mirror of
https://github.com/suitenumerique/meet.git
synced 2026-07-28 04:39:16 +00:00
59d4c2583b
Fixes "Invalid LiveKit token" errors caused by field mismatch between token generation and authentication lookup. Previously: - generate_token() used user.sub as token identity - LiveKitTokenAuthentication tried to retrieve user via user.id field - This failed when sub was not a UUID (e.g., from LemonLDAP OIDC provider) Now: - generate_token() continues using user.sub (canonical OIDC identifier) - LiveKitTokenAuthentication correctly looks up by sub field - Both sides now consistently use the same field This ensures compatibility with all RFC 7519-compliant OIDC providers, regardless of their sub claim format.
43 lines
1.3 KiB
Python
43 lines
1.3 KiB
Python
"""Authentication using LiveKit token for the Meet core app."""
|
|
|
|
from django.conf import settings
|
|
from django.contrib.auth import get_user_model
|
|
from django.contrib.auth.models import AnonymousUser
|
|
|
|
from livekit.api import TokenVerifier
|
|
from rest_framework import authentication, exceptions
|
|
|
|
UserModel = get_user_model()
|
|
|
|
|
|
class LiveKitTokenAuthentication(authentication.BaseAuthentication):
|
|
"""Authenticate using LiveKit token and load the associated Django user."""
|
|
|
|
def authenticate(self, request):
|
|
token = request.data.get("token")
|
|
if not token:
|
|
return None # No authentication attempted
|
|
|
|
try:
|
|
verifier = TokenVerifier(
|
|
api_key=settings.LIVEKIT_CONFIGURATION["api_key"],
|
|
api_secret=settings.LIVEKIT_CONFIGURATION["api_secret"],
|
|
)
|
|
claims = verifier.verify(token)
|
|
|
|
user_id = claims.identity
|
|
if not user_id:
|
|
raise exceptions.AuthenticationFailed("Token missing user identity")
|
|
|
|
try:
|
|
user = UserModel.objects.get(sub=user_id)
|
|
except UserModel.DoesNotExist:
|
|
user = AnonymousUser()
|
|
|
|
return (user, claims)
|
|
|
|
except Exception as e:
|
|
raise exceptions.AuthenticationFailed(
|
|
f"Invalid LiveKit token: {str(e)}"
|
|
) from e
|