beec8204e5
The Phase-1 interop harness exposed a substantial mismatch between our
production HTTP client and what the nostrnests reference server actually
exposes. This commit refactors `:nestsClient` and the wiring above it so
the production code path can talk to a real moq-auth + moq-relay.
| Aspect | Before | After (matches nostrnests/moq-auth/src/index.ts) |
|-----------|-------------------------------------------|--------------------------------------------------|
| Method | GET | POST |
| URL | `<base>/<roomId>` | `<base>/auth` |
| Body | none | `{"namespace":"nests/<kind>:<host>:<roomId>","publish":bool}` |
| Response | `{endpoint, token, codec, sample_rate}` | `{token}` only |
| Endpoint | from response | from event's `endpoint` tag (passed via `NestsRoomConfig.endpoint`) |
| NIP-98 | bound to GET URL | bound to POST URL + body hash |
Type changes:
- New `NestsRoomConfig` data class bundling (authBaseUrl, endpoint,
hostPubkey, roomId, kind). Built by the caller (UI / VM) from the
NIP-53 kind 30312 event before invoking connectNests*.
- `NestsRoomConfig.moqNamespace()` produces the exact format
moq-auth's NAMESPACE_REGEX expects: `nests/<kind>:<hex64>:<roomId>`.
- `NestsRoomInfo` deleted; replaced with a tiny `NestsTokenResponse(token)`
matching the real response shape.
- `NestsClient.resolveRoom(serviceBase, roomId, signer): NestsRoomInfo`
→ `NestsClient.mintToken(room, publish, signer): String`. The
publish flag drives the JWT claims (`get` for listeners, `put`
for speakers).
Wire path:
- `OkHttpNestsClient` now POSTs `<authBase>/auth` with a JSON body
and a NIP-98 Authorization header bound to (POST, url, body-hash).
- `connectNestsListener` / `connectNestsSpeaker` take `room:
NestsRoomConfig` instead of split (serviceBase, roomId), pass
`publish=false` / `publish=true` respectively, and use the room's
`endpoint` (not a server-returned one) for the WebTransport
connect. The minted JWT is the bearer token.
- `NestsListenerState.Connected` / `NestsSpeakerState.Connected` /
`Broadcasting` carry the `room: NestsRoomConfig` instead of the old
`roomInfo: NestsRoomInfo`.
- MoQ TrackNamespace for the room is now a single segment whose
bytes are `room.moqNamespace()` — the simplest mapping to the
relay's JWT claim check (`root: "<namespace>"`); Phase-3 round-trip
test will confirm and adjust if the relay expects a multi-segment
tuple.
Wiring above:
- `AudioRoomViewModel` constructor: replaces `(serviceBase, roomId)`
with `(room: NestsRoomConfig)`. Connector seam interfaces
(NestsListenerConnector, NestsSpeakerConnector) follow the same
shape.
- `AudioRoomViewModelFactory` (Android) takes `room: NestsRoomConfig`.
- `AudioRoomActivity` adds `EXTRA_AUTH_BASE_URL`, `EXTRA_ENDPOINT`,
`EXTRA_HOST_PUBKEY`, `EXTRA_KIND` Intent extras (was just service
+ roomId) and reconstructs `NestsRoomConfig` in onCreate. Drops
`EXTRA_SERVICE_BASE`.
- `AudioRoomJoinCard` reads `event.endpoint()` + `event.pubKey` +
`event.kind` in addition to `event.service()`; rooms missing any
of those are silently un-joinable (the event author didn't host
on a nests-compatible relay).
- `AudioRoomActivityContent` takes `room: NestsRoomConfig` in place
of (serviceBase, roomId) and threads it down.
Phase-1 ping test rewired to use the production `OkHttpNestsClient`
end-to-end against the real `/auth`, asserting we get back a
3-segment JWT.
Existing in-process tests updated for the new types: NestsConnectTest,
NestsSpeakerTest, AudioRoomViewModelTest. NestsRoomInfoTest renamed to
NestsRoomConfigTest with new cases for the namespace formatter and the
auth-URL helper. All 80 in-process tests still green.
