Skip to content

fix: require viewer consent before unmuting on web and desktop - #127

Merged
ralyodio merged 1 commit into
profullstack:masterfrom
phucnguyen1707:fix/web-desktop-microphone-consent
Sep 28, 2026
Merged

ralyodio merged 1 commit into
profullstack:masterfrom
phucnguyen1707:fix/web-desktop-microphone-consent

Conversation

@phucnguyen1707

Copy link
Copy Markdown
Contributor

Summary

  • Apply viewer microphone consent to both website and desktop, for P2P and SFU connections. Remote unmute is a passive request; only the viewer's local mic button enables audio.
  • Preserve muted intent across manual/SDK reconnect in the same hook instance; stop late captures and ignore stale callbacks.
  • Serialize asynchronous microphone operations and flush SDK mute state before a rapid unmute, avoiding an enabled UI with a still-silent track.
  • Use the server-assigned desktop signaling identity for targeted mute messages, and validate malformed/foreign targets.
  • Add viewer status notices and regression coverage without changing native mobile or the existing initial mic-on preference.

Validation

  • Full monorepo test run: 2370 passed (web 1020, desktop 734, shared helpers 99, mobile 314, remote input 166, AI core 37). An additional 34 script tests passed. Unchanged packages reused test results cached earlier in this verification run; the installer test script is a placeholder and is not counted.
  • Real local Chromium checks exercised both actual viewer hooks with synthetic audio, WebRTC data channels and received RTP. A real LiveKit LocalAudioTrack verified the rapid mute/unmute sequence.
  • Full monorepo typechecks and lint passed; 15 pre-existing lint warnings remain outside the changed code. Desktop bundle and Next compile-mode build passed locally (not a complete production deployment).
  • Prettier formatting checked with AST/debug validation, then the full repository format check passed.
  • Claude Opus source cross-review plus focused controller/routing follow-up reviews completed. The final lint-compatible disposal checks have two additional pending-operation regression tests. The reviewer did not run the tests; the counts above are from local verification.

Boundaries before release

  • Chromium checks use mocked IPC/Supabase/SSE and synthetic audio. SFU room lifecycle tests mock the server. This is not a production LiveKit/TURN, WAN, physical-microphone or signed native Electron test.
  • Initial join still requests microphone permission as before; remount/reload is a new join. Muting a P2P track silences outgoing audio, not necessarily the OS microphone indicator.
  • A pending SDK acquisition cannot be silenced before the track is exposed; do not interpret this as a guarantee of zero transient packets.
  • This is not a complete room-authorization audit. Existing server authorization and broader moderation paths are outside this PR and need separate review.
  • See docs/microphone-consent.md. Website deployment and a new desktop release are still required after merge; neither is performed by this PR.

@phucnguyen1707
phucnguyen1707 marked this pull request as ready for review September 28, 2026 08:28
@ralyodio
ralyodio merged commit 2f6b5e4 into profullstack:master Sep 28, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants