From b68efa77748049076a69fae67dbf30ce7d732ed1 Mon Sep 17 00:00:00 2001 From: kdcokenny Date: Fri, 2 Oct 2026 13:26:12 +0000 Subject: [PATCH] fix(token): grant ingress permissions in wizard --- cmd/lk/token.go | 1 + cmd/lk/token_wizard_test.go | 75 +++++++++++++++++++++++++++++++++++++ go.mod | 1 + 3 files changed, 77 insertions(+) create mode 100644 cmd/lk/token_wizard_test.go diff --git a/cmd/lk/token.go b/cmd/lk/token.go index 479c1a0c..ba8ff0f4 100644 --- a/cmd/lk/token.go +++ b/cmd/lk/token.go @@ -409,6 +409,7 @@ func createToken(ctx context.Context, c *cli.Command) error { if slices.Contains(permissions, pEgress) { grant.RoomRecord = true } + grant.IngressAdmin = slices.Contains(permissions, pIngress) grant.SetCanUpdateOwnMetadata(slices.Contains(permissions, pMetadata)) inferenceGrant = slices.Contains(permissions, pInference) } diff --git a/cmd/lk/token_wizard_test.go b/cmd/lk/token_wizard_test.go new file mode 100644 index 00000000..f067d8d9 --- /dev/null +++ b/cmd/lk/token_wizard_test.go @@ -0,0 +1,75 @@ +//go:build !windows + +package main + +import ( + "bytes" + "context" + "io" + "os" + "testing" + + "github.com/creack/pty" + "github.com/livekit/protocol/auth" + "github.com/stretchr/testify/assert" + "github.com/stretchr/testify/require" + "github.com/urfave/cli/v3" + + "github.com/livekit/livekit-cli/v2/pkg/config" +) + +func TestTokenWizardIngressPermissions(t *testing.T) { + // Use the accessible wizard with terminal stdin so SkipPrompts stays false. + t.Setenv("TERM", "dumb") + previousProject := project + project = &config.ProjectConfig{APIKey: "test-key", APISecret: "test-secret"} + t.Cleanup(func() { project = previousProject }) + + for _, tc := range []struct { + name string + input string + grant auth.VideoGrant + }{ + {"ingress", "6\n0\n", auth.VideoGrant{IngressAdmin: true}}, + {"egress", "5\n0\n", auth.VideoGrant{RoomRecord: true}}, + {"join, egress and ingress", "3\n5\n6\n0\n", auth.VideoGrant{RoomJoin: true, RoomRecord: true, IngressAdmin: true}}, + } { + t.Run(tc.name, func(t *testing.T) { + terminal, stdin, err := pty.Open() + require.NoError(t, err) + previousStdin := os.Stdin + os.Stdin = stdin + t.Cleanup(func() { + os.Stdin = previousStdin + _ = stdin.Close() + _ = terminal.Close() + }) + _, err = terminal.WriteString(tc.input) + require.NoError(t, err) + + var stdout bytes.Buffer + cmd := &cli.Command{ + Name: "lk", + Action: createToken, + Writer: &stdout, + ErrWriter: io.Discard, + Flags: []cli.Flag{ + &cli.StringFlag{Name: "room"}, + &cli.StringFlag{Name: "identity"}, + &cli.BoolFlag{Name: "token-only"}, + &cli.StringFlag{Name: "valid-for", Value: "5m"}, + }, + } + require.NoError(t, cmd.Run(context.Background(), []string{ + "lk", "--room", "test-room", "--identity", "test-id", "--token-only", + })) + verifier, err := auth.ParseAPIToken(stdout.String()) + require.NoError(t, err) + _, grants, err := verifier.Verify("test-secret") + require.NoError(t, err) + tc.grant.Room = "test-room" + tc.grant.SetCanUpdateOwnMetadata(false) + assert.Equal(t, &tc.grant, grants.Video) + }) + } +} diff --git a/go.mod b/go.mod index 2ee88fd6..dc28c2e3 100644 --- a/go.mod +++ b/go.mod @@ -12,6 +12,7 @@ require ( github.com/atotto/clipboard v0.1.4 github.com/charmbracelet/colorprofile v0.4.3 github.com/charmbracelet/x/ansi v0.11.8 + github.com/creack/pty v1.1.24 github.com/frostbyte73/core v0.1.1 github.com/fsnotify/fsnotify v1.10.1 github.com/go-logr/logr v1.4.4