mirror of
https://github.com/suitenumerique/meet.git
synced 2026-09-03 14:17:59 +00:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 7e8e98d737 |
@@ -8,16 +8,6 @@ and this project adheres to
|
|||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
### Added
|
|
||||||
|
|
||||||
- ✨(frontend) add 1080p sending resolution option #1660
|
|
||||||
- ✨(backend) add Traefik support via configurable media-auth url header #1649
|
|
||||||
- ✨(backend) update a room's attributes from the external API
|
|
||||||
|
|
||||||
### Fixed
|
|
||||||
|
|
||||||
- 🐛(frontend) keep the sending resolution picked while the camera is off #1667
|
|
||||||
|
|
||||||
## [1.30.0] - 2026-09-01
|
## [1.30.0] - 2026-09-01
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
@@ -65,7 +65,6 @@ RUN apk update && apk upgrade \
|
|||||||
musl \
|
musl \
|
||||||
musl-utils \
|
musl-utils \
|
||||||
zlib>=1.3.2-r0 \
|
zlib>=1.3.2-r0 \
|
||||||
libexpat>=2.8.4-r0 \
|
|
||||||
&& apk del curl
|
&& apk del curl
|
||||||
|
|
||||||
USER nginx
|
USER nginx
|
||||||
|
|||||||
+1
-76
@@ -16,7 +16,7 @@ info:
|
|||||||
* `rooms:list` – List rooms accessible to the delegated user.
|
* `rooms:list` – List rooms accessible to the delegated user.
|
||||||
* `rooms:retrieve` – Retrieve details of a specific room.
|
* `rooms:retrieve` – Retrieve details of a specific room.
|
||||||
* `rooms:create` – Create new rooms.
|
* `rooms:create` – Create new rooms.
|
||||||
* `rooms:update` – Update the access level and configuration of existing rooms.
|
* `rooms:update` – **Coming soon** Update existing rooms, e.g., add attendees to a room.
|
||||||
* `rooms:delete` – **Coming soon** Delete rooms generated by the application.
|
* `rooms:delete` – **Coming soon** Delete rooms generated by the application.
|
||||||
|
|
||||||
#### Upcoming Features
|
#### Upcoming Features
|
||||||
@@ -310,67 +310,6 @@ paths:
|
|||||||
'404':
|
'404':
|
||||||
$ref: '#/components/responses/RoomNotFoundError'
|
$ref: '#/components/responses/RoomNotFoundError'
|
||||||
|
|
||||||
patch:
|
|
||||||
tags:
|
|
||||||
- Rooms
|
|
||||||
summary: Update a room
|
|
||||||
description: |
|
|
||||||
Partially updates a room. Only the delegated user's rooms where they are
|
|
||||||
administrator or owner can be updated; any other role gets a `403`.
|
|
||||||
|
|
||||||
**Updatable fields:** `access_level` and `configuration`. Every other field
|
|
||||||
(`id`, `name`, `slug`, `pin_code`) is read-only and silently ignored when sent.
|
|
||||||
|
|
||||||
`configuration` is replaced as a whole, it is not merged with the stored one.
|
|
||||||
Send the complete object you want the room to end up with.
|
|
||||||
|
|
||||||
Full replacement (`PUT`) is not supported. Use `PATCH` instead.
|
|
||||||
operationId: updateRoom
|
|
||||||
security:
|
|
||||||
- BearerAuth: [rooms:update]
|
|
||||||
parameters:
|
|
||||||
- name: id
|
|
||||||
in: path
|
|
||||||
required: true
|
|
||||||
description: Room UUID
|
|
||||||
schema:
|
|
||||||
type: string
|
|
||||||
format: uuid
|
|
||||||
requestBody:
|
|
||||||
required: true
|
|
||||||
content:
|
|
||||||
application/json:
|
|
||||||
schema:
|
|
||||||
$ref: '#/components/schemas/RoomUpdate'
|
|
||||||
examples:
|
|
||||||
accessLevelOnly:
|
|
||||||
summary: Change the access level
|
|
||||||
value:
|
|
||||||
access_level: "restricted"
|
|
||||||
configurationOnly:
|
|
||||||
summary: Replace the room configuration
|
|
||||||
value:
|
|
||||||
configuration:
|
|
||||||
everyone_can_mute: true
|
|
||||||
responses:
|
|
||||||
'200':
|
|
||||||
description: Room updated successfully
|
|
||||||
content:
|
|
||||||
application/json:
|
|
||||||
schema:
|
|
||||||
$ref: '#/components/schemas/Room'
|
|
||||||
'400':
|
|
||||||
$ref: '#/components/responses/BadRequestError'
|
|
||||||
'401':
|
|
||||||
$ref: '#/components/responses/UnauthorizedError'
|
|
||||||
'403':
|
|
||||||
$ref: '#/components/responses/ForbiddenError'
|
|
||||||
'404':
|
|
||||||
$ref: '#/components/responses/RoomNotFoundError'
|
|
||||||
'405':
|
|
||||||
description: |
|
|
||||||
Method not allowed, `PUT` is not supported on this endpoint.
|
|
||||||
|
|
||||||
components:
|
components:
|
||||||
securitySchemes:
|
securitySchemes:
|
||||||
BearerAuth:
|
BearerAuth:
|
||||||
@@ -447,17 +386,6 @@ components:
|
|||||||
configuration:
|
configuration:
|
||||||
$ref: '#/components/schemas/RoomConfiguration'
|
$ref: '#/components/schemas/RoomConfiguration'
|
||||||
|
|
||||||
RoomUpdate:
|
|
||||||
type: object
|
|
||||||
description: |
|
|
||||||
Fields that can be updated on an existing room. Both are optional, omitted
|
|
||||||
fields keep their current value.
|
|
||||||
properties:
|
|
||||||
access_level:
|
|
||||||
$ref: '#/components/schemas/RoomAccessLevel'
|
|
||||||
configuration:
|
|
||||||
$ref: '#/components/schemas/RoomConfiguration'
|
|
||||||
|
|
||||||
RoomConfiguration:
|
RoomConfiguration:
|
||||||
type: object
|
type: object
|
||||||
description: |
|
description: |
|
||||||
@@ -499,9 +427,6 @@ components:
|
|||||||
- `public`: Anyone with the room link can join directly, no authentication required.
|
- `public`: Anyone with the room link can join directly, no authentication required.
|
||||||
- `trusted`: Authenticated users join directly. Unauthenticated users wait in the lobby for approval.
|
- `trusted`: Authenticated users join directly. Unauthenticated users wait in the lobby for approval.
|
||||||
- `restricted`: Only participants explicitly trusted by the owner bypass the lobby. Everyone else waits for approval regardless of authentication.
|
- `restricted`: Only participants explicitly trusted by the owner bypass the lobby. Everyone else waits for approval regardless of authentication.
|
||||||
|
|
||||||
`public` is rejected with a `400` unless the deployment explicitly enables it
|
|
||||||
for this API. This applies both when creating a room and when updating one.
|
|
||||||
example: "trusted"
|
example: "trusted"
|
||||||
|
|
||||||
Room:
|
Room:
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ info:
|
|||||||
* `lasuite_visio:rooms:list` – List rooms accessible to the delegated user.
|
* `lasuite_visio:rooms:list` – List rooms accessible to the delegated user.
|
||||||
* `lasuite_visio:rooms:retrieve` – Retrieve details of a specific room.
|
* `lasuite_visio:rooms:retrieve` – Retrieve details of a specific room.
|
||||||
* `lasuite_visio:rooms:create` – Create new rooms.
|
* `lasuite_visio:rooms:create` – Create new rooms.
|
||||||
* `lasuite_visio:rooms:update` – Update the access level and configuration of existing rooms.
|
* `lasuite_visio:rooms:update` – **Coming soon** Update existing rooms, e.g., add attendees to a room.
|
||||||
* `lasuite_visio:rooms:delete` – **Coming soon** Delete rooms generated by the application.
|
* `lasuite_visio:rooms:delete` – **Coming soon** Delete rooms generated by the application.
|
||||||
|
|
||||||
#### Upcoming Features
|
#### Upcoming Features
|
||||||
@@ -206,67 +206,6 @@ paths:
|
|||||||
'404':
|
'404':
|
||||||
$ref: '#/components/responses/RoomNotFoundError'
|
$ref: '#/components/responses/RoomNotFoundError'
|
||||||
|
|
||||||
patch:
|
|
||||||
tags:
|
|
||||||
- Rooms
|
|
||||||
summary: Update a room
|
|
||||||
description: |
|
|
||||||
Partially updates a room. Only rooms where the user is administrator or
|
|
||||||
owner can be updated; any other role gets a `403`.
|
|
||||||
|
|
||||||
**Updatable fields:** `access_level` and `configuration`. Every other field
|
|
||||||
(`id`, `name`, `slug`, `pin_code`) is read-only and silently ignored when sent.
|
|
||||||
|
|
||||||
`configuration` is replaced as a whole, it is not merged with the stored one.
|
|
||||||
Send the complete object you want the room to end up with.
|
|
||||||
|
|
||||||
Full replacement (`PUT`) is not supported. Use `PATCH` instead.
|
|
||||||
operationId: updateRoom
|
|
||||||
security:
|
|
||||||
- BearerAuth: [rooms:update]
|
|
||||||
parameters:
|
|
||||||
- name: id
|
|
||||||
in: path
|
|
||||||
required: true
|
|
||||||
description: Room UUID
|
|
||||||
schema:
|
|
||||||
type: string
|
|
||||||
format: uuid
|
|
||||||
requestBody:
|
|
||||||
required: true
|
|
||||||
content:
|
|
||||||
application/json:
|
|
||||||
schema:
|
|
||||||
$ref: '#/components/schemas/RoomUpdate'
|
|
||||||
examples:
|
|
||||||
accessLevelOnly:
|
|
||||||
summary: Change the access level
|
|
||||||
value:
|
|
||||||
access_level: "restricted"
|
|
||||||
configurationOnly:
|
|
||||||
summary: Replace the room configuration
|
|
||||||
value:
|
|
||||||
configuration:
|
|
||||||
everyone_can_mute: true
|
|
||||||
responses:
|
|
||||||
'200':
|
|
||||||
description: Room updated successfully
|
|
||||||
content:
|
|
||||||
application/json:
|
|
||||||
schema:
|
|
||||||
$ref: '#/components/schemas/Room'
|
|
||||||
'400':
|
|
||||||
$ref: '#/components/responses/BadRequestError'
|
|
||||||
'401':
|
|
||||||
$ref: '#/components/responses/UnauthorizedError'
|
|
||||||
'403':
|
|
||||||
$ref: '#/components/responses/ForbiddenError'
|
|
||||||
'404':
|
|
||||||
$ref: '#/components/responses/RoomNotFoundError'
|
|
||||||
'405':
|
|
||||||
description: |
|
|
||||||
Method not allowed, `PUT` is not supported on this endpoint.
|
|
||||||
|
|
||||||
components:
|
components:
|
||||||
securitySchemes:
|
securitySchemes:
|
||||||
BearerAuth:
|
BearerAuth:
|
||||||
@@ -288,17 +227,6 @@ components:
|
|||||||
configuration:
|
configuration:
|
||||||
$ref: '#/components/schemas/RoomConfiguration'
|
$ref: '#/components/schemas/RoomConfiguration'
|
||||||
|
|
||||||
RoomUpdate:
|
|
||||||
type: object
|
|
||||||
description: |
|
|
||||||
Fields that can be updated on an existing room. Both are optional, omitted
|
|
||||||
fields keep their current value.
|
|
||||||
properties:
|
|
||||||
access_level:
|
|
||||||
$ref: '#/components/schemas/RoomAccessLevel'
|
|
||||||
configuration:
|
|
||||||
$ref: '#/components/schemas/RoomConfiguration'
|
|
||||||
|
|
||||||
RoomConfiguration:
|
RoomConfiguration:
|
||||||
type: object
|
type: object
|
||||||
description: |
|
description: |
|
||||||
@@ -340,9 +268,6 @@ components:
|
|||||||
- `public`: Anyone with the room link can join directly, no authentication required.
|
- `public`: Anyone with the room link can join directly, no authentication required.
|
||||||
- `trusted`: Authenticated users join directly. Unauthenticated users wait in the lobby for approval.
|
- `trusted`: Authenticated users join directly. Unauthenticated users wait in the lobby for approval.
|
||||||
- `restricted`: Only participants explicitly trusted by the owner bypass the lobby. Everyone else waits for approval regardless of authentication.
|
- `restricted`: Only participants explicitly trusted by the owner bypass the lobby. Everyone else waits for approval regardless of authentication.
|
||||||
|
|
||||||
`public` is rejected with a `400` unless the deployment explicitly enables it
|
|
||||||
for this API. This applies both when creating a room and when updating one.
|
|
||||||
example: "trusted"
|
example: "trusted"
|
||||||
|
|
||||||
Room:
|
Room:
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ class AnalyticsEvent(StrEnum):
|
|||||||
|
|
||||||
# Rooms
|
# Rooms
|
||||||
ROOM_CREATED = "room_created"
|
ROOM_CREATED = "room_created"
|
||||||
ROOM_UPDATED = "room_updated"
|
|
||||||
|
|
||||||
# Roomkit (meeting-room SIP devices)
|
# Roomkit (meeting-room SIP devices)
|
||||||
ROOMKIT_JOINED = "roomkit_joined"
|
ROOMKIT_JOINED = "roomkit_joined"
|
||||||
|
|||||||
@@ -75,7 +75,11 @@ from core.services.participants_management import (
|
|||||||
ParticipantsManagementException,
|
ParticipantsManagementException,
|
||||||
)
|
)
|
||||||
from core.services.room_creation import RoomCreation
|
from core.services.room_creation import RoomCreation
|
||||||
from core.services.room_management import RoomManagement
|
from core.services.room_management import (
|
||||||
|
RoomManagement,
|
||||||
|
RoomManagementException,
|
||||||
|
RoomNotFoundException,
|
||||||
|
)
|
||||||
from core.services.room_roles import (
|
from core.services.room_roles import (
|
||||||
RoomRoleError,
|
RoomRoleError,
|
||||||
RoomRoleService,
|
RoomRoleService,
|
||||||
@@ -352,7 +356,26 @@ class RoomViewSet(
|
|||||||
):
|
):
|
||||||
return
|
return
|
||||||
|
|
||||||
RoomManagement.sync_room_metadata(room)
|
metadata = {
|
||||||
|
"configuration": room.configuration,
|
||||||
|
"access_level": room.access_level,
|
||||||
|
}
|
||||||
|
|
||||||
|
try:
|
||||||
|
RoomManagement().update_metadata(
|
||||||
|
room_name=str(room.id),
|
||||||
|
metadata=metadata,
|
||||||
|
)
|
||||||
|
except RoomNotFoundException:
|
||||||
|
logger.info(
|
||||||
|
"LiveKit room %s does not exist yet, skipping metadata sync",
|
||||||
|
room.id,
|
||||||
|
)
|
||||||
|
except RoomManagementException:
|
||||||
|
logger.warning(
|
||||||
|
"Failed to sync metadata to LiveKit for room %s",
|
||||||
|
room.id,
|
||||||
|
)
|
||||||
|
|
||||||
@decorators.action(
|
@decorators.action(
|
||||||
detail=True,
|
detail=True,
|
||||||
@@ -1053,10 +1076,9 @@ class RecordingViewSet(
|
|||||||
|
|
||||||
def _auth_get_original_url(self, request):
|
def _auth_get_original_url(self, request):
|
||||||
"""
|
"""
|
||||||
Extracts and parses the original URL from the configured header.
|
Extracts and parses the original URL from the "HTTP_X_ORIGINAL_URL" header.
|
||||||
Raises PermissionDenied if the header is missing.
|
Raises PermissionDenied if the header is missing.
|
||||||
The original url is passed by the reverse proxy in the header named by the
|
The original url is passed by nginx in the "HTTP_X_ORIGINAL_URL" header.
|
||||||
MEDIA_AUTH_ORIGINAL_URL_HEADER setting, which defaults to "HTTP_X_ORIGINAL_URL".
|
|
||||||
See corresponding ingress configuration in Helm chart and read about the
|
See corresponding ingress configuration in Helm chart and read about the
|
||||||
nginx.ingress.kubernetes.io/auth-url annotation to understand how the Nginx ingress
|
nginx.ingress.kubernetes.io/auth-url annotation to understand how the Nginx ingress
|
||||||
is configured to do this.
|
is configured to do this.
|
||||||
@@ -1066,13 +1088,9 @@ class RecordingViewSet(
|
|||||||
reasons.
|
reasons.
|
||||||
"""
|
"""
|
||||||
# Extract the original URL from the request header
|
# Extract the original URL from the request header
|
||||||
original_url = request.META.get(settings.MEDIA_AUTH_ORIGINAL_URL_HEADER)
|
original_url = request.META.get("HTTP_X_ORIGINAL_URL")
|
||||||
if not original_url:
|
if not original_url:
|
||||||
logger.warning(
|
logger.warning("Missing HTTP_X_ORIGINAL_URL header in subrequest")
|
||||||
"Missing %s header in subrequest. Set MEDIA_AUTH_ORIGINAL_URL_HEADER "
|
|
||||||
"to the header your reverse proxy sends.",
|
|
||||||
settings.MEDIA_AUTH_ORIGINAL_URL_HEADER,
|
|
||||||
)
|
|
||||||
raise drf_exceptions.PermissionDenied()
|
raise drf_exceptions.PermissionDenied()
|
||||||
|
|
||||||
logger.debug("Original url: '%s'", original_url)
|
logger.debug("Original url: '%s'", original_url)
|
||||||
@@ -1397,8 +1415,7 @@ class FileViewSet(
|
|||||||
Authorize access based on the original URL of an Nginx subrequest
|
Authorize access based on the original URL of an Nginx subrequest
|
||||||
and user permissions. Returns a dictionary of URL parameters if authorized.
|
and user permissions. Returns a dictionary of URL parameters if authorized.
|
||||||
|
|
||||||
The original url is passed by the reverse proxy in the header named by the
|
The original url is passed by nginx in the "HTTP_X_ORIGINAL_URL" header.
|
||||||
MEDIA_AUTH_ORIGINAL_URL_HEADER setting, which defaults to "HTTP_X_ORIGINAL_URL".
|
|
||||||
See corresponding ingress configuration in Helm chart and read about the
|
See corresponding ingress configuration in Helm chart and read about the
|
||||||
nginx.ingress.kubernetes.io/auth-url annotation to understand how the Nginx ingress
|
nginx.ingress.kubernetes.io/auth-url annotation to understand how the Nginx ingress
|
||||||
is configured to do this.
|
is configured to do this.
|
||||||
@@ -1417,13 +1434,9 @@ class FileViewSet(
|
|||||||
- PermissionDenied if authorization fails.
|
- PermissionDenied if authorization fails.
|
||||||
"""
|
"""
|
||||||
# Extract the original URL from the request header
|
# Extract the original URL from the request header
|
||||||
original_url = request.META.get(settings.MEDIA_AUTH_ORIGINAL_URL_HEADER)
|
original_url = request.META.get("HTTP_X_ORIGINAL_URL")
|
||||||
if not original_url:
|
if not original_url:
|
||||||
logger.warning(
|
logger.warning("Missing HTTP_X_ORIGINAL_URL header in subrequest")
|
||||||
"Missing %s header in subrequest. Set MEDIA_AUTH_ORIGINAL_URL_HEADER "
|
|
||||||
"to the header your reverse proxy sends.",
|
|
||||||
settings.MEDIA_AUTH_ORIGINAL_URL_HEADER,
|
|
||||||
)
|
|
||||||
raise drf_exceptions.PermissionDenied()
|
raise drf_exceptions.PermissionDenied()
|
||||||
|
|
||||||
parsed_url = urlparse(original_url)
|
parsed_url = urlparse(original_url)
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
"""External API endpoints"""
|
"""External API endpoints"""
|
||||||
|
|
||||||
import copy
|
|
||||||
from logging import getLogger
|
from logging import getLogger
|
||||||
|
|
||||||
from django.conf import settings
|
from django.conf import settings
|
||||||
@@ -26,7 +25,6 @@ from rest_framework import (
|
|||||||
from core import analytics, api, models
|
from core import analytics, api, models
|
||||||
from core.api.feature_flag import FeatureFlag
|
from core.api.feature_flag import FeatureFlag
|
||||||
from core.services.jwt_token import JwtTokenService
|
from core.services.jwt_token import JwtTokenService
|
||||||
from core.services.room_management import RoomManagement
|
|
||||||
|
|
||||||
from ..services.provisional_user_service import (
|
from ..services.provisional_user_service import (
|
||||||
ProvisionalUserCreationDisabledError,
|
ProvisionalUserCreationDisabledError,
|
||||||
@@ -144,7 +142,6 @@ class RoomViewSet(
|
|||||||
mixins.CreateModelMixin,
|
mixins.CreateModelMixin,
|
||||||
mixins.RetrieveModelMixin,
|
mixins.RetrieveModelMixin,
|
||||||
mixins.ListModelMixin,
|
mixins.ListModelMixin,
|
||||||
mixins.UpdateModelMixin,
|
|
||||||
viewsets.GenericViewSet,
|
viewsets.GenericViewSet,
|
||||||
):
|
):
|
||||||
"""Application-delegated API for room management.
|
"""Application-delegated API for room management.
|
||||||
@@ -157,12 +154,8 @@ class RoomViewSet(
|
|||||||
- list: List rooms the user has access to (requires 'rooms:list' scope)
|
- list: List rooms the user has access to (requires 'rooms:list' scope)
|
||||||
- retrieve: Get room details (requires 'rooms:retrieve' scope)
|
- retrieve: Get room details (requires 'rooms:retrieve' scope)
|
||||||
- create: Create a new room owned by the user (requires 'rooms:create' scope)
|
- create: Create a new room owned by the user (requires 'rooms:create' scope)
|
||||||
- partial_update: Update a room's access level and configuration, for
|
|
||||||
administrators and owners only (requires 'rooms:update' scope)
|
|
||||||
"""
|
"""
|
||||||
|
|
||||||
http_method_names = ["get", "post", "patch", "head", "options"]
|
|
||||||
|
|
||||||
authentication_classes = [
|
authentication_classes = [
|
||||||
authentication.ApplicationJWTAuthentication,
|
authentication.ApplicationJWTAuthentication,
|
||||||
authentication.AddonsJWTAuthentication,
|
authentication.AddonsJWTAuthentication,
|
||||||
@@ -196,39 +189,7 @@ class RoomViewSet(
|
|||||||
serializer = self.get_serializer(queryset, many=True)
|
serializer = self.get_serializer(queryset, many=True)
|
||||||
return drf_response.Response(serializer.data)
|
return drf_response.Response(serializer.data)
|
||||||
|
|
||||||
def _track_room_event(self, room, event, **extra_properties):
|
def perform_create(self, serializer):
|
||||||
"""Log a room operation for auditing and forward it to analytics."""
|
|
||||||
|
|
||||||
auth_method = type(self.request.successful_authenticator).__name__
|
|
||||||
client_id = (self.request.auth or {}).get("client_id", "unknown")
|
|
||||||
|
|
||||||
# Log for auditing
|
|
||||||
details = "".join(f", {key}={value}" for key, value in extra_properties.items())
|
|
||||||
logger.info(
|
|
||||||
"Room %s via application: room_id=%s, user_id=%s, client_id=%s, auth_method=%s%s",
|
|
||||||
event.removeprefix("room_"),
|
|
||||||
room.id,
|
|
||||||
self.request.user.id,
|
|
||||||
client_id,
|
|
||||||
auth_method,
|
|
||||||
details,
|
|
||||||
)
|
|
||||||
|
|
||||||
analytics.capture(
|
|
||||||
self.request.user,
|
|
||||||
event,
|
|
||||||
{
|
|
||||||
"room_id": str(room.pk),
|
|
||||||
"access_level": room.access_level,
|
|
||||||
"client_id": client_id,
|
|
||||||
"external_api": True,
|
|
||||||
"auth_method": auth_method,
|
|
||||||
**extra_properties,
|
|
||||||
"$set": {"email": self.request.user.email},
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|
||||||
def perform_create(self, serializer: serializers.RoomSerializer):
|
|
||||||
"""Set the current user as owner of the newly created room."""
|
"""Set the current user as owner of the newly created room."""
|
||||||
room = serializer.save()
|
room = serializer.save()
|
||||||
models.ResourceAccess.objects.create(
|
models.ResourceAccess.objects.create(
|
||||||
@@ -237,31 +198,27 @@ class RoomViewSet(
|
|||||||
role=models.RoleChoices.OWNER,
|
role=models.RoleChoices.OWNER,
|
||||||
)
|
)
|
||||||
|
|
||||||
self._track_room_event(room, analytics.AnalyticsEvent.ROOM_CREATED)
|
auth_method = type(self.request.successful_authenticator).__name__
|
||||||
|
client_id = (self.request.auth or {}).get("client_id", "unknown")
|
||||||
|
|
||||||
def perform_update(self, serializer: serializers.RoomSerializer):
|
# Log for auditing
|
||||||
"""Persist the room update, sync it to LiveKit, then log and track it."""
|
logger.info(
|
||||||
|
"Room created via application: room_id=%s, user_id=%s, client_id=%s, auth_method=%s",
|
||||||
previous_values = {
|
room.id,
|
||||||
"access_level": serializer.instance.access_level,
|
self.request.user.id,
|
||||||
"configuration": copy.deepcopy(serializer.instance.configuration),
|
client_id,
|
||||||
}
|
auth_method,
|
||||||
|
|
||||||
room = serializer.save()
|
|
||||||
|
|
||||||
# Report the fields that actually changed, not the ones that were submitted.
|
|
||||||
updated_fields = sorted(
|
|
||||||
field
|
|
||||||
for field, previous_value in previous_values.items()
|
|
||||||
if getattr(room, field) != previous_value
|
|
||||||
)
|
)
|
||||||
|
|
||||||
if updated_fields:
|
analytics.capture(
|
||||||
RoomManagement.sync_room_metadata(room)
|
self.request.user,
|
||||||
|
analytics.AnalyticsEvent.ROOM_CREATED,
|
||||||
self._track_room_event(
|
{
|
||||||
room,
|
"room_id": str(room.pk),
|
||||||
analytics.AnalyticsEvent.ROOM_UPDATED,
|
"access_level": room.access_level,
|
||||||
updated_fields=updated_fields,
|
"client_id": client_id,
|
||||||
previous_access_level=previous_values["access_level"],
|
"external_api": True,
|
||||||
|
"auth_method": auth_method,
|
||||||
|
"$set": {"email": self.request.user.email},
|
||||||
|
},
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -48,6 +48,8 @@ class ResourceFactory(factory.django.DjangoModelFactory):
|
|||||||
else:
|
else:
|
||||||
UserResourceAccessFactory(resource=self, user=item[0], role=item[1])
|
UserResourceAccessFactory(resource=self, user=item[0], role=item[1])
|
||||||
|
|
||||||
|
self.save()
|
||||||
|
|
||||||
|
|
||||||
class UserResourceAccessFactory(factory.django.DjangoModelFactory):
|
class UserResourceAccessFactory(factory.django.DjangoModelFactory):
|
||||||
"""Create fake resource user accesses for testing."""
|
"""Create fake resource user accesses for testing."""
|
||||||
@@ -95,6 +97,8 @@ class RecordingFactory(factory.django.DjangoModelFactory):
|
|||||||
recording=self, user=item[0], role=item[1]
|
recording=self, user=item[0], role=item[1]
|
||||||
)
|
)
|
||||||
|
|
||||||
|
self.save()
|
||||||
|
|
||||||
|
|
||||||
class UserRecordingAccessFactory(factory.django.DjangoModelFactory):
|
class UserRecordingAccessFactory(factory.django.DjangoModelFactory):
|
||||||
"""Create fake recording user accesses for testing."""
|
"""Create fake recording user accesses for testing."""
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ class RecordingEventsService:
|
|||||||
recording_status = status_mapping.get(egress_status)
|
recording_status = status_mapping.get(egress_status)
|
||||||
if recording_status:
|
if recording_status:
|
||||||
try:
|
try:
|
||||||
RoomManagement.update_metadata(
|
RoomManagement().update_metadata(
|
||||||
room_name, {"recording_status": recording_status}
|
room_name, {"recording_status": recording_status}
|
||||||
)
|
)
|
||||||
except RoomNotFoundException:
|
except RoomNotFoundException:
|
||||||
|
|||||||
@@ -68,7 +68,7 @@ class WorkerServiceMediator:
|
|||||||
mode = recording.options.get("original_mode", None) or recording.mode
|
mode = recording.options.get("original_mode", None) or recording.mode
|
||||||
|
|
||||||
try:
|
try:
|
||||||
RoomManagement.update_metadata(
|
RoomManagement().update_metadata(
|
||||||
room_name, {"recording_mode": mode, "recording_status": "starting"}
|
room_name, {"recording_mode": mode, "recording_status": "starting"}
|
||||||
)
|
)
|
||||||
except RoomNotFoundException:
|
except RoomNotFoundException:
|
||||||
|
|||||||
@@ -192,7 +192,7 @@ class LiveKitEventsService:
|
|||||||
|
|
||||||
try:
|
try:
|
||||||
room_name = str(recording.room.id)
|
room_name = str(recording.room.id)
|
||||||
RoomManagement.update_metadata(
|
RoomManagement().update_metadata(
|
||||||
room_name, remove_keys=["recording_mode", "recording_status"]
|
room_name, remove_keys=["recording_mode", "recording_status"]
|
||||||
)
|
)
|
||||||
except RoomNotFoundException:
|
except RoomNotFoundException:
|
||||||
|
|||||||
@@ -30,10 +30,9 @@ class RoomNotFoundException(RoomManagementException):
|
|||||||
class RoomManagement:
|
class RoomManagement:
|
||||||
"""Service for managing LiveKit rooms."""
|
"""Service for managing LiveKit rooms."""
|
||||||
|
|
||||||
@classmethod
|
|
||||||
@async_to_sync
|
@async_to_sync
|
||||||
async def update_metadata(
|
async def update_metadata(
|
||||||
cls,
|
self,
|
||||||
room_name: str,
|
room_name: str,
|
||||||
metadata: Optional[Dict] = None,
|
metadata: Optional[Dict] = None,
|
||||||
remove_keys: Optional[list[str]] = None,
|
remove_keys: Optional[list[str]] = None,
|
||||||
@@ -91,9 +90,8 @@ class RoomManagement:
|
|||||||
finally:
|
finally:
|
||||||
await lkapi.aclose()
|
await lkapi.aclose()
|
||||||
|
|
||||||
@classmethod
|
|
||||||
@async_to_sync
|
@async_to_sync
|
||||||
async def delete_room(cls, room_name: str):
|
async def delete_room(self, room_name: str):
|
||||||
"""Delete a LiveKit room and disconnect all participants.
|
"""Delete a LiveKit room and disconnect all participants.
|
||||||
|
|
||||||
Raises:
|
Raises:
|
||||||
@@ -118,32 +116,3 @@ class RoomManagement:
|
|||||||
raise RoomManagementException("Could not delete room") from e
|
raise RoomManagementException("Could not delete room") from e
|
||||||
finally:
|
finally:
|
||||||
await lkapi.aclose()
|
await lkapi.aclose()
|
||||||
|
|
||||||
@classmethod
|
|
||||||
def sync_room_metadata(cls, room):
|
|
||||||
"""Push a room's configuration and access level to its LiveKit room metadata.
|
|
||||||
|
|
||||||
Failures are swallowed: a room that is not live yet, or a LiveKit hiccup,
|
|
||||||
should never fail the request that triggered the update.
|
|
||||||
"""
|
|
||||||
|
|
||||||
metadata = {
|
|
||||||
"configuration": room.configuration,
|
|
||||||
"access_level": room.access_level,
|
|
||||||
}
|
|
||||||
|
|
||||||
try:
|
|
||||||
cls.update_metadata(
|
|
||||||
room_name=str(room.id),
|
|
||||||
metadata=metadata,
|
|
||||||
)
|
|
||||||
except RoomNotFoundException:
|
|
||||||
logger.info(
|
|
||||||
"LiveKit room %s does not exist yet, skipping metadata sync",
|
|
||||||
room.id,
|
|
||||||
)
|
|
||||||
except RoomManagementException:
|
|
||||||
logger.warning(
|
|
||||||
"Failed to sync metadata to LiveKit for room %s",
|
|
||||||
room.id,
|
|
||||||
)
|
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ def delete_connection_test_room(room_name: str):
|
|||||||
return
|
return
|
||||||
|
|
||||||
try:
|
try:
|
||||||
RoomManagement.delete_room(room_name)
|
RoomManagement().delete_room(room_name)
|
||||||
except RoomNotFoundException:
|
except RoomNotFoundException:
|
||||||
# Room may already be gone after empty/departure timeout.
|
# Room may already be gone after empty/departure timeout.
|
||||||
logger.info("Connection test room '%s' already gone.", room_name)
|
logger.info("Connection test room '%s' already gone.", room_name)
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ from urllib.parse import quote, urlparse
|
|||||||
|
|
||||||
from django.conf import settings
|
from django.conf import settings
|
||||||
from django.core.files.storage import default_storage
|
from django.core.files.storage import default_storage
|
||||||
from django.test import override_settings
|
|
||||||
from django.utils import timezone
|
from django.utils import timezone
|
||||||
|
|
||||||
import pytest
|
import pytest
|
||||||
@@ -144,59 +143,3 @@ def test_api_files_media_auth_own_file_deleted():
|
|||||||
)
|
)
|
||||||
|
|
||||||
assert response.status_code == 403
|
assert response.status_code == 403
|
||||||
|
|
||||||
|
|
||||||
@override_settings(MEDIA_AUTH_ORIGINAL_URL_HEADER="HTTP_X_FORWARDED_URI")
|
|
||||||
def test_api_files_media_auth_custom_original_url_header():
|
|
||||||
"""
|
|
||||||
Authorization should honour the configured original-url header.
|
|
||||||
|
|
||||||
Covers the attachment subrequest path, which resolves the header separately
|
|
||||||
from the recording one. Reverse proxies other than nginx-ingress use
|
|
||||||
different headers: Traefik's ForwardAuth sends X-Forwarded-Uri and cannot
|
|
||||||
emit X-Original-URL at all.
|
|
||||||
"""
|
|
||||||
user = factories.UserFactory()
|
|
||||||
|
|
||||||
file = factories.FileFactory(
|
|
||||||
type=models.FileTypeChoices.BACKGROUND_IMAGE,
|
|
||||||
update_upload_state=models.FileUploadStateChoices.READY,
|
|
||||||
creator=user,
|
|
||||||
)
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.force_login(user)
|
|
||||||
|
|
||||||
default_storage.save(file.file_key, BytesIO(b"my prose"))
|
|
||||||
|
|
||||||
original_url = f"http://localhost/media/{file.file_key:s}"
|
|
||||||
response = client.get(
|
|
||||||
"/api/v1.0/files/media-auth/", HTTP_X_FORWARDED_URI=original_url
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
assert "AWS4-HMAC-SHA256 Credential=" in response["Authorization"]
|
|
||||||
|
|
||||||
|
|
||||||
@override_settings(MEDIA_AUTH_ORIGINAL_URL_HEADER="HTTP_X_FORWARDED_URI")
|
|
||||||
def test_api_files_media_auth_default_header_ignored_when_reconfigured():
|
|
||||||
"""
|
|
||||||
Only the configured header should be honoured, never a hardcoded fallback.
|
|
||||||
"""
|
|
||||||
user = factories.UserFactory()
|
|
||||||
|
|
||||||
file = factories.FileFactory(
|
|
||||||
type=models.FileTypeChoices.BACKGROUND_IMAGE,
|
|
||||||
update_upload_state=models.FileUploadStateChoices.READY,
|
|
||||||
creator=user,
|
|
||||||
)
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.force_login(user)
|
|
||||||
|
|
||||||
original_url = f"http://localhost/media/{file.file_key:s}"
|
|
||||||
response = client.get(
|
|
||||||
"/api/v1.0/files/media-auth/", HTTP_X_ORIGINAL_URL=original_url
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 403
|
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ from uuid import uuid4
|
|||||||
|
|
||||||
from django.conf import settings
|
from django.conf import settings
|
||||||
from django.core.files.storage import default_storage
|
from django.core.files.storage import default_storage
|
||||||
from django.test import override_settings
|
|
||||||
from django.utils import timezone
|
from django.utils import timezone
|
||||||
|
|
||||||
import pytest
|
import pytest
|
||||||
@@ -283,63 +282,3 @@ def test_api_recordings_media_auth_success_administrator(mode):
|
|||||||
timeout=1,
|
timeout=1,
|
||||||
)
|
)
|
||||||
assert response.content.decode("utf-8") == "my prose"
|
assert response.content.decode("utf-8") == "my prose"
|
||||||
|
|
||||||
|
|
||||||
def test_api_recordings_media_auth_missing_header():
|
|
||||||
"""
|
|
||||||
Test that a subrequest without the configured original-url header is rejected.
|
|
||||||
"""
|
|
||||||
user = UserFactory()
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.force_login(user)
|
|
||||||
|
|
||||||
response = client.get("/api/v1.0/recordings/media-auth/")
|
|
||||||
|
|
||||||
assert response.status_code == 403
|
|
||||||
|
|
||||||
|
|
||||||
@override_settings(MEDIA_AUTH_ORIGINAL_URL_HEADER="HTTP_X_FORWARDED_URI")
|
|
||||||
def test_api_recordings_media_auth_custom_original_url_header():
|
|
||||||
"""
|
|
||||||
Test that the header carrying the original URL can be configured.
|
|
||||||
|
|
||||||
Reverse proxies other than nginx-ingress use different headers: Traefik's
|
|
||||||
ForwardAuth sends X-Forwarded-Uri and cannot emit X-Original-URL at all.
|
|
||||||
"""
|
|
||||||
user = UserFactory()
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.force_login(user)
|
|
||||||
|
|
||||||
original_url = f"http://localhost/media/recordings/{uuid4()!s}.mp4"
|
|
||||||
|
|
||||||
response = client.get(
|
|
||||||
"/api/v1.0/recordings/media-auth/", HTTP_X_FORWARDED_URI=original_url
|
|
||||||
)
|
|
||||||
|
|
||||||
# The header was read and parsed: we get as far as looking the recording up,
|
|
||||||
# rather than being rejected for a missing header.
|
|
||||||
assert response.status_code == 404
|
|
||||||
|
|
||||||
|
|
||||||
@override_settings(MEDIA_AUTH_ORIGINAL_URL_HEADER="HTTP_X_FORWARDED_URI")
|
|
||||||
def test_api_recordings_media_auth_default_header_ignored_when_reconfigured():
|
|
||||||
"""
|
|
||||||
Test that only the configured header is honoured.
|
|
||||||
|
|
||||||
Guards against the header being read from a hardcoded name in parallel with
|
|
||||||
the setting.
|
|
||||||
"""
|
|
||||||
user = UserFactory()
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.force_login(user)
|
|
||||||
|
|
||||||
original_url = f"http://localhost/media/recordings/{uuid4()!s}.mp4"
|
|
||||||
|
|
||||||
response = client.get(
|
|
||||||
"/api/v1.0/recordings/media-auth/", HTTP_X_ORIGINAL_URL=original_url
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 403
|
|
||||||
|
|||||||
@@ -381,11 +381,38 @@ def test_api_rooms_update_administrators_of_another():
|
|||||||
assert other_room.slug == "old-name"
|
assert other_room.slug == "old-name"
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize("exception", [RoomNotFoundException, RoomManagementException])
|
@patch.object(RoomManagement, "update_metadata", side_effect=RoomNotFoundException)
|
||||||
@patch.object(RoomManagement, "update_metadata")
|
def test_api_rooms_update_livekit_room_not_found(mock_update_metadata):
|
||||||
def test_api_rooms_update_livekit_sync_failure(mock_update_metadata, exception):
|
"""Should not fail the API request when the LiveKit room does not exist yet."""
|
||||||
"""Should not fail the API request when the LiveKit metadata sync fails."""
|
user = UserFactory()
|
||||||
mock_update_metadata.side_effect = exception
|
room = RoomFactory(
|
||||||
|
users=[(user, random.choice(["administrator", "owner"]))],
|
||||||
|
configuration={},
|
||||||
|
)
|
||||||
|
client = APIClient()
|
||||||
|
client.force_login(user)
|
||||||
|
|
||||||
|
response = client.patch(
|
||||||
|
f"/api/v1.0/rooms/{room.id!s}/",
|
||||||
|
{"configuration": {"can_publish_sources": ["camera"]}},
|
||||||
|
format="json",
|
||||||
|
)
|
||||||
|
assert response.status_code == 200
|
||||||
|
room.refresh_from_db()
|
||||||
|
assert room.configuration == {"can_publish_sources": ["camera"]}
|
||||||
|
|
||||||
|
mock_update_metadata.assert_called_once_with(
|
||||||
|
room_name=str(room.id),
|
||||||
|
metadata={
|
||||||
|
"access_level": room.access_level,
|
||||||
|
"configuration": {"can_publish_sources": ["camera"]},
|
||||||
|
},
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
@patch.object(RoomManagement, "update_metadata", side_effect=RoomManagementException)
|
||||||
|
def test_api_rooms_update_livekit_sync_failure(mock_update_metadata):
|
||||||
|
"""Should not fail the API request when the LiveKit metadata sync fails."""
|
||||||
user = UserFactory()
|
user = UserFactory()
|
||||||
room = RoomFactory(
|
room = RoomFactory(
|
||||||
users=[(user, random.choice(["administrator", "owner"]))],
|
users=[(user, random.choice(["administrator", "owner"]))],
|
||||||
|
|||||||
@@ -5,8 +5,6 @@ from unittest import mock
|
|||||||
import pytest
|
import pytest
|
||||||
from livekit.api import TwirpError
|
from livekit.api import TwirpError
|
||||||
|
|
||||||
from core.factories import RoomFactory
|
|
||||||
from core.models import RoomAccessLevel
|
|
||||||
from core.services.room_management import (
|
from core.services.room_management import (
|
||||||
RoomManagement,
|
RoomManagement,
|
||||||
RoomManagementException,
|
RoomManagementException,
|
||||||
@@ -22,7 +20,7 @@ def test_delete_room_calls_livekit(mock_create_livekit_client):
|
|||||||
mock_api.aclose = mock.AsyncMock()
|
mock_api.aclose = mock.AsyncMock()
|
||||||
mock_create_livekit_client.return_value = mock_api
|
mock_create_livekit_client.return_value = mock_api
|
||||||
|
|
||||||
RoomManagement.delete_room("room-abc")
|
RoomManagement().delete_room("room-abc")
|
||||||
|
|
||||||
mock_api.room.delete_room.assert_awaited_once()
|
mock_api.room.delete_room.assert_awaited_once()
|
||||||
request = mock_api.room.delete_room.await_args.args[0]
|
request = mock_api.room.delete_room.await_args.args[0]
|
||||||
@@ -41,7 +39,7 @@ def test_delete_room_raises_not_found(mock_create_livekit_client):
|
|||||||
mock_create_livekit_client.return_value = mock_api
|
mock_create_livekit_client.return_value = mock_api
|
||||||
|
|
||||||
with pytest.raises(RoomNotFoundException):
|
with pytest.raises(RoomNotFoundException):
|
||||||
RoomManagement.delete_room("missing-room")
|
RoomManagement().delete_room("missing-room")
|
||||||
|
|
||||||
mock_api.aclose.assert_awaited_once()
|
mock_api.aclose.assert_awaited_once()
|
||||||
|
|
||||||
@@ -57,25 +55,6 @@ def test_delete_room_raises_management_exception(mock_create_livekit_client):
|
|||||||
mock_create_livekit_client.return_value = mock_api
|
mock_create_livekit_client.return_value = mock_api
|
||||||
|
|
||||||
with pytest.raises(RoomManagementException):
|
with pytest.raises(RoomManagementException):
|
||||||
RoomManagement.delete_room("room-abc")
|
RoomManagement().delete_room("room-abc")
|
||||||
|
|
||||||
mock_api.aclose.assert_awaited_once()
|
mock_api.aclose.assert_awaited_once()
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_sync_room_metadata_pushes_configuration_and_access_level(mock_update_metadata):
|
|
||||||
"""The room's configuration and access level are forwarded to LiveKit."""
|
|
||||||
room = RoomFactory.build(
|
|
||||||
access_level=RoomAccessLevel.RESTRICTED,
|
|
||||||
configuration={"everyone_can_mute": True},
|
|
||||||
)
|
|
||||||
|
|
||||||
RoomManagement.sync_room_metadata(room)
|
|
||||||
|
|
||||||
mock_update_metadata.assert_called_once_with(
|
|
||||||
room_name=str(room.id),
|
|
||||||
metadata={
|
|
||||||
"configuration": {"everyone_can_mute": True},
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|||||||
@@ -16,17 +16,8 @@ import responses
|
|||||||
from lasuite.oidc_resource_server.authentication import ResourceServerAuthentication
|
from lasuite.oidc_resource_server.authentication import ResourceServerAuthentication
|
||||||
from rest_framework.test import APIClient
|
from rest_framework.test import APIClient
|
||||||
|
|
||||||
from core.analytics import AnalyticsEvent
|
|
||||||
from core.factories import ApplicationFactory, RoomFactory, UserFactory
|
from core.factories import ApplicationFactory, RoomFactory, UserFactory
|
||||||
from core.models import (
|
from core.models import ApplicationScope, RoleChoices, Room, RoomAccessLevel, User
|
||||||
Application,
|
|
||||||
ApplicationScope,
|
|
||||||
RoleChoices,
|
|
||||||
Room,
|
|
||||||
RoomAccessLevel,
|
|
||||||
User,
|
|
||||||
)
|
|
||||||
from core.services.room_management import RoomManagement
|
|
||||||
|
|
||||||
pytestmark = pytest.mark.django_db
|
pytestmark = pytest.mark.django_db
|
||||||
|
|
||||||
@@ -889,509 +880,6 @@ def test_api_rooms_create_public_access_level_when_default_is_public(settings):
|
|||||||
assert response.data["access_level"] == RoomAccessLevel.PUBLIC
|
assert response.data["access_level"] == RoomAccessLevel.PUBLIC
|
||||||
|
|
||||||
|
|
||||||
@mock.patch("core.external_api.viewsets.analytics.capture")
|
|
||||||
def test_api_rooms_create_tracks_analytics(mock_capture):
|
|
||||||
"""Creating a room should emit a ROOM_CREATED analytics event."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_CREATE])
|
|
||||||
application = Application.objects.get()
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.post(
|
|
||||||
"/external-api/v1.0/rooms/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 201
|
|
||||||
|
|
||||||
mock_capture.assert_called_once()
|
|
||||||
captured_user, event, properties = mock_capture.call_args[0]
|
|
||||||
|
|
||||||
assert captured_user == user
|
|
||||||
assert event == AnalyticsEvent.ROOM_CREATED
|
|
||||||
assert properties == {
|
|
||||||
"room_id": response.data["id"],
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
"client_id": str(application.client_id),
|
|
||||||
"external_api": True,
|
|
||||||
"auth_method": "ApplicationJWTAuthentication",
|
|
||||||
"$set": {"email": user.email},
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
def test_api_rooms_update_requires_authentication():
|
|
||||||
"""Updating a room without authentication should return 401."""
|
|
||||||
|
|
||||||
room = RoomFactory(users=[(UserFactory(), RoleChoices.OWNER)])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 401
|
|
||||||
|
|
||||||
|
|
||||||
def test_api_rooms_update_requires_scope():
|
|
||||||
"""Updating a room requires the ROOMS_UPDATE scope."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(users=[(user, RoleChoices.OWNER)])
|
|
||||||
|
|
||||||
# Token without ROOMS_UPDATE scope
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_RETRIEVE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 403
|
|
||||||
assert (
|
|
||||||
"insufficient permissions. required scope: rooms:update"
|
|
||||||
in str(response.data).lower()
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
def test_api_rooms_update_no_scope():
|
|
||||||
"""Updating a room without any scope should return 403."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(users=[(user, RoleChoices.OWNER)])
|
|
||||||
|
|
||||||
token = generate_test_token(user, [])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 403
|
|
||||||
assert "insufficient permissions." in str(response.data).lower()
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_owner_success(mock_update_metadata, settings):
|
|
||||||
"""An owner should be able to update the access level and the configuration."""
|
|
||||||
|
|
||||||
settings.APPLICATION_BASE_URL = "http://your-application.com"
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
configuration={},
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
"configuration": {"everyone_can_mute": True},
|
|
||||||
},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
assert response.data["id"] == str(room.id)
|
|
||||||
assert response.data["access_level"] == RoomAccessLevel.RESTRICTED
|
|
||||||
assert response.data["configuration"] == {"everyone_can_mute": True}
|
|
||||||
assert response.data["url"] == f"http://your-application.com/{room.slug}"
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.RESTRICTED
|
|
||||||
assert room.configuration == {"everyone_can_mute": True}
|
|
||||||
|
|
||||||
mock_update_metadata.assert_called_once_with(
|
|
||||||
room_name=str(room.id),
|
|
||||||
metadata={
|
|
||||||
"configuration": {"everyone_can_mute": True},
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_replaces_configuration(mock_update_metadata):
|
|
||||||
"""The configuration is replaced as a whole, it is not merged with the stored one."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
configuration={"can_publish_sources": ["camera"], "everyone_can_mute": True},
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"configuration": {"everyone_can_mute": False}},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
|
|
||||||
# The keys missing from the payload are dropped, not kept.
|
|
||||||
assert response.data["configuration"] == {"everyone_can_mute": False}
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.configuration == {"everyone_can_mute": False}
|
|
||||||
|
|
||||||
mock_update_metadata.assert_called_once_with(
|
|
||||||
room_name=str(room.id),
|
|
||||||
metadata={
|
|
||||||
"configuration": {"everyone_can_mute": False},
|
|
||||||
"access_level": room.access_level,
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_administrator_success(mock_update_metadata):
|
|
||||||
"""An administrator should be able to update a room."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.ADMIN)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.RESTRICTED
|
|
||||||
mock_update_metadata.assert_called_once()
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_put_not_allowed(mock_update_metadata):
|
|
||||||
"""PUT is not exposed: full replacement is not supported, only PATCH is."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
configuration={},
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.put(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
"configuration": {"everyone_can_mute": True},
|
|
||||||
},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 405
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.TRUSTED
|
|
||||||
assert room.configuration == {}
|
|
||||||
mock_update_metadata.assert_not_called()
|
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize("role", [RoleChoices.MEMBER, None])
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_without_privileges(mock_update_metadata, role):
|
|
||||||
"""Members and users without any role should not be able to update a room."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
users = [(user, role)] if role else []
|
|
||||||
room = RoomFactory(users=users, access_level=RoomAccessLevel.TRUSTED)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 403
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.TRUSTED
|
|
||||||
mock_update_metadata.assert_not_called()
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_readonly_enforcement(mock_update_metadata):
|
|
||||||
"""Read-only fields provided on update should be ignored, the slug stays immutable."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
)
|
|
||||||
expected_id, expected_name = str(room.id), room.name
|
|
||||||
expected_slug, expected_pin_code = room.slug, room.pin_code
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{
|
|
||||||
"id": str(uuid.uuid4()),
|
|
||||||
"name": "fake-name",
|
|
||||||
"slug": "fake-slug",
|
|
||||||
"pin_code": "000000",
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
assert response.data["id"] == expected_id
|
|
||||||
assert response.data["name"] == expected_name
|
|
||||||
assert response.data["slug"] == expected_slug
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert str(room.id) == expected_id
|
|
||||||
assert room.name == expected_name
|
|
||||||
assert room.slug == expected_slug
|
|
||||||
assert room.pin_code == expected_pin_code
|
|
||||||
|
|
||||||
# The one writable field in the payload was applied
|
|
||||||
assert room.access_level == RoomAccessLevel.RESTRICTED
|
|
||||||
mock_update_metadata.assert_called_once()
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_rejects_invalid_configuration(mock_update_metadata):
|
|
||||||
"""Updating a room with unsupported configuration keys should fail."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(users=[(user, RoleChoices.OWNER)], configuration={})
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"configuration": {"unsupported_flag": True}},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 400
|
|
||||||
assert "extra inputs are not permitted" in str(response.data).lower()
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.configuration == {}
|
|
||||||
mock_update_metadata.assert_not_called()
|
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize(
|
|
||||||
"invalid_configuration",
|
|
||||||
[
|
|
||||||
{"can_publish_sources": ["invalid-source"]},
|
|
||||||
{"everyone_can_mute": "invalid-value"},
|
|
||||||
],
|
|
||||||
)
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_rejects_invalid_configuration_values(
|
|
||||||
mock_update_metadata, invalid_configuration
|
|
||||||
):
|
|
||||||
"""Updating a room with invalid configuration values should fail."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(users=[(user, RoleChoices.OWNER)], configuration={})
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"configuration": invalid_configuration},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 400
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.configuration == {}
|
|
||||||
mock_update_metadata.assert_not_called()
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_public_access_disabled_by_default(mock_update_metadata):
|
|
||||||
"""Switching a room to public should be disabled for the external API by default."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.PUBLIC},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 400
|
|
||||||
assert "public rooms are disabled" in str(response.data).lower()
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.TRUSTED
|
|
||||||
mock_update_metadata.assert_not_called()
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_public_access_enabled_with_settings(
|
|
||||||
mock_update_metadata, settings
|
|
||||||
):
|
|
||||||
"""Switching a room to public should be allowed when explicitly enabled."""
|
|
||||||
|
|
||||||
settings.EXTERNAL_API_ALLOW_PUBLIC_ACCESS = True
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.PUBLIC},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
assert response.data["access_level"] == RoomAccessLevel.PUBLIC
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.PUBLIC
|
|
||||||
mock_update_metadata.assert_called_once()
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch("core.external_api.viewsets.analytics.capture")
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_unchanged_skips_livekit_sync(
|
|
||||||
mock_update_metadata, mock_capture
|
|
||||||
):
|
|
||||||
"""An update that changes nothing should not sync metadata nor report changes."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
configuration={"everyone_can_mute": True},
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{
|
|
||||||
"access_level": RoomAccessLevel.TRUSTED,
|
|
||||||
"configuration": {"everyone_can_mute": True},
|
|
||||||
},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
mock_update_metadata.assert_not_called()
|
|
||||||
|
|
||||||
# The event is still emitted for auditing, but reports an empty delta.
|
|
||||||
_, _, properties = mock_capture.call_args[0]
|
|
||||||
assert properties["updated_fields"] == []
|
|
||||||
|
|
||||||
|
|
||||||
@mock.patch("core.external_api.viewsets.analytics.capture")
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_tracks_analytics(mock_update_metadata, mock_capture):
|
|
||||||
"""Updating a room should emit a ROOM_UPDATED analytics event."""
|
|
||||||
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
configuration={},
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
application = Application.objects.get()
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
"configuration": {"everyone_can_mute": True},
|
|
||||||
},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
|
|
||||||
mock_capture.assert_called_once()
|
|
||||||
captured_user, event, properties = mock_capture.call_args[0]
|
|
||||||
|
|
||||||
assert captured_user == user
|
|
||||||
assert event == AnalyticsEvent.ROOM_UPDATED
|
|
||||||
assert properties == {
|
|
||||||
"room_id": str(room.pk),
|
|
||||||
"access_level": RoomAccessLevel.RESTRICTED,
|
|
||||||
"updated_fields": ["access_level", "configuration"],
|
|
||||||
"previous_access_level": RoomAccessLevel.TRUSTED,
|
|
||||||
"client_id": str(application.client_id),
|
|
||||||
"external_api": True,
|
|
||||||
"auth_method": "ApplicationJWTAuthentication",
|
|
||||||
"$set": {"email": user.email},
|
|
||||||
}
|
|
||||||
|
|
||||||
mock_update_metadata.assert_called_once()
|
|
||||||
|
|
||||||
|
|
||||||
def test_api_rooms_response_no_url(settings):
|
def test_api_rooms_response_no_url(settings):
|
||||||
"""Response should not include url field when APPLICATION_BASE_URL is None."""
|
"""Response should not include url field when APPLICATION_BASE_URL is None."""
|
||||||
settings.APPLICATION_BASE_URL = None
|
settings.APPLICATION_BASE_URL = None
|
||||||
@@ -2009,106 +1497,6 @@ def test_resource_server_denies_access_with_insufficient_scopes(settings):
|
|||||||
assert response.status_code == 403
|
assert response.status_code == 403
|
||||||
|
|
||||||
|
|
||||||
@responses.activate
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_resource_server_updates_room_with_prefixed_scope(
|
|
||||||
mock_update_metadata, settings
|
|
||||||
):
|
|
||||||
"""A resource server token carrying the prefixed update scope should be accepted."""
