Kanidm group-gated rooms and minimal mesh calling

Rooms can now require a Kanidm group (via the `groups` OIDC claim,
mapped by `oauth2 update-claim-map` server-side) - dev/ops require
`developers`, enforced at every message path (send, history, SSE).

Adds a minimal WebRTC mesh call feature scoped to the lobby room,
signaled over a separate `call.room.*` NATS subject kept out of the
chat archive: public STUN only, no TURN, no SFU - small groups on
friendly networks, by design.
This commit is contained in:
Bendik Aagaard Lynghaug
2026-07-27 23:52:27 +02:00
parent 46bdad1629
commit 650ed50c21
12 changed files with 875 additions and 26 deletions
+1
View File
@@ -90,6 +90,7 @@ async fn main() -> anyhow::Result<()> {
.route("/auth/callback", get(oidc::callback))
.route("/auth/logout", get(oidc::logout))
.route("/sse/{room}", get(sse::room_events))
.route("/call-sse/{room}", get(sse::call_events))
.route("/api/{*fn_name}", any(server_fn_handler))
.leptos_routes_with_context(
&state,