• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

decentraland / comms-gatekeeper
86%

Build:
DEFAULT BRANCH: main
Repo Added 17 Oct 2024 08:45PM UTC
Token H9CF0YzviAGXBYzx8ZZY8Lv8V4wtqKxTm regen
Build 874 Last
Files 151
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH main
branch: SELECT
CHANGE BRANCH
x
Sync Branches
  • No branch selected
  • 1.1.0
  • 1.1.1
  • 1.2.0
  • 1.2.1
  • 1.3.0
  • 2.0.0
  • 2.0.1
  • 2.1.0
  • 2.1.1
  • 2.10.0
  • 2.11.0
  • 2.12.0
  • 2.13.0
  • 2.13.1
  • 2.13.2
  • 2.14.0
  • 2.15.0
  • 2.16.0
  • 2.17.0
  • 2.17.1
  • 2.18.0
  • 2.19.0
  • 2.19.1
  • 2.19.2
  • 2.19.3
  • 2.2.0
  • 2.2.1
  • 2.20.0
  • 2.20.1
  • 2.21.0
  • 2.21.1
  • 2.22.0
  • 2.23.0
  • 2.24.0
  • 2.25.0
  • 2.26.0
  • 2.26.1
  • 2.26.2
  • 2.26.3
  • 2.26.4
  • 2.27.0
  • 2.27.1
  • 2.28.0
  • 2.29.0
  • 2.29.1
  • 2.3.0
  • 2.4.0
  • 2.6.0
  • 2.6.1
  • 2.7.0
  • 2.8.0
  • 2.9.0
  • add-ai-agent-context-to-readme
  • chore/WKC-presentation
  • chore/add-agents-file
  • chore/add-debugging-logs-for-room-started-handler
  • chore/bump-node
  • chore/bump-upstream-fetch-http-server
  • chore/pin-node-24-base-image
  • chore/update-dcl-schemas
  • chore/update-node-24
  • chore/use-docs-generic-action
  • coverage
  • dependabot/npm_and_yarn/dcl/analytics-component-0.2.3
  • dependabot/npm_and_yarn/dcl/analytics-component-0.2.4
  • dependabot/npm_and_yarn/dcl/analytics-component-0.2.5
  • dependabot/npm_and_yarn/dcl/analytics-component-0.2.6
  • dependabot/npm_and_yarn/dcl/analytics-component-0.2.7
  • dependabot/npm_and_yarn/dcl/analytics-component-0.2.8
  • dependabot/npm_and_yarn/dcl/analytics-component-1.0.5
  • dependabot/npm_and_yarn/dcl/crypto-3.7.0
  • dependabot/npm_and_yarn/dcl/crypto-middleware-5.0.0
  • dependabot/npm_and_yarn/dcl/eslint-config-2.2.1
  • dependabot/npm_and_yarn/dcl/eslint-config-2.3.0
  • dependabot/npm_and_yarn/dcl/eslint-config-2.3.1
  • dependabot/npm_and_yarn/dcl/eslint-config-2.4.3
  • dependabot/npm_and_yarn/dcl/features-component-1.0.2
  • dependabot/npm_and_yarn/dcl/http-server-2.2.1
  • dependabot/npm_and_yarn/dcl/platform-crypto-middleware-1.1.0
  • dependabot/npm_and_yarn/dcl/platform-server-commons-1.0.1
  • dependabot/npm_and_yarn/dcl/schemas-16.11.0
  • dependabot/npm_and_yarn/dcl/schemas-16.12.0
  • dependabot/npm_and_yarn/dcl/schemas-16.13.0
  • dependabot/npm_and_yarn/dcl/schemas-16.14.0
  • dependabot/npm_and_yarn/dcl/schemas-16.6.4
  • dependabot/npm_and_yarn/dcl/schemas-16.9.0
  • dependabot/npm_and_yarn/dcl/schemas-17.0.0
  • dependabot/npm_and_yarn/dcl/schemas-17.1.0
  • dependabot/npm_and_yarn/dcl/schemas-17.2.0
  • dependabot/npm_and_yarn/dcl/schemas-18.0.0
  • dependabot/npm_and_yarn/dcl/schemas-18.3.0
  • dependabot/npm_and_yarn/dcl/schemas-18.8.0
  • dependabot/npm_and_yarn/dcl/schemas-19.0.0
  • dependabot/npm_and_yarn/dcl/schemas-19.3.0
  • dependabot/npm_and_yarn/dcl/schemas-19.4.0
  • dependabot/npm_and_yarn/dcl/schemas-19.4.1
  • dependabot/npm_and_yarn/dcl/schemas-19.6.0
  • dependabot/npm_and_yarn/dcl/schemas-19.8.0
  • dependabot/npm_and_yarn/dcl/schemas-20.2.0
  • dependabot/npm_and_yarn/dcl/schemas-20.3.0
  • dependabot/npm_and_yarn/dcl/schemas-22.0.0
  • dependabot/npm_and_yarn/dcl/sns-component-3.0.1
  • dependabot/npm_and_yarn/dcl/sns-component-3.0.2
  • dependabot/npm_and_yarn/well-known-components/fetch-component-3.0.0
  • dependabot/npm_and_yarn/well-known-components/interfaces-1.4.3
  • dependabot/npm_and_yarn/well-known-components/interfaces-1.5.1
  • dependabot/npm_and_yarn/well-known-components/interfaces-1.5.2
  • dependabot/npm_and_yarn/well-known-components/test-helpers-1.5.8
  • docs-update
  • docs/adapt-to-new-docs-workflow
  • docs/add-endpoint-docs
  • docs/ai
  • docs/ai-context
  • docs/banned-name-is-optional
  • docs/confusing-required-props-for-bans-and-admins
  • docs/fix-docs-workflow-usage
  • docs/fix-publish
  • docs/force-publish
  • docs/forcing-re-deploy
  • docs/improve-openapi-description
  • docs/rename-api-spec
  • docs/standarize-readme-schemas-and-agent-context
  • docs/test-api-reference-file
  • docs/update-list-bans-response
  • docs/use-docs-generic-action
  • docs/users-can-also-be-banned-by-name
  • feat/add-analytics
  • feat/add-generate-links
  • feat/add-logs
  • feat/add-names-to-get-admins
  • feat/add-owner-and-operators-in-list-admins
  • feat/add-private-voice-chat
  • feat/add-profile-to-metadata
  • feat/add-scene-room-creds-to-cast
  • feat/add-schema-validator-component
  • feat/add-support-for-multi-world-scenes
  • feat/add-support-for-world-rooms
  • feat/add-tracing
  • feat/add-try-catch
  • feat/add-world-bans-check
  • feat/all-active-voice-chats-endpoint
  • feat/allow-adding-scene-admins-by-name
  • feat/allow-banning-unbanning-by-name
  • feat/authorative-server
  • feat/ban-user-from-scene
  • feat/bans-check
  • feat/bot-presenter-handler
  • feat/bump-crypto-middleware-4.1.0
  • feat/cache-deny-list
  • feat/cache-response-of-fetch-entity-by-id
  • feat/cast-endpoints
  • feat/catch-ingress-not-found
  • feat/change-manual-deploy
  • feat/check-community-calls-ongoing
  • feat/cluster-livekit-subscriber
  • feat/communities-voice-actions
  • feat/communities-voice-chat-store-role
  • feat/community-voice-chat
  • feat/componenterize-blocklist
  • feat/device-aware-ban-status
  • feat/end-community-call
  • feat/enhance-handler
  • feat/expire-rooms
  • feat/filter-local-preview-realm
  • feat/forward-livekit-messages-to-dwh
  • feat/generate-stream-link-get
  • feat/get-private-conversations-room-token
  • feat/get-scene-adapter-should-fail-for-banned-users
  • feat/get-social-privacy-settings-for-metadata
  • feat/get-stream-info-endpoint
  • feat/http-server-for-http2
  • feat/identity
  • feat/identity-handling
  • feat/kick-banned-users
  • feat/land-validation
  • feat/linker-server
  • feat/list-and-revoke-stream-access
  • feat/listen-livekit-webhook
  • feat/livekit-receive-webhook
  • feat/livekit-webhook-handler
  • feat/livekit-webhook-handler-2
  • feat/logs
  • feat/moderator-token-auth
  • feat/move-user-joined-event-to-event-joining-process
  • feat/mute-metadata
  • feat/notifications
  • feat/notify-moderation-events
  • feat/patch-social-privacy-settings
  • feat/places-checker
  • feat/platform-bans-check
  • feat/player-connection-info-device-ip-bans
  • feat/prevent-request-from-being-blocked
  • feat/publish-all-room-join-and-left-events
  • feat/publish-community-streaming-ended-event
  • feat/publish-user-left-room-event
  • feat/re-discovery-changes
  • feat/reject-request-to-speak
  • feat/remove-bans-from-disabled-places
  • feat/remove-old-key
  • feat/reset-logs
  • feat/reset-streaming-key
  • feat/return-world-other-permissions-addresses
  • feat/revoke-endpoint
  • feat/save-speaker-in-metadata
  • feat/scene-admins-for-multiplayer
  • feat/send-notifications-when-ban-unban-from-scene
  • feat/send-the-disconnection-reason-to-analytics
  • feat/setup-scene-admin-addapters-and-controllers
  • feat/sns-component
  • feat/sqs-message
  • feat/store-is-speaker-in-metadata-by-default
  • feat/stream-acces-migretion-adapter
  • feat/stream-link-gen
  • feat/streaming-image
  • feat/streaming-key-ttl-checker
  • feat/streaming-ttl-checker
  • feat/support-getting-community-voice-chat-status-in-bulk
  • feat/support-http2
  • feat/support-listing-bans-from-a-scene
  • feat/support-unban-user-from-scene
  • feat/update-explorer-url
  • feat/update-livekit-metadata-with-bans-info
  • feat/update-metadata-with-bans-after-room-creation
  • feat/upgrade-livekit-sdk
  • feat/use-admin-smart-item-world-scene-wise
  • feat/use-token-middleware
  • feat/user-moderation
  • feat/validate-world-stream-permissions
  • feat/world-device-ban-check
  • feature/ip-banning
  • fix/active-community-calls-endpoint
  • fix/add-debugging-voice-chat-logs
  • fix/add-metadata-validator-to-bans
  • fix/add-missing-update-operators
  • fix/add-more-voice-logging
  • fix/allow-owners-to-access-their-worlds
  • fix/avoid-fetching-places-using-undefined-parcels
  • fix/banned-users-cannot-be-admins
  • fix/bans
  • fix/cache-effectiveness-across-adapters
  • fix/cache-instance-per-call
  • fix/cancel-undrained-response-bodies
  • fix/cast-and-streaming-access-generations-for-multi-scene-worlds
  • fix/cast-expiration-time
  • fix/cast-room-id
  • fix/cast-stream-access-missing-ingress
  • fix/change-auth-token
  • fix/check-world-owner
  • fix/comms-gatekeeper-canonical-signer-validation
  • fix/community-voice-chats-expiring-job
  • fix/community-voice-stale-participant-left
  • fix/correctly-check-for-body-user-metadata
  • fix/crypto-middleware-6
  • fix/denylist
  • fix/ends-time
  • fix/env-var-auth-server
  • fix/expired-query
  • fix/failing-tests
  • fix/github-actions
  • fix/hide-device-id-from-public-ban-status
  • fix/ingress-id-unique-error
  • fix/ingress-not-being-deleted
  • fix/ingress-options
  • fix/kick
  • fix/land-lease-multiple-authorizations-bug
  • fix/livekit-handler
  • fix/livekit-host
  • fix/livekit-host-procol
  • fix/lowercase-address
  • fix/metadata
  • fix/metadata-profile
  • fix/only-fire-end-event-on-closing-call
  • fix/parcels-endpoint-throwing
  • fix/participant-id
  • fix/place-search-response
  • fix/place-world-migration
  • fix/places-id-migration
  • fix/preserve-player-connection-info-on-null-upsert
  • fix/preview-room-name-uses-scene-id
  • fix/print-status-code-on-fetch-error
  • fix/privacy-settings-fetching
  • fix/reliable-community-voice-chat-ended-event
  • fix/remove-streaming-key
  • fix/remove-unused-handler
  • fix/resolve-world-scene-id-before-checking-ban
  • fix/respond-with-404-when-name-owner-not-found
  • fix/respond-with-livekit-connection-url
  • fix/restful-moderation
  • fix/return-created_at-as-number
  • fix/scene-admin-500-when-no-profiles-resolve
  • fix/scene-base-integrity
  • fix/security-audit-findings
  • fix/streaming-key
  • fix/suppress-preview-room-events
  • fix/test
  • fix/test-voice-chat-room-hook
  • fix/tests
  • fix/update-readme
  • fix/use-correct-metadata-validator
  • fix/use-improved-lamb2-land-api
  • fix/use-webhook-event-room-when-room-started
  • fix/voice-chat-room-deletion
  • fix/world-streaming
  • fix/wss-adapter
  • gonpombo8-patch-1
  • main
  • pentreathm-patch-1
  • pentreathm-patch-2
  • refactor/add-scene-ban-input-camel-cased
  • refactor/change-terminlogy-blacklister-to-denylister
  • refactor/localpreview-fallback-cleanup
  • refactor/native-fetch-migration
  • refactor/replace-wkc-with-dcl-components
  • refactor/room-metadata-sync
  • refs/tags/1.0.0
  • refs/tags/1.0.1
  • revert-logging
  • test/duplicate-instance-for-testing-purposes
  • test/livekit
  • update/list-admins

20 Aug 2026 02:29PM UTC coverage: 85.967% (+0.3%) from 85.683%
32380477054

push

github

web-flow
fix(auth): upgrade @dcl/crypto-middleware to 6 (#289)

* fix(auth): upgrade @dcl/crypto-middleware to 6

Version 6 binds the metadata bytes into the signed payload instead of
lowercasing them, so the signature now covers the metadata exactly as
delivered rather than only its case-folded form.

No source changes are needed. The middleware already handed handlers the
metadata as the client sent it, cased, both before and after this change;
only the payload the signature is checked against differs. Every
metadata.signer comparison and every value read out of authMetadata keeps
behaving as it did.

The test helper does need to catch up: getAuthHeaders signed the previous
payload format, so without this every integration auth test would fail
against a correctly working service.

Note that clients must ship the new signing format before this deploys.
Any explorer still signing the previous payload gets a 401, and that is
every scene-originated request rather than a subset, because the metadata
this service reads is camelCase throughout (sceneId, realmName,
realm.serverName, deviceIdentifier).

* test(auth): expect the signature rejection rather than the removed guard

The watcher-token spec covering a scene signer signed canonically and
delivered re-cased asserted a 400 from the canonical-value guard that
@dcl/crypto-middleware 5.1.0 applied. Version 6 joins the metadata bytes
into the signed payload, so the delivered bytes no longer reproduce what
was signed and the request fails verification first, with a 401.

The behaviour under test is unchanged: the request is still refused and
the handler is still not reached. Only the layer that refuses it moved,
from a guard covering two named fields to the signature covering all of
them.

* refactor(auth): use the shared signer predicates from crypto-middleware 6.1

The five hand-rolled metadataValidator closures are replaced by
requireSigner and rejectIfSigner. Same gates, expressed once in the
library rather tha... (continued)

1145 of 1456 branches covered (78.64%)

Branch coverage included in aggregate %.

3 of 3 new or added lines in 2 files covered. (100.0%)

3137 of 3525 relevant lines covered (88.99%)

78.61 hits per line

Relevant lines Covered
Build:
Build:
3525 RELEVANT LINES 3137 COVERED LINES
78.61 HITS PER LINE
Source Files on main
  • Tree
  • List 151
  • Changed 97
  • Source Changed 2
  • Coverage Changed 97
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
32380477054 main fix(auth): upgrade @dcl/crypto-middleware to 6 (#289) * fix(auth): upgrade @dcl/crypto-middleware to 6 Version 6 binds the metadata bytes into the signed payload instead of lowercasing them, so the signature now covers the metadata exactly as de... push 20 Aug 2026 02:31PM UTC web-flow github
85.97
32374157099 fix/crypto-middleware-6 test(auth): cover the legacy fallback through the middleware path too The scene-adapter routes verify through validate()/oldValidate(); every other route goes through the middleware instances. Those are two separate opt-ins, and the spec only exe... Pull #289 20 Aug 2026 01:27PM UTC LautaroPetaccio github
85.97
32314105557 fix/crypto-middleware-6 feat(auth): accept the legacy payload on explorer-facing routes Upgrading to crypto-middleware 6 breaks every explorer client: unity, godot and bevy all still sign the pre-6.0.0 payload, and the metadata they send is camelCase throughout, so fold... Pull #289 19 Aug 2026 11:40PM UTC LautaroPetaccio github
85.97
32186114728 fix/crypto-middleware-6 refactor(auth): use the shared signer predicates from crypto-middleware 6.1 The five hand-rolled metadataValidator closures are replaced by requireSigner and rejectIfSigner. Same gates, expressed once in the library rather than repeated per route... Pull #289 18 Aug 2026 09:09PM UTC LautaroPetaccio github
85.66
32174690553 fix/crypto-middleware-6 test(auth): expect the signature rejection rather than the removed guard The watcher-token spec covering a scene signer signed canonically and delivered re-cased asserted a 400 from the canonical-value guard that @dcl/crypto-middleware 5.1.0 appl... Pull #289 18 Aug 2026 07:07PM UTC LautaroPetaccio github
85.68
31608223803 fix/scene-base-integrity perf: cache active world scene lookups Pull #285 12 Aug 2026 02:44PM UTC LautaroPetaccio github
85.65
31599212132 fix/reliable-community-voice-chat-ended-event fix: publish the ended event for every expired community voice chat The expiration sweep resolved each room's participant count from `getAllActiveCommunityVoiceChats`, but that query only returns rooms that still have an active moderator — which ... Pull #288 12 Aug 2026 01:02PM UTC LautaroPetaccio github
85.79
31554999125 fix/scene-base-integrity fix: resolve active world scene before token issuance Pull #285 12 Aug 2026 01:53AM UTC LautaroPetaccio github
85.56
31535246478 fix/scene-base-integrity Merge origin/main into fix/scene-base-integrity Pull #285 11 Aug 2026 08:56PM UTC LautaroPetaccio github
85.44
31203221036 2.29.1 fix(auth): upgrade crypto middleware validation (#287) push 07 Aug 2026 05:44PM UTC GitHub github
85.68
See All Builds (871)

Badge your Repo: comms-gatekeeper

We detected this repo isn’t badged! Grab the embed code to the right, add it to your repo to show off your code coverage, and when the badge is live hit the refresh button to remove this message.

Could not find badge in README.

Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

Refresh
  • Settings
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc