User interface changes

The BigBlueButton settings form now stores the API secret in a password
field; leave it empty on save to keep the existing secret.

No changes to the meeting join flow, recordings display, or content
editing for end users.

API changes

Now requires bigbluebutton/bigbluebutton-api-php ^3.0 and PHP 8.2+.

Participants join by role (role=MODERATOR / role=VIEWER); the meeting
password is still sent as a fallback for BigBlueButton servers that predate
role support, so joining works on both.

The recording view and download routes now include the host entity type,
entity UUID and recording ID, and enforce access to that entity. Code or
links built against the previous route signatures must be updated.

The meeting-end callback route now validates a signed token generated by the module.

The meeting-info REST resource returns a reduced set of status fields.

New route access check: `_bigbluebutton_entity_access`.

New public helper methods on BigBlueButtonHelper (e.g. loadMeetingEntity(),
getMeetingRole(), probeBBBServer()); hook_bigbluebutton_meeting_role_alter()
may now return NULL to deny a join.

Data model changes

None. No field storage or schema changes; the BigBlueButton field's
existing properties are unchanged.

Comments

globexplorer created an issue.

  • globexplorer committed 81cd3de2 on 1.0.x
    task: #3626894 Security Fixes & API Upgrade
    
    By: globexplorer