From 9dad6255993de1a2ebdb34e253a3015ab862fc92 Mon Sep 17 00:00:00 2001 From: Aaravanand Date: Fri, 2 Oct 2026 23:43:03 +0530 Subject: [PATCH] fix(presence): respect ALLOW_ANON_PRESENCE and enable presence interaction --- src/worker.py | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/src/worker.py b/src/worker.py index bf344bf..8fe6263 100644 --- a/src/worker.py +++ b/src/worker.py @@ -6527,13 +6527,22 @@ async def on_fetch(self, request): user_param = (qs.get("user_id") or [None])[0] display_param = (qs.get("display_name") or [None])[0] + allow_anon_raw = getattr(self.env, "ALLOW_ANON_PRESENCE", "true") + allow_anon = str(allow_anon_raw).strip().lower() in ("true", "1", "yes") + authenticated_user = verify_token(token_param or "", self.env.JWT_SECRET) if token_param else None - can_interact = authenticated_user is not None if authenticated_user: user_id = str(authenticated_user.get("id", "")) display_name = str(authenticated_user.get("username") or user_id) + can_interact = True else: + if not allow_anon: + return Response( + json.dumps({"error": "Authentication required"}), + status=401, + headers={"Content-Type": "application/json"}, + ) if token_param or not user_param: return Response( json.dumps({"error": "Authentication required"}), @@ -6542,6 +6551,7 @@ async def on_fetch(self, request): ) user_id = str(user_param) display_name = str(display_param or user_id) + can_interact = True user_id = user_id[:64] display_name = display_name[:64]