Phase 3 (next) will add the full round-trip interop test that runs
production `connectNestsListener` + `connectNestsSpeaker` through the
real moq-relay — that's where MoQ wire-format assumptions (draft
revision, OBJECT_DATAGRAM layout, namespace tuple shape) get verified
or get followup audit findings.
88 lines
3.3 KiB
Kotlin
88 lines
3.3 KiB
Kotlin
/*
|
|
* Copyright (c) 2025 Vitor Pamplona
|
|
*
|
|
* Permission is hereby granted, free of charge, to any person obtaining a copy of
|
|
* this software and associated documentation files (the "Software"), to deal in
|
|
* the Software without restriction, including without limitation the rights to use,
|
|
* copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the
|
|
* Software, and to permit persons to whom the Software is furnished to do so,
|
|
* subject to the following conditions:
|
|
*
|
|
* The above copyright notice and this permission notice shall be included in all
|
|
* copies or substantial portions of the Software.
|
|
*
|
|
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
|
|
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
|
|
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN
|
|
* AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
|
|
* WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|
*/
|
|
package com.vitorpamplona.nestsclient
|
|
|
|
import kotlinx.serialization.Serializable
|
|
import kotlinx.serialization.json.Json
|
|
|
|
/**
|
|
* Per-room configuration that orchestration needs to connect. Built from
|
|
* the NIP-53 kind 30312 [MeetingSpaceEvent] by the caller (UI / VM)
|
|
* before invoking `connectNestsListener` / `connectNestsSpeaker`:
|
|
*
|
|
* - [authBaseUrl] — the event's `service` tag (e.g. `https://nostrnests.com/api/v1/nests`).
|
|
* Note: the real moq-auth API is rooted at this base; the client posts
|
|
* to `<authBaseUrl>/auth` to mint a JWT.
|
|
* - [endpoint] — the event's `endpoint` tag (e.g. `https://relay.nostrnests.com:4443/anon`).
|
|
* The MoQ relay's WebTransport URL.
|
|
* - [hostPubkey] — the event author's pubkey. Goes into the
|
|
* [NestsAuth.MOQ_NAMESPACE_PREFIX] to scope the JWT to this room.
|
|
* - [roomId] — the event's `d` tag.
|
|
* - [kind] — the NIP-53 event kind (30312 for meeting spaces).
|
|
*/
|
|
data class NestsRoomConfig(
|
|
val authBaseUrl: String,
|
|
val endpoint: String,
|
|
val hostPubkey: String,
|
|
val roomId: String,
|
|
val kind: Int = MEETING_SPACE_KIND,
|
|
) {
|
|
/**
|
|
* MoQ namespace string for this room, in the format moq-auth expects:
|
|
* `nests/<kind>:<host_pubkey_hex>:<roomId>`.
|
|
*/
|
|
fun moqNamespace(): String = "nests/$kind:$hostPubkey:$roomId"
|
|
|
|
companion object {
|
|
const val MEETING_SPACE_KIND: Int = 30312
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Response shape from `POST <authBase>/auth`. The reference server
|
|
* (`nostrnests/nests/moq-auth/src/index.ts`) returns `{"token":"<jwt>"}`
|
|
* — that JWT is then passed as the WebTransport bearer token to the
|
|
* MoQ relay.
|
|
*/
|
|
@Serializable
|
|
data class NestsTokenResponse(
|
|
val token: String,
|
|
) {
|
|
companion object {
|
|
private val json =
|
|
Json {
|
|
ignoreUnknownKeys = true
|
|
explicitNulls = false
|
|
}
|
|
|
|
fun parse(body: String): NestsTokenResponse = json.decodeFromString(serializer(), body)
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Build the auth URL for a given service base. Trims trailing slashes
|
|
* and appends `/auth`.
|
|
*
|
|
* Example: `https://nostrnests.com/api/v1/nests` →
|
|
* `https://nostrnests.com/api/v1/nests/auth`.
|
|
*/
|
|
fun nestsAuthUrl(authBase: String): String = authBase.trimEnd('/') + "/auth"
|