Skip to content

Show other members' active live locations when a channel loads - #6742

Merged
gpunto merged 3 commits into
developfrom
fix/channel-active-live-locations
Sep 29, 2026
Merged

gpunto merged 3 commits into
developfrom
fix/channel-active-live-locations

Conversation

@gpunto

@gpunto gpunto commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Channel.activeLiveLocations was never populated from REST, so another member's active live location did not show when a channel or the channel list loaded, only after their next location update. The backend sends active_live_locations on the channel state, next to messages and members, but the SDK read it from the nested channel object.

Closes AND-1576

Implementation

  • Parse active_live_locations on the channel state response and map it onto the channel, for query channel, query channels and grouped channels. Drop the field from the nested channel DTO, where the backend never sends it.
  • Add the channel's live locations to the global state on query channel results and channel list updates, in both the default and the legacy channel logic. ChannelState and QueryChannelsState read their live locations from there.

Testing

  • Parsing tests for the three responses, MoshiChatApiTest rows per path, and state tests checking a queried channel exposes another member's location in ChannelState and the global state.
  • On a device, a second user shared a live location in fresh channels the current user was a member of but not watching. Without the fix none of the locations reached the SDK. With it, the other member's location appeared in the queried channel, in ChannelState on channel load and in the channel list. Grouped channels is not available on the sample app, so it is covered by unit tests only.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Active live locations are now parsed from channel responses and included in channel state after queries and channel updates.
    • Responses without active live locations continue to yield an empty list.

@gpunto gpunto added the pr:bug Bug fix label Sep 28, 2026
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

PR checklist ✅

All required conditions are satisfied:

  • Title length is OK (or ignored by label).
  • At least one pr: label exists.
  • Sections ### Goal, ### Implementation, and ### Testing are filled, or the PR is bot-authored.
  • An issue is linked (Linear ticket or GitHub issue), or the PR is bot-authored.

🎉 Great job! This PR is ready for review.

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

SDK Size Comparison 📏

SDK Before After Difference Status
stream-chat-android-client 6.11 MB 6.11 MB 0.00 MB 🟢
stream-chat-android-ui-components 11.41 MB 11.41 MB 0.00 MB 🟢
stream-chat-android-compose 13.09 MB 13.09 MB 0.00 MB 🟢

@gpunto
gpunto marked this pull request as ready for review September 28, 2026 15:36
@gpunto
gpunto requested a review from a team as a code owner September 28, 2026 15:36
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 4f35042d-0347-4234-8f6f-ef2d7b108a17

📥 Commits

Reviewing files that changed from the base of the PR and between 6cca78b and 23b3ead.

📒 Files selected for processing (11)
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/MoshiChatApi.kt
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/mapping/DomainMapping.kt
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/model/dto/ChannelDtos.kt
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/model/response/ChannelResponse.kt
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/ChannelLogicImpl.kt
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/legacy/ChannelStateLogic.kt
  • stream-chat-android-client/src/test/java/io/getstream/chat/android/client/api2/MoshiChatApiTest.kt
  • stream-chat-android-client/src/test/java/io/getstream/chat/android/client/api2/MoshiChatApiTestArguments.kt
  • stream-chat-android-client/src/test/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/ChannelLogicImplActiveLiveLocationsTest.kt
  • stream-chat-android-client/src/test/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/legacy/ChannelStateLogicTest.kt
  • stream-chat-android-client/src/test/java/io/getstream/chat/android/client/parser2/ChannelStateActiveLiveLocationsParsingTest.kt
💤 Files with no reviewable changes (2)
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/mapping/DomainMapping.kt
  • stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/model/dto/ChannelDtos.kt

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


Walkthrough

The API response model now carries active_live_locations, and channel mapping converts those entries to domain locations. Channel query and update paths add the mapped locations to global state. Tests cover response parsing, mapping, and state propagation.

Changes

Active Live Location Flow

Layer / File(s) Summary
Response parsing and channel mapping
stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/model/dto/ChannelDtos.kt, stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/model/response/ChannelResponse.kt, stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/MoshiChatApi.kt, stream-chat-android-client/src/main/java/io/getstream/chat/android/client/api2/mapping/DomainMapping.kt, stream-chat-android-client/src/test/java/io/getstream/chat/android/client/parser2/ChannelStateActiveLiveLocationsParsingTest.kt, stream-chat-android-client/src/test/java/io/getstream/chat/android/client/api2/MoshiChatApiTest*.kt
ChannelResponse now contains active_live_locations. flattenChannel maps the entries to domain locations. Tests cover parsing across channel response types and mapping location fields.
Channel state propagation
stream-chat-android-client/src/main/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/ChannelLogicImpl.kt, stream-chat-android-client/src/main/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/legacy/ChannelStateLogic.kt, stream-chat-android-client/src/test/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/ChannelLogicImplActiveLiveLocationsTest.kt, stream-chat-android-client/src/test/java/io/getstream/chat/android/client/internal/state/plugin/logic/channel/internal/legacy/ChannelStateLogicTest.kt
Channel query and update paths now add channel active live locations to global state. Tests check propagation in current and legacy state logic.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: velikovpetar

Merge Risk: ⚪ Minimal · up to 23b3e

The change makes other members’ active live locations available when channels load. No actionable issue has been established that would prevent merging after normal checks.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 23b3e

Live locations will become visible when channels load, as intended. A delayed channel response can also replace a newer location update, potentially leaving a stale position or sharing status visible until expiration. The server’s location-visibility rules could not be verified here.

Retained concerns

  • Medium · security · inferred: A delayed channel response can replace a newer event’s location for the same message ID without comparing freshness. The new REST-to-global-state path creates another source of such updates, so a stale position or pre-stop expiration value may remain visible until expiry.
Security review details

Security Blast Radius

  • inferred — Exposure is within the client’s global live-location collection and its channel and channel-list projections. The inspected views limit display by channel ID; no change to server privileges or request authority was established.

Security Findings and Attack Paths

  • inferred — No attacker-controlled authorization bypass was established. A delayed REST response can nevertheless overwrite a newer live event for the same message ID; the existing expiry filter bounds retention but does not establish update freshness.

Trust Boundaries and Controls

  • inferred — The REST response is the effective trust boundary for another member’s location visibility: the inspected client does not independently check membership or location ownership before ingestion. Backend enforcement across the response paths is unknown, not a demonstrated bypass.

Resilience and Maintainability Implications

  • observed — Stop-result handling removes expired locations, while response and event updates use the same global merge. Neither path shown provides a response-versus-event freshness check.

Hardening Proposals

  • proposed — Establish the server’s membership, channel-ID and snapshot-completeness guarantees for all channel response paths; preserve the newer location when a delayed response races an event, and reconcile omissions only if responses are authoritative.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 10.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 20 functions across 9 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: exposing other members' active live locations when a channel loads.
Description check ✅ Passed The description includes the goal, implementation details, linked issue, and testing coverage. It explains the REST parsing and global-state changes across channel loading paths. The UI Changes and ch…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the channel stream,
Where live locations join the scene.
They cross the map, then reach the state,
Tests trace each hop and check each gate.
The bunny nods: the paths are green.

Comment @coderabbitai help to get the list of available commands.

@andremion andremion left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. One optional nit inline.

@gpunto
gpunto enabled auto-merge September 29, 2026 08:34
@sonarqubecloud

Copy link
Copy Markdown

1 similar comment
@sonarqubecloud

Copy link
Copy Markdown

@gpunto
gpunto added this pull request to the merge queue Sep 29, 2026
Merged via the queue into develop with commit 84b8cba Sep 29, 2026
19 checks passed
@gpunto
gpunto deleted the fix/channel-active-live-locations branch September 29, 2026 10:17
@stream-public-bot stream-public-bot added the released Included in a release label Sep 30, 2026
@stream-public-bot

Copy link
Copy Markdown
Contributor

🚀 Available in v7.13.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:bug Bug fix released Included in a release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants