Skip to content

Fix the demo chat never connecting for built-in users - #1857

Merged
andremion merged 2 commits into
developfrom
andrerego/and-1580-demo-app-chat-never-connects-for-built-in-users
Sep 30, 2026
Merged

andremion merged 2 commits into
developfrom
andrerego/and-1580-demo-app-chat-never-connects-for-built-in-users

Conversation

@andremion

@andremion andremion commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Fixes AND-1580

In the demo app, the call chat never loaded for a user from the built-in users list. The chat client connected as user.id but requested its token for user.custom["email"]. Built-in users have no email, so the token was for another user and the connection failed.

Implementation

  • The chat TokenProvider in StreamVideoInitHelper.initializeStreamChat requests the token for the connected user id.
  • The video TokenProvider in initializeStreamVideo also uses user.id directly. The email fallback it replaced always gave the same id, because only LoginViewModel.signInSuccess sets email, and it sets it to the same value as id.
  • Removed the unused token parameter of initializeStreamChat.

Testing

  1. Install a development debug build of the demo app.
  2. Log in with a built-in user (for example andrerego).
  3. Start a new call and join it.
  4. Open the chat: the channel loads, and a sent message shows as sent.

Also check that a Google or email login still connects chat and video.

Validation: ./gradlew spotlessApply and :demo-app:compileDevelopmentDebugKotlin pass. Steps 1 to 4 were run on an API 35 emulator. The logcat shows the chat token request with user_id and no JWT mismatch error. The video provider only runs on token renewal, and that path was not triggered on device.

Summary by CodeRabbit

  • Bug Fixes
    • Chat initialization and video token renewal now use the account’s user ID for authentication, rather than substituting an email address when one is available. This keeps authentication consistent across both processes.

The chat token provider asked for a token for the user's email. Built-in users have no email, so the token was for another user and the chat client never connected. Both token providers now use the user id, and the unused token parameter of initializeStreamChat is removed.
@andremion andremion added the pr:demo-app Changes specific to demo app label Sep 30, 2026
@andremion

Copy link
Copy Markdown
Contributor Author

@CodeRabbit review

@github-actions

Copy link
Copy Markdown
Contributor

PR checklist ✅

All required conditions are satisfied:

  • Title length is OK (or ignored by label).
  • At least one pr: label exists.
  • Sections ### Goal, ### Implementation, and ### Testing are filled, or the PR is bot-authored.
  • An issue is linked (Linear ticket or GitHub issue), or the PR is bot-authored.

🎉 Great job! This PR is ready for review.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@andremion
andremion marked this pull request as ready for review September 30, 2026 09:43
@andremion
andremion requested a review from a team as a code owner September 30, 2026 09:43
@github-actions

Copy link
Copy Markdown
Contributor

SDK Size Comparison 📏

SDK Before After Difference Status
stream-video-android-core 12.38 MB 12.38 MB 0.00 MB 🟢
stream-video-android-ui-xml 5.66 MB 5.66 MB 0.00 MB 🟢
stream-video-android-ui-compose 6.19 MB 6.19 MB 0.00 MB 🟢

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: bc5bd135-fce5-4c8b-8090-34c2ac0d160c

📥 Commits

Reviewing files that changed from the base of the PR and between 4da50b2 and 1824d52.

📒 Files selected for processing (1)
  • demo-app/src/main/kotlin/io/getstream/video/android/util/StreamVideoInitHelper.kt

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


Walkthrough

Chat initialization and Stream Video token renewal now request auth data using the user’s ID. Chat initialization no longer passes a token parameter.

Changes

Auth lookup updates

Layer / File(s) Summary
Use user IDs for auth lookups
demo-app/src/main/kotlin/io/getstream/video/android/util/StreamVideoInitHelper.kt
Chat initialization no longer passes a token parameter. Chat and Stream Video token requests use the user’s ID instead of a custom email.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Suggested reviewers: rahul-lohra

Merge Risk: ⚪ Minimal · up to 1824d

Chat continues to obtain its token through the provider, and the changed lookups follow the user-ID convention used elsewhere in the app. No concrete merge-blocking regression is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 1824d

The change aligns token requests with the connected user’s ID. No new authentication bypass is demonstrated, and Chat already used provider-based token loading. Risk remains low rather than minimal because remote token ownership and some renewal and user-switching behavior could not be verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The immediate security scope is the demo app’s Chat connection and Video renewal for the selected user and environment. Downstream access depends on the returned credentials; the remote service’s maximum identity, project and environment authority cannot be established from the client contract.

Trust Boundaries and Controls

  • observed — The client supplies the requested identity to the remote token authority and consumes its returned token. Aligning that request with the connected SDK ID removes the email substitution, but the available client code does not establish server-side authorization or response ownership.

Resilience and Maintainability Implications

  • observed — Explicit sign-out requests Chat disconnection, clears the stored user, logs out Video and removes its client. reloadSdk instead removes only the Video client before reinitializing. These paths are unchanged by the identity-lookup edits; completion of cleanup and isolation during callback races remain unverified.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 40.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 1 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the primary change: fixing demo chat connectivity for built-in users.
Description check ✅ Passed The description explains the goal, implementation, testing steps, validation results, and linked issue. The UI Changes, contributor checklist, reviewer checklist, and GIF sections are not included, bu…
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the tokens bright
User IDs now guide the flight
Chat finds auth along its way
Video renews by ID each day
I nibble clover, hop, and cheer!

Comment @coderabbitai help to get the list of available commands.

@andremion
andremion enabled auto-merge (squash) September 30, 2026 13:38
@sonarqubecloud

Copy link
Copy Markdown

@andremion
andremion merged commit 2cee1c8 into develop Sep 30, 2026
17 checks passed
@andremion
andremion deleted the andrerego/and-1580-demo-app-chat-never-connects-for-built-in-users branch September 30, 2026 13:52
@stream-public-bot stream-public-bot added the released Included in a release label Oct 7, 2026
@stream-public-bot

Copy link
Copy Markdown
Collaborator

🚀 Available in v1.36.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:demo-app Changes specific to demo app released Included in a release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants