refactor(audio-rooms): NestsClient API matches nostrnests reality (phase 2/3)

The Phase-1 interop harness exposed a substantial mismatch between our
production HTTP client and what the nostrnests reference server actually
exposes. This commit refactors `:nestsClient` and the wiring above it so
the production code path can talk to a real moq-auth + moq-relay.

| Aspect    | Before                                    | After (matches nostrnests/moq-auth/src/index.ts) |
|-----------|-------------------------------------------|--------------------------------------------------|
| Method    | GET                                       | POST                                             |
| URL       | `<base>/<roomId>`                         | `<base>/auth`                                    |
| Body      | none                                      | `{"namespace":"nests/<kind>:<host>:<roomId>","publish":bool}` |
| Response  | `{endpoint, token, codec, sample_rate}`   | `{token}` only                                   |
| Endpoint  | from response                             | from event's `endpoint` tag (passed via `NestsRoomConfig.endpoint`) |
| NIP-98    | bound to GET URL                          | bound to POST URL + body hash                    |

Type changes:
- New `NestsRoomConfig` data class bundling (authBaseUrl, endpoint,
  hostPubkey, roomId, kind). Built by the caller (UI / VM) from the
  NIP-53 kind 30312 event before invoking connectNests*.
- `NestsRoomConfig.moqNamespace()` produces the exact format
  moq-auth's NAMESPACE_REGEX expects: `nests/<kind>:<hex64>:<roomId>`.
- `NestsRoomInfo` deleted; replaced with a tiny `NestsTokenResponse(token)`
  matching the real response shape.
- `NestsClient.resolveRoom(serviceBase, roomId, signer): NestsRoomInfo`
  → `NestsClient.mintToken(room, publish, signer): String`. The
  publish flag drives the JWT claims (`get` for listeners, `put`
  for speakers).

Wire path:
- `OkHttpNestsClient` now POSTs `<authBase>/auth` with a JSON body
  and a NIP-98 Authorization header bound to (POST, url, body-hash).
- `connectNestsListener` / `connectNestsSpeaker` take `room:
  NestsRoomConfig` instead of split (serviceBase, roomId), pass
  `publish=false` / `publish=true` respectively, and use the room's
  `endpoint` (not a server-returned one) for the WebTransport
  connect. The minted JWT is the bearer token.
- `NestsListenerState.Connected` / `NestsSpeakerState.Connected` /
  `Broadcasting` carry the `room: NestsRoomConfig` instead of the old
  `roomInfo: NestsRoomInfo`.
- MoQ TrackNamespace for the room is now a single segment whose
  bytes are `room.moqNamespace()` — the simplest mapping to the
  relay's JWT claim check (`root: "<namespace>"`); Phase-3 round-trip
  test will confirm and adjust if the relay expects a multi-segment
  tuple.

Wiring above:
- `AudioRoomViewModel` constructor: replaces `(serviceBase, roomId)`
  with `(room: NestsRoomConfig)`. Connector seam interfaces
  (NestsListenerConnector, NestsSpeakerConnector) follow the same
  shape.
- `AudioRoomViewModelFactory` (Android) takes `room: NestsRoomConfig`.
- `AudioRoomActivity` adds `EXTRA_AUTH_BASE_URL`, `EXTRA_ENDPOINT`,
  `EXTRA_HOST_PUBKEY`, `EXTRA_KIND` Intent extras (was just service
  + roomId) and reconstructs `NestsRoomConfig` in onCreate. Drops
  `EXTRA_SERVICE_BASE`.
- `AudioRoomJoinCard` reads `event.endpoint()` + `event.pubKey` +
  `event.kind` in addition to `event.service()`; rooms missing any
  of those are silently un-joinable (the event author didn't host
  on a nests-compatible relay).
- `AudioRoomActivityContent` takes `room: NestsRoomConfig` in place
  of (serviceBase, roomId) and threads it down.

Phase-1 ping test rewired to use the production `OkHttpNestsClient`
end-to-end against the real `/auth`, asserting we get back a
3-segment JWT.

Existing in-process tests updated for the new types: NestsConnectTest,
NestsSpeakerTest, AudioRoomViewModelTest. NestsRoomInfoTest renamed to
NestsRoomConfigTest with new cases for the namespace formatter and the
auth-URL helper. All 80 in-process tests still green.

