Skip to content

fix(react-native): only process stream.video call.ring VoIP pushes on iOS - #2486

Merged
oliverlaz merged 1 commit into
mainfrom
rn-439-ios-voip-ring-push-filter
Oct 2, 2026
Merged

oliverlaz merged 1 commit into
mainfrom
rn-439-ios-voip-ring-push-filter

Conversation

@oliverlaz

@oliverlaz oliverlaz commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

💡 Overview

The iOS VoIP push handler (onVoipNotificationReceived) filtered payloads with sender !== 'stream.video' && type !== 'call.ring', so a stream.video push with a non-ring type, or a call.ring push from another sender, was processed as a ringing call. It now requires both, matching the Android handler.

📝 Implementation notes

  • ios.ts: switch the guard to || so only stream.video + call.ring payloads are processed.
  • New __tests__/push/ios.test.ts (same jest.isolateModules + jest.doMock style as android.test.ts): a non-ring stream.video payload and a ring from another sender are ignored, a stream.video ring is processed. The two "ignored" cases fail without the fix.

🎫 Ticket: https://linear.app/stream/issue/RN-439

📑 Docs: N/A

Summary by CodeRabbit

  • Bug Fixes
    • iOS VoIP push notifications are now processed only when they’re call.ring events sent by stream.video. Other notification types and senders are ignored.

… iOS

The iOS VoIP handler used `&&` in its payload filter, so a stream.video
push with a non-ring type, or a call.ring push from another sender, was
processed as a ringing call. Require both, matching the Android handler.

Ref: RN-439
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (2)
packages/react-native-sdk/CLAUDE.md — auto-discovered
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 104f9b0e-cc86-4878-ae99-f020f9b59e9a

📥 Commits

Reviewing files that changed from the base of the PR and between fd61a31 and cb4c9d9.

📒 Files selected for processing (2)
  • packages/react-native-sdk/__tests__/push/ios.test.ts
  • packages/react-native-sdk/src/utils/push/internal/ios.ts

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The iOS VoIP handler now processes notifications only when the sender is stream.video and the type is call.ring. New tests verify that non-matching notifications do not create a client and that a matching notification does.

Changes

iOS VoIP notification filtering

Layer / File(s) Summary
Notification filter and tests
packages/react-native-sdk/src/utils/push/internal/ios.ts, packages/react-native-sdk/__tests__/push/ios.test.ts
The handler rejects a notification if its sender or type does not match. Tests check two non-matching payloads and one matching payload against client factory calls.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to cb4c9

The iOS handler rejects unrelated VoIP notifications while continuing to process matching ring notifications. No identified issue blocks merging after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to cb4c9

The filter now rejects unrelated notifications before creating JavaScript call state. No security regression is established, but native push-completion and call-cleanup behavior for newly ignored notifications remains unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — For payloads reaching this JavaScript handler, the accepted set is strictly smaller than before. The PR therefore reduces reachability of client creation and ringing-call processing without granting additional downstream authority.

Trust Boundaries and Controls

  • observed — Native registration uses PKPushRegistry, and the native notification manager forwards the payload dictionary into an event. The JavaScript sender/type check is an eligibility control, not evidence of authenticated sender identity. Attacker injectability or provenance guarantees are not established by these excerpts.

Resilience and Maintainability Implications

  • inferred — Newly rejected payloads cannot create JavaScript call objects or subscription-map entries because rejection precedes those operations. Matching payloads retain the existing lifecycle, including event-driven unsubscription and map deletion. This does not establish cleanup of native state created before event delivery.

Hardening Proposals

  • proposed — Verify and document native push-completion and incoming-call cleanup ownership for rejected payloads, including whether these obligations complete independently of JavaScript call creation.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: restricting iOS VoIP processing to stream.video call.ring pushes.
Description check ✅ Passed The description includes the required Overview and Implementation notes sections, explains the bug and fix, summarizes the tests, and provides the ticket and documentation fields. The Docs: N/A entr…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Bundle size

Built package output. Sizes in KB; delta vs main@fd61a31.

No significant package size increase vs main.

@oliverlaz oliverlaz added the backport-v1 PRs that need to be backported to the `release-v1` branch label Oct 2, 2026
@oliverlaz
oliverlaz merged commit bf6d27f into main Oct 2, 2026
9 checks passed
@oliverlaz
oliverlaz deleted the rn-439-ios-voip-ring-push-filter branch October 2, 2026 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-v1 PRs that need to be backported to the `release-v1` branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants