voice-limit-guard: live revoke never fired — LiveKit's JSON uses snake_case permissions
livekit-server (verified on 1.13.7) serialises ParticipantPermission as can_publish / can_publish_sources; the reconciler read canPublish / canPublishSources, saw 'publishes nothing' for everyone and never called UpdateParticipant, so turning Allow Screen Sharing off did not stop an in-progress share. Normalise the permission keys before deciding. Verified on a local Synapse + LiveKit + guard stack: share track gone from the SFU 2 s after the policy flip. Tests added (44 pass). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
This commit is contained in:
@@ -399,10 +399,27 @@ def reconcile_publish_sources(current, forbidden: set):
|
||||
return sorted(effective - forbidden)
|
||||
|
||||
|
||||
def _camel(key: str) -> str:
|
||||
head, *rest = key.split("_")
|
||||
return head + "".join(part.capitalize() for part in rest)
|
||||
|
||||
|
||||
def normalize_permission(perm: dict) -> dict:
|
||||
"""LiveKit's Twirp JSON serialises ParticipantPermission with proto field
|
||||
names (`can_publish`, `can_publish_sources`, ...) — verified against
|
||||
livekit-server 1.13 — while the JWT grant and older docs use camelCase.
|
||||
Return a camelCase copy so the policy code reads one shape. (protojson
|
||||
accepts either spelling on input, so the copy we send back is fine.)"""
|
||||
out = {}
|
||||
for key, value in (perm or {}).items():
|
||||
out[_camel(key) if "_" in key else key] = value
|
||||
return out
|
||||
|
||||
|
||||
def reconcile_participant(alias: str, participant: dict, forbidden: set) -> bool:
|
||||
"""Enforce the forbidden-source policy on one live participant. Returns True
|
||||
if an UpdateParticipant call was issued."""
|
||||
perm = participant.get("permission") or {}
|
||||
perm = normalize_permission(participant.get("permission") or {})
|
||||
if not perm.get("canPublish", False):
|
||||
return False # publishes nothing -> nothing to revoke
|
||||
current = perm.get("canPublishSources") or []
|
||||
|
||||
Reference in New Issue
Block a user