Phase 3 (next) will add the full round-trip interop test that runs
production `connectNestsListener` + `connectNestsSpeaker` through the
real moq-relay — that's where MoQ wire-format assumptions (draft
revision, OBJECT_DATAGRAM layout, namespace tuple shape) get verified
or get followup audit findings.
This commit is contained in:
Claude
2026-04-26 14:42:26 +00:00
parent 3283d302fa
commit beec8204e5
17 changed files with 353 additions and 318 deletions
@@ -36,10 +36,11 @@ import kotlinx.coroutines.flow.MutableStateFlow
* Walk the full join-as-listener handshake against a nests-compatible audio
* server:
*
* 1. Resolve the room — POST/GET `<serviceBase>/<roomId>` with NIP-98 auth,
* returning [NestsRoomInfo] (the MoQ endpoint + bearer token).
* 1. Mint a JWT — POST `<authBase>/auth` with NIP-98 + namespace body
* (see [NestsClient.mintToken]).
* 2. Open a [com.vitorpamplona.nestsclient.transport.WebTransportSession]
* against the endpoint via [transport].
* against the [room.endpoint] via [transport], passing the JWT as the
* bearer token.
* 3. Run the MoQ SETUP handshake.
*
* The returned [NestsListener] is in state [NestsListenerState.Connected];
@@ -47,7 +48,9 @@ import kotlinx.coroutines.flow.MutableStateFlow
* [NestsListenerState.Failed] with the underlying cause attached and the
* transport torn down.
*
* @param signer NIP-98 signer for the resolveRoom HTTP call.
* @param room per-room config built from the NIP-53 kind 30312 event by
* the caller (UI / VM).
* @param signer NIP-98 signer for the mintToken HTTP call.
* @param scope where the [MoqSession] pumps live (typically the caller's
* ViewModel scope so they cancel when the screen leaves).
* @param supportedMoqVersions in preference order; defaults to draft-17.
@@ -56,8 +59,7 @@ suspend fun connectNestsListener(
httpClient: NestsClient,
transport: WebTransportFactory,
scope: CoroutineScope,
serviceBase: String,
roomId: String,
room: NestsRoomConfig,
signer: NostrSigner,
supportedMoqVersions: List<Long> = listOf(MoqVersion.DRAFT_17),
): NestsListener {
@@ -66,11 +68,11 @@ suspend fun connectNestsListener(
NestsListenerState.Connecting(NestsListenerState.Connecting.ConnectStep.ResolvingRoom),
)
val roomInfo =
val token =
try {
httpClient.resolveRoom(serviceBase = serviceBase, roomId = roomId, signer = signer)
httpClient.mintToken(room = room, publish = false, signer = signer)
} catch (t: NestsException) {
state.value = NestsListenerState.Failed("Room resolution failed: ${t.message}", t)
state.value = NestsListenerState.Failed("Auth failed: ${t.message}", t)
return failedListener(state)
}
@@ -78,11 +80,11 @@ suspend fun connectNestsListener(
val (authority, path) =
try {
parseEndpoint(roomInfo.endpoint)
parseEndpoint(room.endpoint)
} catch (t: Throwable) {
state.value =
NestsListenerState.Failed(
"Malformed MoQ endpoint URL '${roomInfo.endpoint}': ${t.message}",
"Malformed MoQ endpoint URL '${room.endpoint}': ${t.message}",
t,
)
return failedListener(state)
@@ -90,7 +92,7 @@ suspend fun connectNestsListener(
val webTransport =
try {
transport.connect(authority = authority, path = path, bearerToken = roomInfo.token)
transport.connect(authority = authority, path = path, bearerToken = token)
} catch (t: WebTransportException) {
state.value =
NestsListenerState.Failed(
@@ -118,10 +120,15 @@ suspend fun connectNestsListener(
return failedListener(state)
}
state.value = NestsListenerState.Connected(roomInfo, negotiatedVersion)
state.value = NestsListenerState.Connected(room, negotiatedVersion)
return DefaultNestsListener(
session = moq,
roomNamespace = TrackNamespace.of("nests", roomId),
// moq-auth's JWT claim is `root: "<moqNamespace>"` — the simplest
// wire-level mapping is a 1-segment TrackNamespace whose only
// element is that exact string. Phase-3 interop test will
// confirm; if the real relay expects a multi-segment tuple
// (e.g. split on `/` or `:`), adjust here.
roomNamespace = TrackNamespace.of(room.moqNamespace()),
mutableState = state,
)
}
@@ -160,8 +167,7 @@ suspend fun connectNestsSpeaker(
httpClient: NestsClient,
transport: WebTransportFactory,
scope: CoroutineScope,
serviceBase: String,
roomId: String,
room: NestsRoomConfig,
signer: NostrSigner,
speakerPubkeyHex: String,
captureFactory: () -> AudioCapture,
@@ -173,11 +179,11 @@ suspend fun connectNestsSpeaker(
NestsSpeakerState.Connecting(NestsSpeakerState.Connecting.ConnectStep.ResolvingRoom),
)
val roomInfo =
val token =
try {
httpClient.resolveRoom(serviceBase = serviceBase, roomId = roomId, signer = signer)
httpClient.mintToken(room = room, publish = true, signer = signer)
} catch (t: NestsException) {
state.value = NestsSpeakerState.Failed("Room resolution failed: ${t.message}", t)
state.value = NestsSpeakerState.Failed("Auth failed: ${t.message}", t)
return failedSpeaker(state)
}
@@ -185,11 +191,11 @@ suspend fun connectNestsSpeaker(
val (authority, path) =
try {
parseEndpoint(roomInfo.endpoint)
parseEndpoint(room.endpoint)
} catch (t: Throwable) {
state.value =
NestsSpeakerState.Failed(
"Malformed MoQ endpoint URL '${roomInfo.endpoint}': ${t.message}",
"Malformed MoQ endpoint URL '${room.endpoint}': ${t.message}",
t,
)
return failedSpeaker(state)
@@ -197,7 +203,7 @@ suspend fun connectNestsSpeaker(
val webTransport =
try {
transport.connect(authority = authority, path = path, bearerToken = roomInfo.token)
transport.connect(authority = authority, path = path, bearerToken = token)
} catch (t: WebTransportException) {
state.value =
NestsSpeakerState.Failed(
@@ -225,10 +231,11 @@ suspend fun connectNestsSpeaker(
return failedSpeaker(state)
}
state.value = NestsSpeakerState.Connected(roomInfo, negotiatedVersion)
state.value = NestsSpeakerState.Connected(room, negotiatedVersion)
return DefaultNestsSpeaker(
session = moq,
roomNamespace = TrackNamespace.of("nests", roomId),
// Same single-segment shape as the listener path; see comment there.
roomNamespace = TrackNamespace.of(room.moqNamespace()),
speakerTrackName = speakerPubkeyHex.encodeToByteArray(),
captureFactory = captureFactory,
encoderFactory = encoderFactory,