Commit Graph
195 Commits
Author SHA1 Message Date
RXWatcherandClaude Opus 4.7 462ce40ef7 test(audiobooks): cover PATCH /me/item/{id}/bookmark upsert semantics
Drives the same handleUpsertBookmark with reason="bookmark_updated",
asserts the (user, profile, item, time) tuple is unique (PATCH updates
title in place, never duplicates) and that the ULID is preserved
across upsert.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 14:01:02 +02:00
RXWatcherandClaude Opus 4.7 29c40f448c chore(audiobooks): drop unused parseBookmarkTime from bookmark handler
The helper was added in advance of the DELETE handler (next task in
the plan) but is unused in this commit, which trips golangci-lint's
unused check. Reintroduce it together with its first caller.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 14:00:01 +02:00
RXWatcherandClaude Opus 4.7 815f207d6c feat(audiobooks): POST /me/item/{id}/bookmark — ABS bookmark create
First of three ABS bookmark endpoints. Body { title, time } upserts on
(user, profile, item, time); response is the item's full bookmark
list. Backed by a new BookmarkStore dependency (nil-safe: handler
returns 503 when unwired). Item validation via MediaStore;
realtime user_updated event with reason=bookmark_created on success.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 13:41:03 +02:00
RXWatcherandClaude Opus 4.7 6ae492be84 feat(audiobooks): add BookmarkStore interface + ABS envelope helper
Defines the storage contract and wire-shape serialiser the bookmarks
handlers will consume. Envelope test asserts the six required keys
(id, libraryItemId, time, title, createdAt, updatedAt) and the
JS-epoch-millis timestamp shape ABS Android pattern-matches on.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 13:36:13 +02:00
RXWatcherandClaude Opus 4.7 a5e430864b chore(audiobooks): drop abs_bookmarks indexes explicitly in down migration
Matches the convention used by 143_abs_playback_sessions and
147_abs_sessions. Functionally a no-op (DROP TABLE cascade-drops owned
indexes), but reads as complete next to its sibling migrations.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 13:34:34 +02:00
RXWatcherandClaude Opus 4.7 1c74a8870d feat(audiobooks): add abs_bookmarks migration (148)
Backs the upcoming ABS-compatible bookmark endpoints. Schema and
rationale documented in
docs/superpowers/specs/2026-05-26-abs-bookmarks-design.md §5.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 13:31:42 +02:00
RXWatcherandClaude Opus 4.7 73b9aca959 docs(audiobooks): Phase 1 sub-project 1 — ABS bookmarks spec
Three-endpoint, per-(user,profile)-scoped bookmark surface for the
Audiobookshelf-compatibility API. Mirrors the canonical continuum
plugin's "key by (item, time)" model, with silo's profile-isolation
overlay and the existing nil-safe socket publish wrapper for
realtime user_updated events. One migration (148_abs_bookmarks),
one new store, one new handlers file. Ready for the implementation
plan once the user signs off.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 11:39:05 +02:00
RXWatcherandClaude Opus 4.7 a902055acf fix(audiobooks): mount /public/session/{sid}/track/{idx} for ABS DirectPlay
Root cause: the official ABS Android client (PlaybackSession.kt:194-200)
on ABS server v2.22.0+ with DirectPlay builds the streaming URL as
"$serverAddress/public/session/$id/track/$index" WITHOUT a token,
ignoring audioTrack.contentUrl entirely. Silo reports version 2.35.0
and emits playMethod: 0 (DIRECTPLAY) but never mounted this route, so
every play attempt 404'd silently — spinner forever.

Add handlePublicTrack: look up the session by sid (ULID as capability,
matches booklore-ng + continuum-plugin behavior), resolve the track by
1-based index against the session's media files, stream via
playback.ServeDirectPlay (Range + HEAD supported). Mounted OUTSIDE
bearerAuth at both /public/session/... and /abs/public/session/... .

6 unit tests cover serve / HEAD probe / unknown session / closed
session / out-of-range / bad-index paths.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 10:56:48 +02:00
RXWatcherandClaude Opus 4.7 64bb15de84 refactor(audiobooks): unify login timestamp + document filterdata shape
- loginEnvelope now takes the caller's time.Now() rather than computing
  its own. completeLogin and handleABSAuthorize each pass the same
  instant they use elsewhere, so the user.lastSeen/createdAt timestamps
  share a single moment with the token ExpiresAt the caller persisted —
  no more two-call drift in the same response.
- buildFilterData: add a comment explaining why the parallel author/series
  blocks aren't extracted into a helper (different types, different store
  methods — a generic version costs more LoC than it saves).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 10:34:25 +02:00
RXWatcherandClaude Opus 4.7 460d4fd4d5 refactor(audiobooks): minor review-cleanup pass
- loginEnvelope: add a comment explaining the displayName→userID fallback.
- handleRefresh: stop leaking internal err detail in 500 responses; log
  via slog and return a sanitized "token mint/persist/rotation failed".
- handlePlayStart: document why no "progress" field on playbackSession
  (canonical omits it; spec was over-specified).
- Extract resolveDefaultLibrary helper to dedupe the
  "first-audiobook-lib-else-virtual" snippet from three handlers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 10:29:48 +02:00
RXWatcherandClaude Opus 4.7 ca4ebc65a9 test(audiobooks): cover refresh race + revoke-failure semantics
The plan documented both behaviors but neither was exercised:

- Concurrent rotation: two clients presenting the same refresh token whose
  GetTokenByJTI lookups both complete before either revoke must both
  succeed with distinct new pairs. Uses a barrierStore that gates the
  first Revoke so the test is deterministic instead of relying on the
  scheduler.
- Revoke failure: if RevokeTokenByJTI errors after the new pair is
  persisted, /auth/refresh returns 500 and the OLD JTI stays valid so
  the client can retry without losing access.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 10:24:55 +02:00
RXWatcherandClaude Opus 4.7 2415e6b570 test(audiobooks): assert /login + /authorize envelope shape stays stable
Tasks 2 and 3 enriched the login envelope to match the real ABS shape but
shipped without tests; a regression dropping seriesHideFromContinueListening,
itemTagsAccessible, or any of the permissions/serverSettings keys would
silently land and only surface on a live device. Cover the marshaled JSON
shape (top-level keys + user + permissions + serverSettings), the
x-return-tokens opt-in path, and the displayName fallback.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 10:22:50 +02:00
RXWatcherandClaude Opus 4.7 38cc9f1f0c fix(audiobooks): mount /logout outside bearerAuth + add root path
Logout was sitting inside the bearerAuth group, so a client whose access
token had expired — the primary "I want to sign out" UX moment —
received 401 instead of being able to revoke. handleLogout now parses
the bearer locally and ALWAYS returns 204, mirroring continuum-plugin
canonical behavior. Mounted at /logout, /api/logout, /abs/api/logout,
and the legacy /abs/api/auth/logout path; signature is still verified
so an attacker can't revoke a victim JTI by forging the token shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 10:21:57 +02:00
RXWatcherandClaude Opus 4.7 9c870b3749 fix(audiobooks): make MediaStore mandatory at construction
Previously deps.Items / deps.Files were conditionally constructed into a
MediaStore, leaving it nil when either was missing. Most ABS handlers
deref the store unconditionally on the request hot path, so a
misconfigured deployment would pass /login then panic on the next request.
Two scattered nil-guards (buildFilterData, loginEnvelope) masked the
problem without fixing it.

- BuildABSHandler panics at startup if Items/Files are missing.
- abs.New panics if MediaStore is nil.
- Remove the two nil-guards (production now always has a store).
- noopMediaStore test fake for handlers that don't exercise catalog reads.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 10:20:03 +02:00
RXWatcherandClaude Opus 4.7 be69e92b74 fix(audiobooks): nil-guard MediaStore + MetaTags + limit=0 + slog key
Final review follow-up for ABS Phase 0. Five fixes:

1. loginEnvelope and handlePersonalized now nil-guard h.deps.MediaStore
   so a partially-wired deployment doesnt panic on /login or /personalized.
2. handleLibraryAuthors and handleLibrarySeries respect ABS limit=0
   ("return all") instead of returning an empty slice.
3. buildSiloAudioTracks now sets MetaTags to map[string]string{} so the
   "spinner forever" failure mode types.go warns about cannot bite the
   play-session response (item-detail path already sets it; play path
   silently omitted the key).
4. slog key normalised from "error" to "err" in the play-session
   persist-failure log so log parsers find it.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:48:12 +02:00
RXWatcherandClaude Opus 4.7 018059b75a docs(audiobooks): mark ABS Phase 0 as implemented with commit ledger
13 commits across 8 implementation tasks + review-feedback fixes; all
audiobook package tests pass; deployed image verified responding on
:13378 with correct status codes at all mount points.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:39:21 +02:00
RXWatcherandClaude Opus 4.7 8a780fbe45 feat(audiobooks): add POST /logout for ABS sign-out
Mounted inside bearerAuth so the JTI is already validated. Revokes the
access JTI in abs_sessions and returns 204. Idempotent: re-calling on an
already-revoked JTI still returns 204. Refresh JTI is intentionally NOT
revoked here — clients that want hard sign-out-everywhere will use the
sessions endpoint added in Phase 3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:30:58 +02:00
RXWatcherandClaude Opus 4.7 0e71f31aa1 feat(audiobooks): add POST /auth/refresh for ABS token rotation
Mobile clients call refresh every ~22h to avoid the 24h access-token
re-login trap. Accepts the token via x-refresh-token header (real ABS
convention) or {refreshToken} body (legacy). Mints a fresh pair, persists
both new JTIs, then revokes the old refresh JTI atomically — if any step
in 3-4 fails, the old refresh stays valid and the client can retry.

Returns the user{accessToken, refreshToken} object AND top-level token
fields so mainline and 3rd-party clients both find their expected shape.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:27:56 +02:00
RXWatcherandClaude Opus 4.7 4bbab4ccf0 fix(audiobooks): seed currentTime from ProgressStore so resume works
handlePlayStart now looks up the persisted progress row and emits the
saved currentTime in the playback session manifest. Without this every
play start began at 0, breaking cross-device resume which is one of the
core ABS-app value props.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:24:18 +02:00
RXWatcherandClaude Opus 4.7 4b97908d92 chore(audiobooks): rename const cap to fetchCap in buildFilterData
cap shadowed the Go builtin. fetchCap matches the naming used elsewhere
in the file for the same kind of over-fetch ceiling.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:22:22 +02:00
RXWatcherandClaude Opus 4.7 18898f9f7f fix(audiobooks): hydrate filterdata authors and series in library detail
handleLibraryDetail now populates filterdata.authors and filterdata.series
from MediaStore so the iOS filter sheet has real options. Narrators,
genres, publishers, languages, tags stay empty arrays for now (Phase 1
will index those aggregations); empty arrays are gracefully handled by
the client.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:20:53 +02:00
RXWatcherandClaude Opus 4.7 c91daa72c4 fix(audiobooks): proper pagination total + tags key in play session
Review follow-up to c0e9229. handleLibraryAuthors and handleLibrarySeries
fetched the page slice and reported len(results) as total, hiding the
next-page button for libraries with > 50 authors / > 25 series. Both
now over-fetch (cap 5000) and paginate locally so total is the real DB
row count. Also adds the "tags" key (and confirms "genres") on the play
session mediaMetadata map so strict 3rd-party clients dont crash on
undefined; this completes the empty-array guarantee Task 4 began on the
browse/detail surface. Strengthens the series slug test to pin actual
slugify output.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:19:10 +02:00
RXWatcherandClaude Opus 4.7 c0e9229cf0 fix(audiobooks): emit IDs on authors/series and stable genres/tags arrays
3rd-party ABS clients (Plappa, AudioBookShelfFully) require id on every
authors[] and series[] entry to encode filter selections; missing IDs
made author/series chips dead-end. Also ensures genres and tags are
always non-nil arrays so clients that branch on .length don't crash.

Tags is empty for now (silo has no item-tag concept); shape is stable so
future tag work won't break clients.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:11:07 +02:00
RXWatcherandClaude Opus 4.7 f9aafba336 docs(audiobooks): restore x-return-tokens and displayName fallback comments
Code-review follow-up to 36f68d5: the loginEnvelope refactor dropped the
x-return-tokens compatibility comment, and handleABSAuthorize's reuse of
a.UserID for displayName looked like a copy-paste. Both now explained.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:08:48 +02:00
RXWatcherandClaude Opus 4.7 36f68d56ca fix(audiobooks): /authorize returns identical envelope to /login
Extracts the shared envelope builder so /authorize emits the same shape
as /login including accessToken (echoes the caller's bearer), libraries,
permissions, and full serverSettings. The previous /authorize omission
caused iOS resume-on-launch to fall back into re-login.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:02:55 +02:00
RXWatcherandClaude Opus 4.7 a1bed22591 chore(audiobooks): reuse existing now var in login envelope
Replaces second time.Now() call with now.UnixMilli() using the now var
already created higher up in completeLogin for token TTL math.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:00:50 +02:00
RXWatcherandClaude Opus 4.7 abb342f59a fix(audiobooks): enrich ABS login envelope to match real client expectations
Adds itemTagsAccessible, itemTagsSelected, seriesHideFromContinueListening,
lastSeen, createdAt to the user object. Expands permissions to the eight
keys real ABS emits. Enriches serverSettings with the dozen-plus flags
official iOS/Android apps branch on (coverAspectRatio, dateFormat,
timeFormat, scannerDisableWatcher, chromecastEnabled, etc.).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:56:51 +02:00
RXWatcherandClaude Opus 4.7 cadf0eaa92 chore(audiobooks): normalize slog "err" key and add path to secret-fetch log
Brings the pre-existing cred-validator error log into line with the new
keys added in cd4f629 (all use "err"). Adds "path" to the jwt-secret
fetch error log so it matches its sibling rejection logs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:55:11 +02:00
RXWatcherandClaude Opus 4.7 cd4f62965c feat(audiobooks): add diagnostic logging to ABS bearer auth and login
Each rejection branch in bearerAuth now emits a slog line so failures
are traceable from journalctl. Login success path emits a debug line
confirming token persistence; this makes "I cant login" debuggable
without a tcpdump.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:47:33 +02:00
RXWatcherandClaude Opus 4.7 f967fad9ff docs(audiobooks): ABS Phase 0 implementation plan
Step-by-step TDD plan for the login + critical-bug-fix phase. Eleven
tasks, each with file:line targets, complete code blocks, test code,
and exact verification commands. Lands diagnostic logging, login/
authorize envelope enrichment, author/series ID surfacing, filterdata
hydration, resume-position wire-up, POST /auth/refresh, and POST /logout.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:44:32 +02:00
RXWatcherandClaude Opus 4.7 88441eb975 docs(audiobooks): ABS implementation fix design spec
Phased plan to bring silo-server's ABS-compat surface to full parity with
the canonical continuum-plugin-audiobooks reference so that official ABS
iOS/Android/3rd-party clients work end-to-end.

Phase 0: login + critical bug fixes (response shape, resume position,
filterdata, /auth/refresh, /logout).
Phase 1: bookmarks, collections, playlists, smart collections, RSS,
author/series detail, listening stats.
Phase 2: socket.io full event parity (~30 events) with cross-package
publisher hooks.
Phase 3: hardening — media tokens, device tracking, audit log.

Each phase ships as its own PR with its own implementation plan.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:36:48 +02:00
RXWatcher 71174db04e Merge remote-tracking branch 'origin/main' into feat/audiobooks
# Conflicts:
#	AGENTS.md
#	Makefile.local.example
#	internal/metadata/tmdb/client.go
#	web/src/components/AppSidebar.tsx
2026-05-25 19:50:59 +02:00
RXWatcherandClaude Opus 4.7 d59c1cb0b4 chore(migrations): renumber 139_abs_sessions to 147 for origin/main merge
origin/main adds 139_media_requests at the same number our local
audiobook branch had used for abs_sessions. Renumber ours to 147 to
free up 139 for the upstream migration. The schema_versions row is
updated in lockstep on the running database so the migrator sees the
abs_sessions migration as already applied at its new version.

Migrations 140-146 (podcast feeds, media_folders kind noop, audiobook
feature flag, abs playback sessions, podcast episode guid, audiobook
series, audiobook title cleanup) stay where they are — they don't
collide with anything on origin/main.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 19:48:15 +02:00
RXWatcherandClaude Opus 4.7 14a05bba9f feat(audiobooks): comprehensive UX, scanner, and collections work
Detail page:
- collapse Chapters section behind header toggle (73-chapter pages no
  longer push content below the fold)
- square cover frames throughout (audiobook covers are Audible-style 1:1,
  not 2:3 book portrait)
- narrator picker dropdown when multiple narrations of the same book exist
- clickable genre badges (route to /audiobooks?genre=X)
- reordered so credits/rails sit above the chapter list
- Play-from-Start button forces remount via playToken counter (was a
  no-op when player was already at position 0)
- regression test for the Play-from-Start fix

Mini bar / Now Listening:
- mini bar respects --app-sidebar-offset so it stops getting covered by
  the desktop sidebar
- Now Listening adds overflow scroll + a labeled "Back to player" button
  so controls are never inaccessible on short viewports

Library page:
- infinite scroll (replaces Previous/Next pagination)
- genre filter chip with X-to-clear

Scanner:
- 8-worker parallel reconcile (env SILO_AUDIOBOOK_SCAN_WORKERS to override)
- file-path-first dedup so cleaned titles don't collapse separate
  narrations
- title cleanup at write time (strips "Read by X" / "(unabridged)"
  suffixes; original tag preserved in original_title)
- audiobook_series upsert from tag-derived series_name/series_position
- secondary dedup check (author + narrator + year + duration ±0.5% +
  title-prefix) so two folders of the same book attach to one row

Backend detail handler:
- new fetchAlsoByAuthor, fetchInSeries (with series row > 1 entry guard),
  fetchSimilar (embedding-first with shared-genre fallback),
  fetchOtherNarrations (regex-strips narrator suffix to group siblings)
- audiobookDetailResponse gained also_by_author, in_series,
  similar_audiobooks, other_narrations fields
- list endpoint accepts a genre query param

Embeddings:
- BuildEmbeddingText branches on item.Type == "audiobook" to use
  author/narrator credits instead of cast/director/writer
- mediaTypeLabel helper centralizes movie / "TV series" / audiobook
- ListEmbeddingTextCandidates SQL mirrors the Go branching exactly
- ItemsNeedingEmbedding and TotalMediaItemCount loosen status='matched'
  gate to also include audiobooks (which don't go through TMDB match)
- FindSimilar gains a mediaType filter so cross-type results never appear
- callers in similar.go and personal.go pass the source item's type

Collections:
- MediaAudiobook MediaKind + audiobook(s) case in templateEligibleForLibrary
  (stops offering broken movie/TV templates to audiobook libraries)
- useAddItemToCollection hook (user + admin/library endpoints)
- AddToCollectionDialog wired into audiobook detail and movie/series
  ActionBar overflow menu
- ManualCollectionItemsEditor gained a search-and-add panel with
  debounced live results
- QueryDefinition.media_scope, QuerySortRelevanceScope, ALL_MEDIA_SCOPES
  extended to include "audiobook"
- CatalogFilterBar gained an Audiobooks media scope option
- parseCatalogMediaScope (backend) accepts "audiobook"

Migrations:
- 145_audiobook_series: per-book series_name/series_index with a
  best-effort title-pattern backfill for the existing corpus
- 146_audiobook_title_cleanup: strips narrator suffix / (unabridged)
  noise from existing titles, preserving raw in original_title

Scripts:
- scripts/dedup_audiobooks.py: one-shot merge for "Title" vs
  "Title: Subtitle" duplicates, file-path-stable, dry-run by default

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 19:47:54 +02:00
Silo Server Migration c9a0fcbe64 ci(docker): build image on push to main via self-hosted runner
- Trigger Docker image builds on pushes to main instead of nightly cron
- Run on self-hosted Linux runner
- Drop the `nightly` tag
2026-05-25 13:03:56 -04:00
Silo Server Migration 41dbcaa828 fix(catalog): gate search overview-only matches behind title FTS
- Always apply stats CTE + CROSS JOIN so single-word queries no longer flood results with description-only hits
- Require overview_rank >= 0.15 for overview-only fallback rows
- Switch title gate from contiguous LIKE to title_rank > 0 so reordered-token title matches aren't demoted
2026-05-25 12:49:38 -04:00
Silo Server Migration 98ea57ead8 chore: add planning docs and requests updates
- Add plans for date-named episodes and Jellyfin autoscan compat
- Update requests handlers, service, and UI hooks
- Remove Makefile.local.example
2026-05-25 12:07:50 -04:00
QuickandGitHub 6080cbad72 Merge pull request #7 from Silo-Server/t3code/discover-studios-networks-genres-clean
feat(requests): add media request system
2026-05-25 10:56:57 -04:00
Silo Server Migration c157be571f feat(requests): tighten browse grid with more columns
- Increase poster density across breakpoints and use fluid cards
2026-05-25 10:55:33 -04:00
Silo Server Migration 1ea3e078d3 feat(requests): sync search and tab state with URL params
- Persist tab, query, media type, and page in the URL so requests views are shareable and survive reloads
- Rename the "mine" tab to "yours" with backward-compatible normalization
- Require at least 2 characters before submitting a search
2026-05-25 10:48:48 -04:00
Silo Server Migration 7a9d7bcc94 fix(requests): clear prior failed rows on re-request
{"subject":"fix(requests): clear prior failed rows on re-request","body":""}
2026-05-25 10:02:06 -04:00
Silo Server Migration b5d9243942 fix(requests/radarr): decode tmdb lookup as single object
- Radarr's /api/v3/movie/lookup/tmdb returns a single MovieResource, not an array
- Update test fixtures to match the actual response shape
2026-05-25 02:22:14 -04:00
Silo Server Migration ee8aefb311 fix(web): remove padding on request detail routes 2026-05-25 02:09:28 -04:00
Silo Server Migration cc09e14154 feat(tmdb): cache discover and external ID responses
- Add TTL caches with singleflight for DiscoverSection, DiscoverPage, and GetExternalIDs to reduce upstream TMDB calls
- Reuse CastCarousel with a fullBleed variant on RequestDetail and drop the bespoke RequestCastRow
2026-05-25 02:02:33 -04:00
Silo Server Migration 9cf5062bf0 chore: restore tmdb project api key fallback and move requests nav
- tmdb client falls back to bundled project API key when none configured
- move Requests link next to Recommendations in the sidebar
2026-05-25 01:12:47 -04:00
Silo Server MigrationandClaude Opus 4.7 8a86e0cf08 refactor: tmdb and requests polish
- GetExternalIDs now uses the dedicated /movie/{id}/external_ids and
  /tv/{id}/external_ids endpoints instead of fetching the full detail
  with append_to_response=external_ids. The dedicated payload is
  one or two orders of magnitude smaller for the same fields.
- Document PosterPath/BackdropPath on MediaResult as raw TMDB path
  fragments that callers must prefix with the image base URL.
- normalizeCast switches from inline insertion sort to sort.SliceStable.
  The output is identical; the new form is one line and O(n log n).
- normalizeIntegration no longer reuses integration.Tags' backing
  array via Tags[:0]; the slice is callable code, so reusing the
  array would silently corrupt the caller's slice if it kept a
  reference. Allocate a fresh slice instead.
- HandleGet now requires a profile, matching the rest of the
  /requests user-group handlers. Router middleware enforces this
  already, but the inline check is defense-in-depth for any future
  remount.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 00:27:39 -04:00
Silo Server MigrationandClaude Opus 4.7 e8143d5757 chore: tighten local-path-leak guard scope and tooling
- Narrow the worktree-id/T3-path check to docs/superpowers/specs and
  docs/superpowers/plans. Scanning the whole repo flagged any
  legitimate reference to .t3/worktrees or t3code-<hex> (fixtures,
  example configs) and would block unrelated commits.
- Switch the pre-commit hook shebang to bash and call the check via
  an absolute path derived from git rev-parse so the hook works
  regardless of the cwd git happens to invoke it from.
- install-hooks now warns when it overwrites an existing
  core.hooksPath rather than silently clobbering a custom setup.
- Add make verify-local-paths to the AGENTS.md pre-MR checklist so
  contributors run it explicitly even when --no-verify is used.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 00:27:29 -04:00
Silo Server MigrationandClaude Opus 4.7 64765126b8 feat(web): replace decline prompt with dialog and polish list query
window.prompt for the admin decline reason was inaccessible (screen
reader announcements are inconsistent), unstylable, and blocked in
hardened environments. Replace with a controlled Dialog and a small
textarea so the decline UX matches the rest of the admin pages.

buildListQuery used a truthiness check on params.offset/params.limit
that silently dropped explicit zero values, leaving the URL out of
sync with the query key. Compare against null and positive numbers
instead.

Poster <img> elements had alt="" with no surrounding aria-label, so
screen readers reaching the cards via image-mode browsing got no
title. Use the poster's own title as the alt text.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 00:27:21 -04:00
Silo Server MigrationandClaude Opus 4.7 9250661aaa fix(tmdb): require an api key instead of falling back to a default
The client previously fell back to a hardcoded project-level API key
when the caller passed an empty string. Once committed the key cannot
be rotated without a rebuild, and the silent fallback meant that
misconfiguration produced unattributed traffic against a shared key.
Remove the default. Clients constructed with an empty key now return
ErrMissingAPIKey from every API call so operators see the
configuration problem immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 00:21:56 -04:00
Silo Server MigrationandClaude Opus 4.7 34f92fdc1d refactor(requests): consolidate shared Arr client helpers
The radarr and sonarr clients carried byte-identical copies of
rootFolderResource, qualityProfileResource, tagResource (and the
corresponding list helpers) plus acceptedWithoutResponse and
statusFromQueueEvaluation. Move the shared wire types and helpers
into the arrclient package and update the callers to use the
exported helpers. No behavior change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-25 00:21:50 -04:00