImicSAG+lTotAe5izcs1fz49Zk48w7pDusqYg04WaPhCoej8BJ24soMu3iLXIrsi273s4P1gZrYGrqReMfgEEA==",
|
||||
"version": "3.49.0",
|
||||
"resolved": "https://registry.npmjs.org/react-stately/-/react-stately-3.49.0.tgz",
|
||||
"integrity": "sha512-13iNq2KzBrRAzxRc+n53hgROfIistiYY/sPtIhCw1qUB7/kmo+X1xEU2uiS5zcCIrc55AUPwoHqOIIpKWSwB9A==",
|
||||
"license": "Apache-2.0",
|
||||
"dependencies": {
|
||||
"@internationalized/date": "^3.12.2",
|
||||
"@internationalized/date": "^3.12.3",
|
||||
"@internationalized/number": "^3.6.7",
|
||||
"@internationalized/string": "^3.2.9",
|
||||
"@react-types/shared": "^3.36.0",
|
||||
"@internationalized/string": "^3.2.10",
|
||||
"@react-types/shared": "^3.36.1",
|
||||
"@swc/helpers": "^0.5.0",
|
||||
"use-sync-external-store": "^1.6.0"
|
||||
},
|
||||
|
||||
@@ -38,11 +38,11 @@
|
||||
"livekit-client": "2.21.0",
|
||||
"posthog-js": "1.418.10",
|
||||
"react": "18.3.1",
|
||||
"react-aria": "3.50.0",
|
||||
"react-aria-components": "1.19.0",
|
||||
"react-aria": "3.51.0",
|
||||
"react-aria-components": "1.20.0",
|
||||
"react-dom": "18.3.1",
|
||||
"react-i18next": "17.0.12",
|
||||
"react-stately": "3.48.0",
|
||||
"react-stately": "3.49.0",
|
||||
"use-sound": "5.0.0",
|
||||
"valtio": "2.3.2",
|
||||
"wouter": "3.10.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
export const mediaUrl = (path: string) => {
|
||||
const origin =
|
||||
import.meta.env.VITE_API_BASE_URL ||
|
||||
import.meta.env.VITE_MEDIA_BASE_URL ||
|
||||
(typeof window !== 'undefined' ? window.location.origin : '')
|
||||
|
||||
// Remove leading/trailing slashes from origin/path if it exists
|
||||
|
||||
@@ -22,12 +22,14 @@ export interface ApiConfig {
|
||||
url: string
|
||||
}
|
||||
documentation_url?: string
|
||||
technical_documentation_url?: string
|
||||
external_home_url?: string
|
||||
silence_livekit_debug_logs?: boolean
|
||||
is_silent_login_enabled?: boolean
|
||||
custom_css_url?: string
|
||||
use_french_gov_footer?: boolean
|
||||
use_proconnect_button?: boolean
|
||||
allow_unregistered_rooms?: boolean
|
||||
idle_disconnect_warning_delay?: number
|
||||
recording?: {
|
||||
is_enabled?: boolean
|
||||
|
||||
@@ -22,6 +22,12 @@ export type IceCandidateInfo = {
|
||||
port?: number
|
||||
/** Local candidates only, and not reported by every browser. */
|
||||
networkType?: string
|
||||
/**
|
||||
* For a local relay candidate, the TURN URL it was gathered from
|
||||
* (e.g. `turns:turn.example.com:443?transport=tcp`). Used as a fallback
|
||||
* when the browser does not report `relayProtocol`.
|
||||
*/
|
||||
url?: string
|
||||
}
|
||||
|
||||
export type IceCandidatePair = {
|
||||
@@ -42,6 +48,57 @@ export type IceCandidateReport = {
|
||||
working: IceCandidatePair[]
|
||||
}
|
||||
|
||||
const isObject = (value: unknown): value is Record<string, unknown> =>
|
||||
typeof value === 'object' && value !== null
|
||||
|
||||
/** Narrows the loosely typed `data` stored on a step result. */
|
||||
export const isIceCandidateReport = (
|
||||
data: unknown
|
||||
): data is IceCandidateReport =>
|
||||
isObject(data) &&
|
||||
Array.isArray(data.working) &&
|
||||
(data.selected === null ||
|
||||
(isObject(data.selected) && isObject(data.selected.local)))
|
||||
|
||||
/**
|
||||
* Transport between the browser and the TURN server for a local relay
|
||||
* candidate: udp, tcp or tls, or undefined when it cannot be determined.
|
||||
*
|
||||
* `protocol` is deliberately not used here: on a relay candidate it describes
|
||||
* the TURN allocation (server to peer), which is UDP even when the client
|
||||
* reaches the TURN server over TLS.
|
||||
*/
|
||||
export const getRelayTransport = (
|
||||
candidate: IceCandidateInfo
|
||||
): string | undefined => {
|
||||
if (candidate.relayProtocol) return candidate.relayProtocol.toLowerCase()
|
||||
if (!candidate.url) return undefined
|
||||
|
||||
const url = candidate.url.toLowerCase()
|
||||
if (url.startsWith('turns:')) return 'tls'
|
||||
if (!url.startsWith('turn:')) return undefined
|
||||
const transport = /[?&]transport=(udp|tcp)\b/.exec(url)?.[1]
|
||||
// RFC 7065: a turn: URI without a transport parameter defaults to UDP.
|
||||
return transport ?? 'udp'
|
||||
}
|
||||
|
||||
/**
|
||||
* True when the selected pair goes through a TURN relay reached over TCP or
|
||||
* TLS. Media still flows, but TCP head-of-line blocking usually degrades
|
||||
* audio and video under packet loss.
|
||||
*
|
||||
* Direct routes (host, srflx, prflx), including ICE-TCP to the SFU, are out of
|
||||
* scope: the warning and its documentation are about TURN fallbacks.
|
||||
* An undetermined transport is not evidence of a bad route.
|
||||
*/
|
||||
export const isRelayedOverTcp = (data: unknown): boolean => {
|
||||
if (!isIceCandidateReport(data) || !data.selected) return false
|
||||
const { local } = data.selected
|
||||
if (local.type !== 'relay') return false
|
||||
const transport = getRelayTransport(local)
|
||||
return transport === 'tcp' || transport === 'tls'
|
||||
}
|
||||
|
||||
const PROBE_WIDTH = 320
|
||||
const PROBE_HEIGHT = 180
|
||||
const PROBE_FPS = 15
|
||||
@@ -57,6 +114,7 @@ const readCandidate = (stats?: Stats): IceCandidateInfo => {
|
||||
protocol: stats.protocol as string | undefined,
|
||||
relayProtocol: stats.relayProtocol as string | undefined,
|
||||
networkType: stats.networkType as string | undefined,
|
||||
url: stats.url as string | undefined,
|
||||
...(INCLUDE_CANDIDATE_ADDRESSES
|
||||
? {
|
||||
address: stats.address as string | undefined,
|
||||
@@ -67,7 +125,10 @@ const readCandidate = (stats?: Stats): IceCandidateInfo => {
|
||||
}
|
||||
|
||||
const describeCandidate = (candidate: IceCandidateInfo) => {
|
||||
const transport = candidate.relayProtocol ?? candidate.protocol ?? 'unknown'
|
||||
const transport =
|
||||
(candidate.type === 'relay' ? getRelayTransport(candidate) : undefined) ??
|
||||
candidate.protocol ??
|
||||
'unknown'
|
||||
const endpoint =
|
||||
candidate.address === undefined
|
||||
? ''
|
||||
|
||||
@@ -2,18 +2,44 @@ import type { ReactNode } from 'react'
|
||||
import { useTranslation } from 'react-i18next'
|
||||
import { ProgressBar } from 'react-aria-components'
|
||||
import { css, cx } from '@/styled-system/css'
|
||||
import { A } from '@/primitives'
|
||||
import { useConfig } from '@/api/useConfig'
|
||||
import type { ConnectionTestStats } from '../types'
|
||||
import { statusSquareClass } from './stepAppearance'
|
||||
|
||||
type SummaryState = 'idle' | 'running' | 'passed' | 'partial' | 'failed'
|
||||
type SummaryState =
|
||||
| 'idle'
|
||||
| 'running'
|
||||
| 'passed'
|
||||
| 'partial'
|
||||
| 'failed'
|
||||
| 'warning'
|
||||
|
||||
/** Only a failure earns a colour: everything else stays near-black. */
|
||||
/** Only a failure or a degraded route earns a colour: everything else stays near-black. */
|
||||
const stateColorClass: Record<SummaryState, string> = {
|
||||
idle: css({ color: 'greyscale.1000' }),
|
||||
running: css({ color: 'greyscale.1000' }),
|
||||
passed: css({ color: 'greyscale.1000' }),
|
||||
partial: css({ color: 'greyscale.1000' }),
|
||||
failed: css({ color: 'danger.600' }),
|
||||
warning: css({ color: 'warning' }),
|
||||
}
|
||||
|
||||
/**
|
||||
* A hard failure still outranks a warning step; a warning outranks 'partial'
|
||||
* because a measured degraded route matters more than skipped camera or
|
||||
* microphone checks.
|
||||
*/
|
||||
const getSummaryState = (
|
||||
stats: ConnectionTestStats,
|
||||
isRunning: boolean
|
||||
): SummaryState => {
|
||||
if (isRunning) return 'running'
|
||||
if (!stats.hasStarted) return 'idle'
|
||||
if (stats.failed > 0) return 'failed'
|
||||
if (stats.warnings > 0) return 'warning'
|
||||
if (stats.skipped > 0) return 'partial'
|
||||
return 'passed'
|
||||
}
|
||||
|
||||
const cardClass = css({
|
||||
@@ -183,16 +209,15 @@ export const ConnectionTestSummary = ({
|
||||
children?: ReactNode
|
||||
}) => {
|
||||
const { t } = useTranslation('connectionTest')
|
||||
const { data: config } = useConfig()
|
||||
|
||||
const state: SummaryState = isRunning
|
||||
? 'running'
|
||||
: !stats.hasStarted
|
||||
? 'idle'
|
||||
: stats.failed > 0
|
||||
? 'failed'
|
||||
: stats.skipped > 0
|
||||
? 'partial'
|
||||
: 'passed'
|
||||
// Network prerequisites for the reader's IT department. Instance specific,
|
||||
// so it comes from the backend; without it the warning shows no link.
|
||||
const networkDocUrl = config?.technical_documentation_url
|
||||
|
||||
const state = getSummaryState(stats, isRunning)
|
||||
// Skipped device checks still deserve their hint under a route warning.
|
||||
const showPartialHint = state === 'warning' && stats.skipped > 0
|
||||
|
||||
return (
|
||||
<section className={cardClass}>
|
||||
@@ -206,7 +231,27 @@ export const ConnectionTestSummary = ({
|
||||
: t(`summary.${state}`)}
|
||||
</p>
|
||||
|
||||
<p className={hintClass}>{t(`summary.${state}Hint`)}</p>
|
||||
<p className={hintClass}>
|
||||
{t(`summary.${state}Hint`)}
|
||||
{state === 'warning' && networkDocUrl && (
|
||||
<>
|
||||
{' '}
|
||||
<A
|
||||
href={networkDocUrl}
|
||||
target="_blank"
|
||||
rel="noopener noreferrer"
|
||||
size="sm"
|
||||
externalIcon
|
||||
aria-label={t('summary.warningDocLinkAriaLabel')}
|
||||
>
|
||||
{t('summary.warningDocLink')}
|
||||
</A>
|
||||
</>
|
||||
)}
|
||||
</p>
|
||||
{showPartialHint && (
|
||||
<p className={hintClass}>{t('summary.partialHint')}</p>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{stats.hasStarted && (
|
||||
@@ -237,6 +282,13 @@ export const ConnectionTestSummary = ({
|
||||
value={stats.passed}
|
||||
label={t('counts.passed')}
|
||||
/>
|
||||
{stats.warnings > 0 && (
|
||||
<Counter
|
||||
squareClass={statusSquareClass.warning}
|
||||
value={stats.warnings}
|
||||
label={t('counts.warnings')}
|
||||
/>
|
||||
)}
|
||||
<Counter
|
||||
squareClass={statusSquareClass.skipped}
|
||||
value={stats.skipped}
|
||||
|
||||
@@ -15,15 +15,20 @@ export const statusSquareClass: Record<ConnectionTestStepStatus, string> = {
|
||||
animation: 'pulse_background 1.2s ease-in-out infinite',
|
||||
}),
|
||||
success: css({ backgroundColor: 'success.600' }),
|
||||
warning: css({ backgroundColor: 'warning' }),
|
||||
failed: css({ backgroundColor: 'danger.600' }),
|
||||
skipped: css({ backgroundColor: 'greyscale.300' }),
|
||||
}
|
||||
|
||||
/** Colour is carried by the square; the label stays near-black except on failure. */
|
||||
/**
|
||||
* Colour is carried by the square; the label stays near-black except on
|
||||
* failure and warning.
|
||||
*/
|
||||
export const statusTextClass: Record<ConnectionTestStepStatus, string> = {
|
||||
pending: css({ color: 'greyscale.500' }),
|
||||
running: css({ color: 'greyscale.700' }),
|
||||
success: css({ color: 'greyscale.1000' }),
|
||||
warning: css({ color: 'warning', fontWeight: 'medium' }),
|
||||
failed: css({ color: 'danger.600', fontWeight: 'medium' }),
|
||||
skipped: css({ color: 'greyscale.500' }),
|
||||
}
|
||||
|
||||
@@ -8,7 +8,10 @@ import {
|
||||
type CheckInfo,
|
||||
} from 'livekit-client'
|
||||
import { fetchConnectionTestDetails } from '../api/fetchConnectionTestDetails'
|
||||
import { SelectedCandidateCheck } from '../checks/selectedCandidate'
|
||||
import {
|
||||
isRelayedOverTcp,
|
||||
SelectedCandidateCheck,
|
||||
} from '../checks/selectedCandidate'
|
||||
import {
|
||||
createInitialSteps,
|
||||
type ConnectionTestLog,
|
||||
@@ -49,10 +52,23 @@ const getErrorMessage = (error: unknown, fallback = 'Unknown error') =>
|
||||
const isPermissionError = (error: unknown) =>
|
||||
error instanceof Error && PERMISSION_ERROR_NAMES.has(error.name)
|
||||
|
||||
const toStepStatus = (info: CheckInfo): ConnectionTestStepStatus => {
|
||||
const status = CHECK_STATUS_TO_STEP[info.status] ?? 'failed'
|
||||
return status === 'success' && isRelayedOverTcp(info.data)
|
||||
? 'warning'
|
||||
: status
|
||||
}
|
||||
|
||||
const fromCheckInfo = (info: CheckInfo): Partial<ConnectionTestStepResult> => ({
|
||||
status: CHECK_STATUS_TO_STEP[info.status] ?? 'failed',
|
||||
status: toStepStatus(info),
|
||||
summary: info.description,
|
||||
logs: info.logs,
|
||||
// Only SelectedCandidateCheck sets `data` (the ICE candidate report).
|
||||
// Consumers narrow it with a type guard (see isIceCandidateReport).
|
||||
data:
|
||||
typeof info.data === 'object' && info.data !== null
|
||||
? (info.data as Record<string, unknown>)
|
||||
: undefined,
|
||||
})
|
||||
|
||||
const groupDevicesByKind = (devices: MediaDeviceInfo[]) => {
|
||||
|
||||
@@ -15,6 +15,7 @@ export type ConnectionTestStepStatus =
|
||||
| 'pending'
|
||||
| 'running'
|
||||
| 'success'
|
||||
| 'warning'
|
||||
| 'failed'
|
||||
| 'skipped'
|
||||
|
||||
@@ -63,6 +64,7 @@ export type ConnectionTestStats = {
|
||||
total: number
|
||||
settled: number
|
||||
passed: number
|
||||
warnings: number
|
||||
failed: number
|
||||
skipped: number
|
||||
hasStarted: boolean
|
||||
@@ -77,24 +79,27 @@ export const summarizeSteps = (
|
||||
steps: ConnectionTestStepResult[]
|
||||
): ConnectionTestStats => {
|
||||
let passed = 0
|
||||
let warnings = 0
|
||||
let failed = 0
|
||||
let skipped = 0
|
||||
let pending = 0
|
||||
|
||||
for (const step of steps) {
|
||||
if (step.status === 'success') passed += 1
|
||||
else if (step.status === 'warning') warnings += 1
|
||||
else if (step.status === 'failed') failed += 1
|
||||
else if (step.status === 'skipped') skipped += 1
|
||||
else if (step.status === 'pending') pending += 1
|
||||
}
|
||||
|
||||
const total = steps.length
|
||||
const settled = passed + failed + skipped
|
||||
const settled = passed + warnings + failed + skipped
|
||||
|
||||
return {
|
||||
total,
|
||||
settled,
|
||||
passed,
|
||||
warnings,
|
||||
failed,
|
||||
skipped,
|
||||
hasStarted: pending < total,
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
import { useTranslation } from 'react-i18next'
|
||||
import { Button } from '@/primitives'
|
||||
import { navigateTo } from '@/navigation/navigateTo'
|
||||
import { generateRoomId } from '@/features/rooms'
|
||||
|
||||
export const CreateUnregisteredMeetingButton = () => {
|
||||
const { t } = useTranslation('home')
|
||||
return (
|
||||
<Button
|
||||
variant="primary"
|
||||
data-attr="create-unregistered-meeting"
|
||||
onPress={() =>
|
||||
navigateTo('room', generateRoomId(), { state: { create: true } })
|
||||
}
|
||||
>
|
||||
{t('createMeeting')}
|
||||
</Button>
|
||||
)
|
||||
}
|
||||
@@ -9,6 +9,7 @@ import { JoinMeetingDialog } from '../components/JoinMeetingDialog'
|
||||
import { IntroSlider } from '../components/IntroSlider'
|
||||
import { MoreLink } from '../components/MoreLink'
|
||||
import { CreateMeetingMenu } from '../components/CreateMeetingMenu'
|
||||
import { CreateUnregisteredMeetingButton } from '../components/CreateUnregisteredMeetingButton'
|
||||
import { ReactNode, useEffect, useState } from 'react'
|
||||
|
||||
import { css } from '@/styled-system/css'
|
||||
@@ -189,13 +190,19 @@ const Home = () => {
|
||||
display: 'flex',
|
||||
gap: 0.5,
|
||||
flexDirection: { base: 'column', xsm: 'row' },
|
||||
flexWrap: 'wrap',
|
||||
alignItems: { base: 'center', xsm: 'items-start' },
|
||||
})}
|
||||
>
|
||||
{isLoggedIn ? (
|
||||
<CreateMeetingMenu />
|
||||
) : (
|
||||
<LoginButton proConnectHint={false} />
|
||||
<>
|
||||
{data?.allow_unregistered_rooms && (
|
||||
<CreateUnregisteredMeetingButton />
|
||||
)}
|
||||
<LoginButton proConnectHint={false} />
|
||||
</>
|
||||
)}
|
||||
<DialogTrigger>
|
||||
<Button
|
||||
|
||||
@@ -40,11 +40,15 @@ const StyledRACDialog = styled(Dialog, {
|
||||
})
|
||||
|
||||
export const InviteDialog = ({ mode }: { mode: 'join' | 'create' }) => {
|
||||
const [showInviteDialog, setShowInviteDialog] = useState(mode === 'create')
|
||||
|
||||
const { t } = useTranslation('rooms', { keyPrefix: 'shareDialog' })
|
||||
|
||||
const roomData = useRoomData()
|
||||
|
||||
const isCreatingUnregisteredRoom =
|
||||
roomData?.id === null && !!history.state?.create
|
||||
const [isDismissed, setIsDismissed] = useState(false)
|
||||
const showInviteDialog =
|
||||
!isDismissed && (mode === 'create' || isCreatingUnregisteredRoom)
|
||||
const roomUrl = roomData?.slug ? getRouteUrl('room', roomData.slug) : ''
|
||||
|
||||
const telephony = useTelephony()
|
||||
@@ -78,7 +82,7 @@ export const InviteDialog = ({ mode }: { mode: 'join' | 'create' }) => {
|
||||
variant="tertiaryText"
|
||||
size="xs"
|
||||
onPress={() => {
|
||||
setShowInviteDialog(false)
|
||||
setIsDismissed(true)
|
||||
}}
|
||||
aria-label={t('closeDialog')}
|
||||
>
|
||||
|
||||
@@ -126,6 +126,9 @@ export const Footer = () => {
|
||||
return null
|
||||
}
|
||||
|
||||
const isConnectionTestEnabled = !!data.diagnostics?.connection_test_enabled
|
||||
const technicalDocumentationUrl = data.technical_documentation_url
|
||||
|
||||
return (
|
||||
<footer
|
||||
className={css({
|
||||
@@ -256,7 +259,9 @@ export const Footer = () => {
|
||||
{t('links.data')}
|
||||
</A>
|
||||
</StyledLi>
|
||||
<StyledLi divider>
|
||||
<StyledLi
|
||||
divider={isConnectionTestEnabled || !!technicalDocumentationUrl}
|
||||
>
|
||||
<Link
|
||||
underline={false}
|
||||
footer="minor"
|
||||
@@ -266,8 +271,8 @@ export const Footer = () => {
|
||||
{t('links.accessibility')}
|
||||
</Link>
|
||||
</StyledLi>
|
||||
{data?.diagnostics?.connection_test_enabled && (
|
||||
<StyledLi divider>
|
||||
{isConnectionTestEnabled && (
|
||||
<StyledLi divider={!!technicalDocumentationUrl}>
|
||||
<Link
|
||||
underline={false}
|
||||
footer="minor"
|
||||
@@ -278,19 +283,21 @@ export const Footer = () => {
|
||||
</Link>
|
||||
</StyledLi>
|
||||
)}
|
||||
<StyledLi>
|
||||
<A
|
||||
externalIcon
|
||||
underline={false}
|
||||
footer="minor"
|
||||
href="https://docs.numerique.gouv.fr/docs/f2baa1b9-f29e-4d58-959d-65d4376fc6b8/"
|
||||
aria-label={
|
||||
t('links.technicalDetails') + ' - ' + t('links.ariaLabel')
|
||||
}
|
||||
>
|
||||
{t('links.technicalDetails')}
|
||||
</A>
|
||||
</StyledLi>
|
||||
{technicalDocumentationUrl && (
|
||||
<StyledLi>
|
||||
<A
|
||||
externalIcon
|
||||
underline={false}
|
||||
footer="minor"
|
||||
href={technicalDocumentationUrl}
|
||||
aria-label={
|
||||
t('links.technicalDetails') + ' - ' + t('links.ariaLabel')
|
||||
}
|
||||
>
|
||||
{t('links.technicalDetails')}
|
||||
</A>
|
||||
</StyledLi>
|
||||
)}
|
||||
</SecondRow>
|
||||
<ThirdRow>
|
||||
{t('mentions')}{' '}
|
||||
|
||||
@@ -29,11 +29,13 @@
|
||||
"pending": "Ausstehend",
|
||||
"running": "Läuft…",
|
||||
"success": "Erfolgreich",
|
||||
"warning": "Nicht optimal",
|
||||
"failed": "Fehlgeschlagen",
|
||||
"skipped": "Übersprungen"
|
||||
},
|
||||
"counts": {
|
||||
"passed": "erfolgreich",
|
||||
"warnings": "nicht optimal",
|
||||
"failed": "fehlgeschlagen",
|
||||
"skipped": "übersprungen"
|
||||
},
|
||||
@@ -46,6 +48,10 @@
|
||||
"passedHint": "Ihr Browser, Ihre Geräte und Ihr Netzwerk sind für eine Besprechung bereit.",
|
||||
"partial": "Teilweiser Test",
|
||||
"partialHint": "Einige Prüfungen wurden übersprungen. Erlauben Sie den Zugriff auf Ihre Kamera und Ihr Mikrofon, um diese zu testen.",
|
||||
"warning": "Verbindung nicht optimal",
|
||||
"warningHint": "Sie können an Ihren Besprechungen teilnehmen, aber die Bild- und Tonqualität kann aufgrund Ihrer Netzwerkeinstellungen beeinträchtigt sein. Ihre IT-Abteilung kann hier Abhilfe schaffen.",
|
||||
"warningDocLink": "Netzwerkanforderungen für Ihre IT-Abteilung",
|
||||
"warningDocLinkAriaLabel": "Netzwerkanforderungen für Ihre IT-Abteilung öffnen – öffnet in neuem Tab",
|
||||
"failed_one": "{{count}} Prüfung fehlgeschlagen",
|
||||
"failed_other": "{{count}} Prüfungen fehlgeschlagen",
|
||||
"failedHint": "Öffnen Sie die fehlgeschlagenen Prüfungen für weitere Details und senden Sie den Bericht an Ihre IT-Abteilung."
|
||||
|
||||
@@ -29,11 +29,13 @@
|
||||
"pending": "Pending",
|
||||
"running": "Running…",
|
||||
"success": "Passed",
|
||||
"warning": "Not optimal",
|
||||
"failed": "Failed",
|
||||
"skipped": "Skipped"
|
||||
},
|
||||
"counts": {
|
||||
"passed": "passed",
|
||||
"warnings": "not optimal",
|
||||
"failed": "failed",
|
||||
"skipped": "skipped"
|
||||
},
|
||||
@@ -46,6 +48,10 @@
|
||||
"passedHint": "Your browser, your devices and your network are ready for a meeting.",
|
||||
"partial": "Partially tested",
|
||||
"partialHint": "Some checks were skipped. Allow access to your camera and microphone to test them.",
|
||||
"warning": "Suboptimal connection",
|
||||
"warningHint": "You can join your meetings, but video and audio quality may be reduced because of your network settings. Your IT department can improve this.",
|
||||
"warningDocLink": "Network requirements for your IT department",
|
||||
"warningDocLinkAriaLabel": "Open the network requirements for your IT department - opens in new window",
|
||||
"failed_one": "{{count}} check failed",
|
||||
"failed_other": "{{count}} checks failed",
|
||||
"failedHint": "Open the failed checks below for details, then send the report to your IT department."
|
||||
|
||||
@@ -29,11 +29,13 @@
|
||||
"pending": "En espera",
|
||||
"running": "En curso…",
|
||||
"success": "Correcto",
|
||||
"warning": "No óptimo",
|
||||
"failed": "Error",
|
||||
"skipped": "Omitido"
|
||||
},
|
||||
"counts": {
|
||||
"passed": "correctas",
|
||||
"warnings": "no óptimas",
|
||||
"failed": "con errores",
|
||||
"skipped": "omitidas"
|
||||
},
|
||||
@@ -46,6 +48,10 @@
|
||||
"passedHint": "Tu navegador, tus dispositivos y tu red están listos para una reunión.",
|
||||
"partial": "Prueba parcial",
|
||||
"partialHint": "Se han omitido algunas comprobaciones. Autoriza el acceso a tu cámara y a tu micrófono para probarlos.",
|
||||
"warning": "Conexión no óptima",
|
||||
"warningHint": "Puedes participar en tus reuniones, pero la calidad de la imagen y del sonido puede verse reducida por la configuración de tu red. Tu servicio informático puede mejorar la situación.",
|
||||
"warningDocLink": "Requisitos de red para tu servicio informático",
|
||||
"warningDocLinkAriaLabel": "Abrir los requisitos de red para tu servicio informático - se abre en una nueva ventana",
|
||||
"failed_one": "{{count}} verificación en error",
|
||||
"failed_other": "{{count}} verificaciones en error",
|
||||
"failedHint": "Abre las verificaciones en error para ver el detalle y transmite después el informe a tu servicio informático."
|
||||
|
||||
@@ -29,11 +29,13 @@
|
||||
"pending": "En attente",
|
||||
"running": "En cours…",
|
||||
"success": "Réussi",
|
||||
"warning": "Non optimal",
|
||||
"failed": "Échec",
|
||||
"skipped": "Ignoré"
|
||||
},
|
||||
"counts": {
|
||||
"passed": "réussis",
|
||||
"warnings": "non optimaux",
|
||||
"failed": "en échec",
|
||||
"skipped": "ignorés"
|
||||
},
|
||||
@@ -46,6 +48,10 @@
|
||||
"passedHint": "Votre navigateur, vos périphériques et votre réseau sont prêts pour une réunion.",
|
||||
"partial": "Test partiel",
|
||||
"partialHint": "Certaines vérifications ont été ignorées. Autorisez l'accès à votre caméra et à votre microphone pour les tester.",
|
||||
"warning": "Connexion non optimale",
|
||||
"warningHint": "Vous pouvez participer à vos réunions, mais la qualité de l'image et du son risque d'être réduite à cause des réglages de votre réseau. Votre service informatique peut améliorer la situation.",
|
||||
"warningDocLink": "Prérequis réseau à transmettre à votre service informatique",
|
||||
"warningDocLinkAriaLabel": "Ouvrir les prérequis réseau à transmettre à votre service informatique - ouvre dans une nouvelle fenêtre",
|
||||
"failed_one": "{{count}} vérification en échec",
|
||||
"failed_other": "{{count}} vérifications en échec",
|
||||
"failedHint": "Ouvrez les vérifications en échec pour voir le détail, puis transmettez le rapport à votre service informatique."
|
||||
|
||||
@@ -29,11 +29,13 @@
|
||||
"pending": "In afwachting",
|
||||
"running": "Bezig…",
|
||||
"success": "Geslaagd",
|
||||
"warning": "Niet optimaal",
|
||||
"failed": "Mislukt",
|
||||
"skipped": "Overgeslagen"
|
||||
},
|
||||
"counts": {
|
||||
"passed": "geslaagd",
|
||||
"warnings": "niet optimaal",
|
||||
"failed": "mislukt",
|
||||
"skipped": "overgeslagen"
|
||||
},
|
||||
@@ -46,6 +48,10 @@
|
||||
"passedHint": "Je browser, apparaten en netwerk zijn klaar voor een vergadering.",
|
||||
"partial": "Gedeeltelijke test",
|
||||
"partialHint": "Sommige controles zijn overgeslagen. Geef toegang tot je camera en microfoon om deze te testen.",
|
||||
"warning": "Verbinding niet optimaal",
|
||||
"warningHint": "Je kunt deelnemen aan je vergaderingen, maar de beeld- en geluidskwaliteit kan minder zijn door de instellingen van je netwerk. Je IT-afdeling kan dit verbeteren.",
|
||||
"warningDocLink": "Netwerkvereisten voor je IT-afdeling",
|
||||
"warningDocLinkAriaLabel": "Netwerkvereisten voor je IT-afdeling openen - opent in nieuw venster",
|
||||
"failed_one": "{{count}} controle mislukt",
|
||||
"failed_other": "{{count}} controles mislukt",
|
||||
"failedHint": "Open de mislukte controles voor meer details en stuur het rapport door naar je IT-afdeling."
|
||||
|
||||
@@ -103,3 +103,8 @@ html:has(.lk-video-conference) {
|
||||
opacity: 1;
|
||||
pointer-events: auto;
|
||||
}
|
||||
|
||||
/* Same workaround as above, see adobe/react-spectrum#10680 */
|
||||
[role='tooltip'][data-rac]:not([data-placement]) {
|
||||
visibility: hidden;
|
||||
}
|
||||
|
||||
Vendored
+1
@@ -6,6 +6,7 @@ declare const __MEDIAPIPE_VERSION__: string
|
||||
interface ImportMetaEnv {
|
||||
readonly VITE_API_BASE_URL: string
|
||||
readonly VITE_APP_TITLE: string
|
||||
readonly VITE_MEDIA_BASE_URL?: string
|
||||
}
|
||||
|
||||
interface ImportMeta {
|
||||
|
||||
@@ -157,6 +157,7 @@ backend:
|
||||
FRONTEND_SUPPORT: "{'id': '58ea6697-8eba-4492-bc59-ad6562585041', 'help_article_transcript': 'https://lasuite.crisp.help/fr/article/visio-transcript-1sjq43x', 'help_article_recording': 'https://lasuite.crisp.help/fr/article/visio-enregistrement-wgc8o0', 'help_article_more_tools': 'https://lasuite.crisp.help/fr/article/visio-tools-bvxj23'}"
|
||||
FRONTEND_FEEDBACK: "{'url': 'https://grist.numerique.gouv.fr/o/docs/cbMv4G7pLY3Z/USER-RESEARCH-or-LA-SUITE/f/26'}"
|
||||
FRONTEND_DOCUMENTATION_URL: "https://docs.numerique.gouv.fr/docs/7c5bd65d-3c21-486f-bce1-26e0a921d642/"
|
||||
FRONTEND_TECHNICAL_DOCUMENTATION_URL: "https://docs.numerique.gouv.fr/docs/f2baa1b9-f29e-4d58-959d-65d4376fc6b8/"
|
||||
FRONTEND_MANIFEST_LINK: "https://docs.numerique.gouv.fr/docs/1ef86abf-f7e0-46ce-b6c7-8be8b8af4c3d/"
|
||||
FRONTEND_IDLE_DISCONNECT_WARNING_DELAY: 9000
|
||||
FRONTEND_TRANSCRIPTION_DESTINATION: "https://docs.numerique.gouv.fr"
|
||||
|
||||
@@ -9,7 +9,6 @@ from typing import Any
|
||||
from urllib.parse import urljoin
|
||||
|
||||
import requests
|
||||
import sentry_sdk
|
||||
from celery import Celery, signals
|
||||
from celery.utils.log import get_task_logger
|
||||
from openai.types.audio import Transcription
|
||||
@@ -42,6 +41,7 @@ from summary.core.prompt import (
|
||||
PROMPT_SYSTEM_TLDR,
|
||||
PROMPT_USER_PART,
|
||||
)
|
||||
from summary.core.sentry import init_sentry
|
||||
from summary.core.shared_models import (
|
||||
SummarizeWebhookFailurePayload,
|
||||
SummarizeWebhookSuccessPayload,
|
||||
@@ -75,12 +75,11 @@ celery = Celery(
|
||||
|
||||
celery.config_from_object("summary.core.celery_config")
|
||||
|
||||
if settings.sentry_dsn and settings.sentry_is_enabled:
|
||||
|
||||
@signals.celeryd_init.connect
|
||||
def init_sentry(**_kwargs):
|
||||
"""Initialize sentry."""
|
||||
sentry_sdk.init(dsn=settings.sentry_dsn, enable_tracing=True)
|
||||
@signals.celeryd_init.connect
|
||||
def init_celery_sentry(**_kwargs):
|
||||
"""Initialize Sentry in the Celery worker."""
|
||||
init_sentry()
|
||||
|
||||
|
||||
file_service = FileService()
|
||||
|
||||
@@ -84,6 +84,8 @@ class Settings(BaseSettings):
|
||||
aws_s3_secret_access_key: SecretStr
|
||||
aws_s3_secure_access: bool = True
|
||||
aws_s3_region_name: str | None = None
|
||||
aws_s3_request_checksum_calculation: str | None = None
|
||||
aws_s3_response_checksum_validation: str | None = None
|
||||
aws_transcript_path: str = "transcripts"
|
||||
aws_summary_path: str = "summaries"
|
||||
|
||||
@@ -126,6 +128,7 @@ class Settings(BaseSettings):
|
||||
# Sentry
|
||||
sentry_is_enabled: bool = False
|
||||
sentry_dsn: Optional[str] = None
|
||||
sentry_traces_sample_rate: float = Field(default=0.1, ge=0.0, le=1.0)
|
||||
|
||||
# Posthog (analytics)
|
||||
posthog_enabled: bool = False
|
||||
|
||||
@@ -286,7 +286,12 @@ def _build_s3_client():
|
||||
aws_access_key_id=settings.aws_s3_access_key_id,
|
||||
aws_secret_access_key=settings.aws_s3_secret_access_key.get_secret_value(),
|
||||
region_name=settings.aws_s3_region_name,
|
||||
config=Config(signature_version="s3v4", s3={"addressing_style": "path"}),
|
||||
config=Config(
|
||||
signature_version="s3v4",
|
||||
s3={"addressing_style": "path"},
|
||||
request_checksum_calculation=settings.aws_s3_request_checksum_calculation,
|
||||
response_checksum_validation=settings.aws_s3_response_checksum_validation,
|
||||
),
|
||||
)
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,94 @@
|
||||
"""Sentry configuration."""
|
||||
|
||||
import sentry_sdk
|
||||
from sentry_sdk.scrubber import DEFAULT_DENYLIST, DEFAULT_PII_DENYLIST, EventScrubber
|
||||
|
||||
from summary.core.config import get_settings
|
||||
|
||||
# Exact names (case-insensitive) of variables and dict keys to redact.
|
||||
SENSITIVE_DATA_DENYLIST = [
|
||||
# Raw payloads and serialized bodies
|
||||
"data",
|
||||
"body",
|
||||
"payload",
|
||||
"args",
|
||||
"kwargs",
|
||||
"response",
|
||||
"res",
|
||||
# Transcripts
|
||||
"transcript",
|
||||
"transcription",
|
||||
"transcription_json",
|
||||
"transcription_res",
|
||||
"new_transcription",
|
||||
"segments",
|
||||
"word_segments",
|
||||
"words",
|
||||
"text",
|
||||
"content",
|
||||
"formatted_output",
|
||||
# Summaries and LLM exchanges
|
||||
"summary",
|
||||
"raw_summary",
|
||||
"cleaned_summary",
|
||||
"tldr",
|
||||
"part",
|
||||
"parts",
|
||||
"parts_summarized",
|
||||
"next_steps",
|
||||
"title",
|
||||
"titles",
|
||||
"action",
|
||||
"line",
|
||||
"lines",
|
||||
"user_prompt",
|
||||
"prompt_user_part",
|
||||
"messages",
|
||||
"json_data", # OpenAI client internals
|
||||
"opts",
|
||||
"options",
|
||||
"input_options",
|
||||
# Participants' personal data
|
||||
"email",
|
||||
"user_email",
|
||||
"assignees",
|
||||
"participant_name",
|
||||
"participant_names",
|
||||
"participants_info",
|
||||
"speaker_to_name",
|
||||
# Signed / pre-authenticated URLs
|
||||
"cloud_storage_url",
|
||||
"transcription_data_url",
|
||||
"summary_data_url",
|
||||
]
|
||||
|
||||
|
||||
def build_event_scrubber() -> EventScrubber:
|
||||
"""Build the scrubber redacting meeting content and personal data."""
|
||||
return EventScrubber(
|
||||
denylist=DEFAULT_DENYLIST + SENSITIVE_DATA_DENYLIST,
|
||||
pii_denylist=DEFAULT_PII_DENYLIST,
|
||||
recursive=True,
|
||||
)
|
||||
|
||||
|
||||
def init_sentry() -> None:
|
||||
"""Initialize Sentry if enabled in the settings."""
|
||||
settings = get_settings()
|
||||
|
||||
if not settings.sentry_is_enabled:
|
||||
return
|
||||
|
||||
if not settings.sentry_dsn:
|
||||
return
|
||||
|
||||
sentry_sdk.init(
|
||||
dsn=settings.sentry_dsn,
|
||||
traces_sample_rate=settings.sentry_traces_sample_rate,
|
||||
# Never attach request bodies, Celery task arguments or user data.
|
||||
send_default_pii=False,
|
||||
# Task creation requests carry the content to summarize.
|
||||
max_request_body_size="never",
|
||||
include_local_variables=True,
|
||||
event_scrubber=build_event_scrubber(),
|
||||
)
|
||||
@@ -1,18 +1,17 @@
|
||||
"""Application."""
|
||||
|
||||
import sentry_sdk
|
||||
from dockerflow.fastapi import router as dockerflow_router
|
||||
from fastapi import FastAPI
|
||||
|
||||
from summary.api.main import api_router_v2
|
||||
from summary.core import checks # noqa: F401 -- registers the Dockerflow checks
|
||||
from summary.core.config import get_settings
|
||||
from summary.core.sentry import init_sentry
|
||||
|
||||
settings = get_settings()
|
||||
|
||||
|
||||
if settings.sentry_dsn and settings.sentry_is_enabled:
|
||||
sentry_sdk.init(dsn=settings.sentry_dsn, enable_tracing=True)
|
||||
init_sentry()
|
||||
|
||||
app = FastAPI(
|
||||
title=settings.app_name,
|
||||
|
||||
@@ -0,0 +1,207 @@
|
||||
"""Tests for the Sentry configuration.
|
||||
|
||||
Each test raises an error from code handling meeting content and inspects the
|
||||
event Sentry would send: the content must be redacted, while harmless local
|
||||
variables are kept for debugging.
|
||||
"""
|
||||
|
||||
import json
|
||||
from collections.abc import Callable, Iterator
|
||||
from unittest.mock import Mock
|
||||
|
||||
import httpx
|
||||
import openai
|
||||
import pytest
|
||||
import sentry_sdk
|
||||
from botocore.exceptions import ClientError
|
||||
from botocore.stub import Stubber
|
||||
from sentry_sdk.transport import Transport
|
||||
|
||||
from summary.core import file_service
|
||||
from summary.core import sentry as sentry_module
|
||||
from summary.core.file_service import FileService
|
||||
from summary.core.llm_service import LLMException, LLMService
|
||||
from summary.core.shared_models import WhisperXResponse
|
||||
|
||||
CANARY = "CANARY-MEETING-CONTENT"
|
||||
|
||||
SentryEvents = Callable[[], list[str]]
|
||||
|
||||
|
||||
class _CapturingTransport(Transport):
|
||||
"""Keep serialized events in memory instead of sending them."""
|
||||
|
||||
def __init__(self):
|
||||
super().__init__()
|
||||
self.events: list[str] = []
|
||||
|
||||
def capture_envelope(self, envelope):
|
||||
"""Store each serialized event of the envelope."""
|
||||
for item in envelope.items:
|
||||
if item.type == "event":
|
||||
self.events.append(item.payload.get_bytes().decode())
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def sentry_events() -> Iterator[SentryEvents]:
|
||||
"""Initialize Sentry as in production, with an in-memory transport."""