|
|
||||||
|
|
||||||
user = UserFactory(sub="very-specific-sub")
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
)
|
|
||||||
|
|
||||||
settings.OIDC_RS_CLIENT_ID = "some_client_id"
|
|
||||||
settings.OIDC_RS_CLIENT_SECRET = "some_client_secret"
|
|
||||||
settings.OIDC_RS_SCOPES_PREFIX = "lasuite_meet"
|
|
||||||
|
|
||||||
settings.OIDC_OP_URL = "https://oidc.example.com"
|
|
||||||
settings.OIDC_VERIFY_SSL = False
|
|
||||||
settings.OIDC_TIMEOUT = 5
|
|
||||||
settings.OIDC_PROXY = None
|
|
||||||
settings.OIDC_OP_JWKS_ENDPOINT = "https://oidc.example.com/jwks"
|
|
||||||
settings.OIDC_OP_INTROSPECTION_ENDPOINT = "https://oidc.example.com/introspect"
|
|
||||||
|
|
||||||
responses.add(
|
|
||||||
responses.POST,
|
|
||||||
"https://oidc.example.com/introspect",
|
|
||||||
json={
|
|
||||||
"iss": "https://oidc.example.com",
|
|
||||||
"aud": "some_client_id", # settings.OIDC_RS_CLIENT_ID
|
|
||||||
"sub": "very-specific-sub",
|
|
||||||
"client_id": "some_service_provider",
|
|
||||||
"scope": "openid lasuite_meet lasuite_meet:rooms:update",
|
|
||||||
"active": True,
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION="Bearer some_token")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.RESTRICTED
|
|
||||||
mock_update_metadata.assert_called_once()
|
|
||||||
|
|
||||||
|
|
||||||
@responses.activate
|
|
||||||
def test_resource_server_denies_room_update_without_update_scope(settings):
|
|
||||||
"""A resource server token without the update scope should be denied."""
|
|
||||||
|
|
||||||
user = UserFactory(sub="very-specific-sub")
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
)
|
|
||||||
|
|
||||||
settings.OIDC_RS_CLIENT_ID = "some_client_id"
|
|
||||||
settings.OIDC_RS_CLIENT_SECRET = "some_client_secret"
|
|
||||||
settings.OIDC_RS_SCOPES_PREFIX = "lasuite_meet"
|
|
||||||
|
|
||||||
settings.OIDC_OP_URL = "https://oidc.example.com"
|
|
||||||
settings.OIDC_VERIFY_SSL = False
|
|
||||||
settings.OIDC_TIMEOUT = 5
|
|
||||||
settings.OIDC_PROXY = None
|
|
||||||
settings.OIDC_OP_JWKS_ENDPOINT = "https://oidc.example.com/jwks"
|
|
||||||
settings.OIDC_OP_INTROSPECTION_ENDPOINT = "https://oidc.example.com/introspect"
|
|
||||||
|
|
||||||
responses.add(
|
|
||||||
responses.POST,
|
|
||||||
"https://oidc.example.com/introspect",
|
|
||||||
json={
|
|
||||||
"iss": "https://oidc.example.com",
|
|
||||||
"aud": "some_client_id", # settings.OIDC_RS_CLIENT_ID
|
|
||||||
"sub": "very-specific-sub",
|
|
||||||
"client_id": "some_service_provider",
|
|
||||||
"scope": "openid lasuite_meet lasuite_meet:rooms:retrieve",
|
|
||||||
"active": True,
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION="Bearer some_token")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 403
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.TRUSTED
|
|
||||||
|
|
||||||
|
|
||||||
# ==============================
|
# ==============================
|
||||||
# Addons
|
# Addons
|
||||||
# ==============================
|
# ==============================
|
||||||
@@ -2160,32 +1548,6 @@ def test_api_rooms_create_with_valid_addons_token():
|
|||||||
assert room.get_role(user) == RoleChoices.OWNER
|
assert room.get_role(user) == RoleChoices.OWNER
|
||||||
|
|
||||||
|
|
||||||
@mock.patch.object(RoomManagement, "update_metadata")
|
|
||||||
def test_api_rooms_update_with_valid_addons_token(mock_update_metadata):
|
|
||||||
"""Updating a room with a valid addons token should succeed."""
|
|
||||||
user = UserFactory()
|
|
||||||
room = RoomFactory(
|
|
||||||
users=[(user, RoleChoices.OWNER)],
|
|
||||||
access_level=RoomAccessLevel.TRUSTED,
|
|
||||||
)
|
|
||||||
|
|
||||||
token = generate_addons_test_token(user, [ApplicationScope.ROOMS_UPDATE])
|
|
||||||
|
|
||||||
client = APIClient()
|
|
||||||
client.credentials(HTTP_AUTHORIZATION=f"Bearer {token}")
|
|
||||||
response = client.patch(
|
|
||||||
f"/external-api/v1.0/rooms/{room.id}/",
|
|
||||||
{"access_level": RoomAccessLevel.RESTRICTED},
|
|
||||||
format="json",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert response.status_code == 200
|
|
||||||
|
|
||||||
room.refresh_from_db()
|
|
||||||
assert room.access_level == RoomAccessLevel.RESTRICTED
|
|
||||||
mock_update_metadata.assert_called_once()
|
|
||||||
|
|
||||||
|
|
||||||
def test_api_rooms_addons_token_inactive_user():
|
def test_api_rooms_addons_token_inactive_user():
|
||||||
"""Addons token for an inactive user should return 401."""
|
"""Addons token for an inactive user should return 401."""
|
||||||
user = UserFactory(is_active=False)
|
user = UserFactory(is_active=False)
|
||||||
|
|||||||
@@ -129,15 +129,6 @@ class Base(Configuration):
|
|||||||
MEDIA_BASE_URL = values.Value(
|
MEDIA_BASE_URL = values.Value(
|
||||||
"", environ_name="MEDIA_BASE_URL", environ_prefix=None
|
"", environ_name="MEDIA_BASE_URL", environ_prefix=None
|
||||||
)
|
)
|
||||||
# Header the reverse proxy uses to pass the original request URL to the
|
|
||||||
# media-auth subrequest views. nginx-ingress sends X-Original-URL, which is
|
|
||||||
# the default. Other proxies use different headers -- Traefik's ForwardAuth,
|
|
||||||
# for instance, sends X-Forwarded-Uri and cannot emit X-Original-URL at all.
|
|
||||||
MEDIA_AUTH_ORIGINAL_URL_HEADER = values.Value(
|
|
||||||
default="HTTP_X_ORIGINAL_URL",
|
|
||||||
environ_name="MEDIA_AUTH_ORIGINAL_URL_HEADER",
|
|
||||||
environ_prefix=None,
|
|
||||||
)
|
|
||||||
|
|
||||||
SITE_ID = 1
|
SITE_ID = 1
|
||||||
|
|
||||||
|
|||||||
@@ -53,7 +53,6 @@ RUN apk update && apk upgrade \
|
|||||||
musl \
|
musl \
|
||||||
musl-utils \
|
musl-utils \
|
||||||
zlib>=1.3.2-r0 \
|
zlib>=1.3.2-r0 \
|
||||||
libexpat>=2.8.4-r0 \
|
|
||||||
&& apk del curl
|
&& apk del curl
|
||||||
|
|
||||||
USER nginx
|
USER nginx
|
||||||
|
|||||||
+2
-6
@@ -2,7 +2,7 @@ import { useTranslation } from 'react-i18next'
|
|||||||
import { useTrackToggle, UseTrackToggleProps } from '@livekit/components-react'
|
import { useTrackToggle, UseTrackToggleProps } from '@livekit/components-react'
|
||||||
import { Button, Popover } from '@/primitives'
|
import { Button, Popover } from '@/primitives'
|
||||||
import { RiArrowUpSLine, RiImageCircleAiFill } from '@remixicon/react'
|
import { RiArrowUpSLine, RiImageCircleAiFill } from '@remixicon/react'
|
||||||
import { Track, type VideoCaptureOptions, VideoPresets } from 'livekit-client'
|
import { Track, type VideoCaptureOptions } from 'livekit-client'
|
||||||
|
|
||||||
import { ToggleDevice } from './ToggleDevice'
|
import { ToggleDevice } from './ToggleDevice'
|
||||||
import { css } from '@/styled-system/css'
|
import { css } from '@/styled-system/css'
|
||||||
@@ -57,8 +57,7 @@ export const VideoDeviceControl = ({
|
|||||||
}: VideoDeviceControlProps) => {
|
}: VideoDeviceControlProps) => {
|
||||||
const { t } = useTranslation('rooms', { keyPrefix: 'selectDevice' })
|
const { t } = useTranslation('rooms', { keyPrefix: 'selectDevice' })
|
||||||
|
|
||||||
const { videoDeviceId, processorConfig, videoPublishResolution } =
|
const { videoDeviceId, processorConfig } = useSnapshot(userChoicesStore)
|
||||||
useSnapshot(userChoicesStore)
|
|
||||||
|
|
||||||
const onChange = React.useCallback(
|
const onChange = React.useCallback(
|
||||||
(enabled: boolean, isUserInitiated: boolean) =>
|
(enabled: boolean, isUserInitiated: boolean) =>
|
||||||
@@ -98,9 +97,6 @@ export const VideoDeviceControl = ({
|
|||||||
|
|
||||||
await toggle(!trackProps.enabled, {
|
await toggle(!trackProps.enabled, {
|
||||||
processor: processor,
|
processor: processor,
|
||||||
...(videoPublishResolution && {
|
|
||||||
resolution: VideoPresets[videoPublishResolution].resolution,
|
|
||||||
}),
|
|
||||||
} as VideoCaptureOptions)
|
} as VideoCaptureOptions)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -18,7 +18,6 @@ import {
|
|||||||
saveVideoPublishResolution,
|
saveVideoPublishResolution,
|
||||||
saveVideoSubscribeQuality,
|
saveVideoSubscribeQuality,
|
||||||
userChoicesStore,
|
userChoicesStore,
|
||||||
VIDEO_RESOLUTIONS,
|
|
||||||
VideoResolution,
|
VideoResolution,
|
||||||
} from '@/stores/userChoices'
|
} from '@/stores/userChoices'
|
||||||
import { RowWrapper } from './layout/RowWrapper'
|
import { RowWrapper } from './layout/RowWrapper'
|
||||||
@@ -33,8 +32,7 @@ const EMPTY_PROPS = {}
|
|||||||
|
|
||||||
export const VideoTab = ({ id }: VideoTabProps) => {
|
export const VideoTab = ({ id }: VideoTabProps) => {
|
||||||
const { t } = useTranslation('settings', { keyPrefix: 'video' })
|
const { t } = useTranslation('settings', { keyPrefix: 'video' })
|
||||||
const room = useRoomContext()
|
const { localParticipant, remoteParticipants } = useRoomContext()
|
||||||
const { localParticipant, remoteParticipants } = room
|
|
||||||
|
|
||||||
const {
|
const {
|
||||||
videoDeviceId,
|
videoDeviceId,
|
||||||
@@ -71,15 +69,13 @@ export const VideoTab = ({ id }: VideoTabProps) => {
|
|||||||
isDisabled: true,
|
isDisabled: true,
|
||||||
}
|
}
|
||||||
|
|
||||||
const handleVideoResolutionChange = async (key: VideoResolution) => {
|
const handleVideoResolutionChange = async (key: 'h720' | 'h360' | 'h180') => {
|
||||||
saveVideoPublishResolution(key)
|
const videoPublication = localParticipant.getTrackPublication(
|
||||||
const videoTrack = localParticipant.getTrackPublication(
|
|
||||||
Track.Source.Camera
|
Track.Source.Camera
|
||||||
)?.track
|
)
|
||||||
if (!videoTrack) {
|
const videoTrack = videoPublication?.track
|
||||||
return
|
if (videoTrack) {
|
||||||
}
|
saveVideoPublishResolution(key)
|
||||||
|
|
||||||
await videoTrack.restartTrack({
|
await videoTrack.restartTrack({
|
||||||
resolution: VideoPresets[key].resolution,
|
resolution: VideoPresets[key].resolution,
|
||||||
deviceId: { exact: videoDeviceId },
|
deviceId: { exact: videoDeviceId },
|
||||||
@@ -87,6 +83,7 @@ export const VideoTab = ({ id }: VideoTabProps) => {
|
|||||||
BackgroundProcessorFactory.fromProcessorConfig(processorConfig),
|
BackgroundProcessorFactory.fromProcessorConfig(processorConfig),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Updates video quality for all existing remote video tracks when user preference changes.
|
* Updates video quality for all existing remote video tracks when user preference changes.
|
||||||
@@ -125,13 +122,20 @@ export const VideoTab = ({ id }: VideoTabProps) => {
|
|||||||
}, [videoDeviceId, videoElement])
|
}, [videoDeviceId, videoElement])
|
||||||
|
|
||||||
const resolutionItems = useMemo(() => {
|
const resolutionItems = useMemo(() => {
|
||||||
const labels: Record<VideoResolution, string> = {
|
return [
|
||||||
h1080: `${t('resolution.publish.items.veryHigh')} (1080p)`,
|
{
|
||||||
h720: `${t('resolution.publish.items.high')} (720p)`,
|
value: 'h720',
|
||||||
h360: `${t('resolution.publish.items.medium')} (360p)`,
|
label: `${t('resolution.publish.items.high')} (720p)`,
|
||||||
h180: `${t('resolution.publish.items.low')} (180p)`,
|
},
|
||||||
}
|
{
|
||||||
return VIDEO_RESOLUTIONS.map((value) => ({ value, label: labels[value] }))
|
value: 'h360',
|
||||||
|
label: `${t('resolution.publish.items.medium')} (360p)`,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
value: 'h180',
|
||||||
|
label: `${t('resolution.publish.items.low')} (180p)`,
|
||||||
|
},
|
||||||
|
]
|
||||||
}, [t])
|
}, [t])
|
||||||
|
|
||||||
const videoQualityItems = useMemo(() => {
|
const videoQualityItems = useMemo(() => {
|
||||||
|
|||||||
@@ -56,7 +56,6 @@
|
|||||||
"publish": {
|
"publish": {
|
||||||
"label": "Wähle die maximale Auflösung beim Senden",
|
"label": "Wähle die maximale Auflösung beim Senden",
|
||||||
"items": {
|
"items": {
|
||||||
"veryHigh": "Sehr hohe Auflösung",
|
|
||||||
"high": "Hohe Auflösung",
|
"high": "Hohe Auflösung",
|
||||||
"medium": "Mittlere Auflösung",
|
"medium": "Mittlere Auflösung",
|
||||||
"low": "Niedrige Auflösung"
|
"low": "Niedrige Auflösung"
|
||||||
|
|||||||
@@ -56,7 +56,6 @@
|
|||||||
"publish": {
|
"publish": {
|
||||||
"label": "Select your sending resolution (max.)",
|
"label": "Select your sending resolution (max.)",
|
||||||
"items": {
|
"items": {
|
||||||
"veryHigh": "Very high definition",
|
|
||||||
"high": "High definition",
|
"high": "High definition",
|
||||||
"medium": "Standard definition",
|
"medium": "Standard definition",
|
||||||
"low": "Low definition"
|
"low": "Low definition"
|
||||||
|
|||||||
@@ -56,7 +56,6 @@
|
|||||||
"publish": {
|
"publish": {
|
||||||
"label": "Selecciona tu resolución de envío (máx.)",
|
"label": "Selecciona tu resolución de envío (máx.)",
|
||||||
"items": {
|
"items": {
|
||||||
"veryHigh": "Muy alta definición",
|
|
||||||
"high": "Alta definición",
|
"high": "Alta definición",
|
||||||
"medium": "Definición estándar",
|
"medium": "Definición estándar",
|
||||||
"low": "Baja definición"
|
"low": "Baja definición"
|
||||||
|
|||||||
@@ -56,7 +56,6 @@
|
|||||||
"publish": {
|
"publish": {
|
||||||
"label": "Sélectionner votre résolution d'envoi (max.)",
|
"label": "Sélectionner votre résolution d'envoi (max.)",
|
||||||
"items": {
|
"items": {
|
||||||
"veryHigh": "Très haute définition",
|
|
||||||
"high": "Haute définition",
|
"high": "Haute définition",
|
||||||
"medium": "Définition standard",
|
"medium": "Définition standard",
|
||||||
"low": "Basse définition"
|
"low": "Basse définition"
|
||||||
|
|||||||
@@ -56,7 +56,6 @@
|
|||||||
"publish": {
|
"publish": {
|
||||||
"label": "Selecteer uw verzendresolutie (max.)",
|
"label": "Selecteer uw verzendresolutie (max.)",
|
||||||
"items": {
|
"items": {
|
||||||
"veryHigh": "Zeer hoge definitie",
|
|
||||||
"high": "Hoge definitie",
|
"high": "Hoge definitie",
|
||||||
"medium": "Standaarddefinitie",
|
"medium": "Standaarddefinitie",
|
||||||
"low": "Lage definitie"
|
"low": "Lage definitie"
|
||||||
|
|||||||
@@ -10,12 +10,7 @@ import {
|
|||||||
} from '@livekit/components-core'
|
} from '@livekit/components-core'
|
||||||
import { VideoQuality } from 'livekit-client'
|
import { VideoQuality } from 'livekit-client'
|
||||||
|
|
||||||
export const VIDEO_RESOLUTIONS = ['h1080', 'h720', 'h360', 'h180'] as const
|
export type VideoResolution = 'h720' | 'h360' | 'h180'
|
||||||
|
|
||||||
export type VideoResolution = (typeof VIDEO_RESOLUTIONS)[number]
|
|
||||||
|
|
||||||
const isVideoResolution = (value: unknown): value is VideoResolution =>
|
|
||||||
VIDEO_RESOLUTIONS.includes(value as VideoResolution)
|
|
||||||
|
|
||||||
export type LocalUserChoices = Omit<LocalUserChoicesLK, 'username'> & {
|
export type LocalUserChoices = Omit<LocalUserChoicesLK, 'username'> & {
|
||||||
processorConfig?: ProcessorConfig
|
processorConfig?: ProcessorConfig
|
||||||
@@ -26,17 +21,13 @@ export type LocalUserChoices = Omit<LocalUserChoicesLK, 'username'> & {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function getUserChoicesState(): LocalUserChoices {
|
function getUserChoicesState(): LocalUserChoices {
|
||||||
const stored: LocalUserChoices = {
|
return {
|
||||||
noiseReductionEnabled: false,
|
noiseReductionEnabled: false,
|
||||||
audioOutputDeviceId: 'default', // Use 'default' to match LiveKit's standard device selection behavior
|
audioOutputDeviceId: 'default', // Use 'default' to match LiveKit's standard device selection behavior
|
||||||
videoPublishResolution: 'h720',
|
videoPublishResolution: 'h720',
|
||||||
videoSubscribeQuality: VideoQuality.HIGH,
|
videoSubscribeQuality: VideoQuality.HIGH,
|
||||||
...loadUserChoices(),
|
...loadUserChoices(),
|
||||||
}
|
}
|
||||||
if (!isVideoResolution(stored.videoPublishResolution)) {
|
|
||||||
stored.videoPublishResolution = 'h720'
|
|
||||||
}
|
|
||||||
return stored
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export const userChoicesStore = proxy<LocalUserChoices>(getUserChoicesState())
|
export const userChoicesStore = proxy<LocalUserChoices>(getUserChoicesState())
|
||||||
|
|||||||
Reference in New Issue
Block a user