Repository navigation
Conversation
The chat token provider asked for a token for the user's email. Built-in users have no email, so the token was for another user and the chat client never connected. Both token providers now use the user id, and the unused token parameter of initializeStreamChat is removed.
|
@CodeRabbit review |
PR checklist ✅All required conditions are satisfied:
🎉 Great job! This PR is ready for review. |
✅ Action performedReview finished.
|
SDK Size Comparison 📏
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. WalkthroughChat initialization and Stream Video token renewal now request auth data using the user’s ID. Chat initialization no longer passes a token parameter. ChangesAuth lookup updates
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to Chat continues to obtain its token through the provider, and the changed lookups follow the user-ID convention used elsewhere in the app. No concrete merge-blocking regression is established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change aligns token requests with the connected user’s ID. No new authentication bypass is demonstrated, and Chat already used provider-based token loading. Risk remains low rather than minimal because remote token ownership and some renewal and user-switching behavior could not be verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the tokens bright Comment |
…nnects-for-built-in-users
|
|
🚀 Available in v1.36.0 |



Goal
Fixes AND-1580
In the demo app, the call chat never loaded for a user from the built-in users list. The chat client connected as
user.idbut requested its token foruser.custom["email"]. Built-in users have no email, so the token was for another user and the connection failed.Implementation
TokenProviderinStreamVideoInitHelper.initializeStreamChatrequests the token for the connected user id.TokenProviderininitializeStreamVideoalso usesuser.iddirectly. The email fallback it replaced always gave the same id, because onlyLoginViewModel.signInSuccesssetsemail, and it sets it to the same value asid.tokenparameter ofinitializeStreamChat.Testing
andrerego).Also check that a Google or email login still connects chat and video.
Validation:
./gradlew spotlessApplyand:demo-app:compileDevelopmentDebugKotlinpass. Steps 1 to 4 were run on an API 35 emulator. The logcat shows the chat token request withuser_idand no JWT mismatch error. The video provider only runs on token renewal, and that path was not triggered on device.Summary by CodeRabbit