|
||||
transport = _CapturingTransport()
|
||||
sentry_sdk.init(
|
||||
dsn="https://public@sentry.example.com/1",
|
||||
transport=transport,
|
||||
send_default_pii=False,
|
||||
include_local_variables=True,
|
||||
event_scrubber=sentry_module.build_event_scrubber(),
|
||||
default_integrations=False,
|
||||
)
|
||||
|
||||
def flush() -> list[str]:
|
||||
sentry_sdk.flush()
|
||||
return transport.events
|
||||
|
||||
yield flush
|
||||
sentry_sdk.init() # Disable Sentry for the following tests
|
||||
|
||||
|
||||
def _transcript() -> WhisperXResponse:
|
||||
return WhisperXResponse.model_validate(
|
||||
{
|
||||
"segments": [
|
||||
{
|
||||
"start": 0.0,
|
||||
"end": 1.0,
|
||||
"text": f"I don't know {CANARY}",
|
||||
"speaker": "SPEAKER_01",
|
||||
"words": [
|
||||
{
|
||||
"word": CANARY,
|
||||
"start": 0.0,
|
||||
"end": 1.0,
|
||||
"score": 0.9,
|
||||
"speaker": "SPEAKER_01",
|
||||
}
|
||||
],
|
||||
}
|
||||
]
|
||||
}
|
||||
)
|
||||
|
||||
|
||||
def _local_vars(event: str) -> list[dict]:
|
||||
"""Return the local variables of every frame of the event."""
|
||||
return [
|
||||
frame.get("vars", {})
|
||||
for exception in json.loads(event)["exception"]["values"]
|
||||
for frame in exception["stacktrace"]["frames"]
|
||||
]
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def s3_stubber(monkeypatch: pytest.MonkeyPatch) -> Iterator[Stubber]:
|
||||
"""Stub the S3 client built by the file service."""
|
||||
monkeypatch.setattr(
|
||||
file_service,
|
||||
"settings",
|
||||
file_service.settings.model_copy(
|
||||
update={
|
||||
"aws_s3_endpoint_url": "garage:9000",
|
||||
"aws_s3_secure_access": False,
|
||||
"aws_s3_region_name": "fr-par",
|
||||
"aws_storage_bucket_name": "meet-media-storage",
|
||||
}
|
||||
),
|
||||
)
|
||||
stubber = Stubber(file_service._build_s3_client())
|
||||
stubber.activate()
|
||||
monkeypatch.setattr(file_service, "_build_s3_client", lambda: stubber.client)
|
||||
yield stubber
|
||||
stubber.assert_no_pending_responses()
|
||||
|
||||
|
||||
def test_sentry_store_transcript_failure_redacts_transcript(
|
||||
sentry_events: SentryEvents, s3_stubber: Stubber
|
||||
) -> None:
|
||||
"""A failed S3 upload does not send the transcript, but keeps the job id."""
|
||||
s3_stubber.add_client_error("put_object", service_error_code="InvalidDigest")
|
||||
|
||||
try:
|
||||
FileService().store_transcript(transcript=_transcript(), job_id="job-1")
|
||||
except ClientError:
|
||||
sentry_sdk.capture_exception()
|
||||
else:
|
||||
pytest.fail("store_transcript should have failed")
|
||||
|
||||
[event] = sentry_events()
|
||||
assert CANARY not in event
|
||||
|
||||
store_transcript_vars = next(
|
||||
frame_vars
|
||||
for frame_vars in _local_vars(event)
|
||||
if "transcript_path" in frame_vars
|
||||
)
|
||||
assert store_transcript_vars["job_id"] == "'job-1'"
|
||||
assert store_transcript_vars["transcript_path"] == "'transcripts/job-1.json'"
|
||||
assert store_transcript_vars["data"] == "[Filtered]"
|
||||
assert store_transcript_vars["transcript"] == "[Filtered]"
|
||||
|
||||
|
||||
def test_sentry_llm_failure_redacts_prompts(sentry_events: SentryEvents) -> None:
|
||||
"""A failed LLM call does not send the prompts, even from OpenAI internals."""
|
||||
client = openai.OpenAI(
|
||||
api_key="test-key",
|
||||
base_url="https://llm.example.com/v1",
|
||||
max_retries=0,
|
||||
http_client=httpx.Client(
|
||||
transport=httpx.MockTransport(lambda request: httpx.Response(500))
|
||||
),
|
||||
)
|
||||
observability = Mock(is_enabled=False)
|
||||
observability.get_openai_client.return_value = client
|
||||
|
||||
try:
|
||||
LLMService(observability).call(
|
||||
system_prompt="Summarize this meeting.",
|
||||
user_prompt=f"Transcript: {CANARY}",
|
||||
name="tldr",
|
||||
)
|
||||
except LLMException:
|
||||
sentry_sdk.capture_exception()
|
||||
else:
|
||||
pytest.fail("the LLM call should have failed")
|
||||
|
||||
[event] = sentry_events()
|
||||
assert CANARY not in event
|
||||
|
||||
|
||||
def test_init_sentry_uses_the_event_scrubber(monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""Sentry is initialized with local variables and the content scrubber."""
|
||||
settings = sentry_module.get_settings().model_copy(
|
||||
update={"sentry_is_enabled": True, "sentry_dsn": "https://k@example.com/1"}
|
||||
)
|
||||
monkeypatch.setattr(sentry_module, "get_settings", lambda: settings)
|
||||
init = Mock()
|
||||
monkeypatch.setattr(sentry_module.sentry_sdk, "init", init)
|
||||
|
||||
sentry_module.init_sentry()
|
||||
|
||||
init.assert_called_once()
|
||||
kwargs = init.call_args.kwargs
|
||||
assert kwargs["send_default_pii"] is False
|
||||
assert kwargs["max_request_body_size"] == "never"
|
||||
assert kwargs["include_local_variables"] is True
|
||||
denylist = kwargs["event_scrubber"].denylist
|
||||
assert {"data", "transcript", "content", "summary", "password"} <= set(denylist)
|
||||
|
||||
|
||||
def test_init_sentry_disabled(monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""Sentry is not initialized when disabled."""
|
||||
settings = sentry_module.get_settings().model_copy(
|
||||
update={"sentry_is_enabled": False, "sentry_dsn": "https://k@example.com/1"}
|
||||
)
|
||||
monkeypatch.setattr(sentry_module, "get_settings", lambda: settings)
|
||||
init = Mock()
|
||||
monkeypatch.setattr(sentry_module.sentry_sdk, "init", init)
|
||||
|
||||
sentry_module.init_sentry()
|
||||
|
||||
init.assert_not_called()
|
||||
Reference in New Issue
Block a user