fix: remove special character requirement from stream keys (#4754)

Some broadcasting software (e.g., Prism Live Studio) strips special
characters from stream keys, making Owncast-generated keys incompatible.

Changes:
- Create separate STREAM_KEY_COMPLEXITY_RULES without special char requirement
- Update generateRndKey() to only use alphanumeric characters
- Keep PASSWORD_COMPLEXITY_RULES unchanged for admin password security
- Update tooltip text to reflect new requirements
- Add comprehensive tests for stream key generation

Fixes #4690

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
John Costa
2026-01-28 11:51:57 -08:00
committed by GitHub
co-authored by Claude Opus 4.5
parent 93b482871f
commit 397ec95d9b
3 changed files with 64 additions and 20 deletions
+25
View File
@@ -639,3 +639,28 @@ export const PASSWORD_COMPLEXITY_RULES = [
];
export const REGEX_PASSWORD = /^(?=.*?[A-Z])(?=.*?[a-z])(?=.*?[0-9])(?=.*?[!@#$%^&*])[^-]{8,192}$/;
// Stream key validation rules - same as password but WITHOUT special character requirement
// This is needed because some broadcasting software (e.g., Prism Live Studio) strips special characters
export const STREAM_KEY_COMPLEXITY_RULES = [
{ min: 8, message: '- minimum 8 characters' },
{ max: 192, message: '- maximum 192 characters' },
{
pattern: /^(?=.*[a-z])/,
message: '- at least one lowercase letter',
},
{
pattern: /^(?=.*[A-Z])/,
message: '- at least one uppercase letter',
},
{
pattern: /\d/,
message: '- at least one digit',
},
{
pattern: /^[^-]+$/,
message: '- must NOT contain a dash: -',
},
];
export const REGEX_STREAM_KEY = /^(?=.*?[A-Z])(?=.*?[a-z])(?=.*?[0-9])[^-]{8,192}$/;