mirror of
https://github.com/suitenumerique/meet.git
synced 2026-09-30 22:48:35 +00:00
002f67ca50
We now use `Authorization: Bearer <token>` to authenticate users from the token exchange flow (used for iframe embeds). Until now, the `Bearer` scheme was also reused for the alternative LiveKit authentication, where a client presents its LiveKit token issued by the backend to prove room membership on actions open to any room participant. Sharing the scheme between the two flows is not viable anymore. Switch the LiveKit token authentication to a dedicated `Authorization` scheme, so `Bearer` stays reserved for the iframe / token-exchange flow. Follow-up: a broader effort should look into harmonizing and hardening the backend authentication stack of the app.