Mounted inside bearerAuth so the JTI is already validated. Revokes the
access JTI in abs_sessions and returns 204. Idempotent: re-calling on an
already-revoked JTI still returns 204. Refresh JTI is intentionally NOT
revoked here — clients that want hard sign-out-everywhere will use the
sessions endpoint added in Phase 3.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Mobile clients call refresh every ~22h to avoid the 24h access-token
re-login trap. Accepts the token via x-refresh-token header (real ABS
convention) or {refreshToken} body (legacy). Mints a fresh pair, persists
both new JTIs, then revokes the old refresh JTI atomically — if any step
in 3-4 fails, the old refresh stays valid and the client can retry.
Returns the user{accessToken, refreshToken} object AND top-level token
fields so mainline and 3rd-party clients both find their expected shape.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
handlePlayStart now looks up the persisted progress row and emits the
saved currentTime in the playback session manifest. Without this every
play start began at 0, breaking cross-device resume which is one of the
core ABS-app value props.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
cap shadowed the Go builtin. fetchCap matches the naming used elsewhere
in the file for the same kind of over-fetch ceiling.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
handleLibraryDetail now populates filterdata.authors and filterdata.series
from MediaStore so the iOS filter sheet has real options. Narrators,
genres, publishers, languages, tags stay empty arrays for now (Phase 1
will index those aggregations); empty arrays are gracefully handled by
the client.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Review follow-up to c0e9229. handleLibraryAuthors and handleLibrarySeries
fetched the page slice and reported len(results) as total, hiding the
next-page button for libraries with > 50 authors / > 25 series. Both
now over-fetch (cap 5000) and paginate locally so total is the real DB
row count. Also adds the "tags" key (and confirms "genres") on the play
session mediaMetadata map so strict 3rd-party clients dont crash on
undefined; this completes the empty-array guarantee Task 4 began on the
browse/detail surface. Strengthens the series slug test to pin actual
slugify output.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
3rd-party ABS clients (Plappa, AudioBookShelfFully) require id on every
authors[] and series[] entry to encode filter selections; missing IDs
made author/series chips dead-end. Also ensures genres and tags are
always non-nil arrays so clients that branch on .length don't crash.
Tags is empty for now (silo has no item-tag concept); shape is stable so
future tag work won't break clients.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Code-review follow-up to 36f68d5: the loginEnvelope refactor dropped the
x-return-tokens compatibility comment, and handleABSAuthorize's reuse of
a.UserID for displayName looked like a copy-paste. Both now explained.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Extracts the shared envelope builder so /authorize emits the same shape
as /login including accessToken (echoes the caller's bearer), libraries,
permissions, and full serverSettings. The previous /authorize omission
caused iOS resume-on-launch to fall back into re-login.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replaces second time.Now() call with now.UnixMilli() using the now var
already created higher up in completeLogin for token TTL math.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Adds itemTagsAccessible, itemTagsSelected, seriesHideFromContinueListening,
lastSeen, createdAt to the user object. Expands permissions to the eight
keys real ABS emits. Enriches serverSettings with the dozen-plus flags
official iOS/Android apps branch on (coverAspectRatio, dateFormat,
timeFormat, scannerDisableWatcher, chromecastEnabled, etc.).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Brings the pre-existing cred-validator error log into line with the new
keys added in cd4f629 (all use "err"). Adds "path" to the jwt-secret
fetch error log so it matches its sibling rejection logs.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Each rejection branch in bearerAuth now emits a slog line so failures
are traceable from journalctl. Login success path emits a debug line
confirming token persistence; this makes "I cant login" debuggable
without a tcpdump.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Step-by-step TDD plan for the login + critical-bug-fix phase. Eleven
tasks, each with file:line targets, complete code blocks, test code,
and exact verification commands. Lands diagnostic logging, login/
authorize envelope enrichment, author/series ID surfacing, filterdata
hydration, resume-position wire-up, POST /auth/refresh, and POST /logout.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Phased plan to bring silo-server's ABS-compat surface to full parity with
the canonical continuum-plugin-audiobooks reference so that official ABS
iOS/Android/3rd-party clients work end-to-end.
Phase 0: login + critical bug fixes (response shape, resume position,
filterdata, /auth/refresh, /logout).
Phase 1: bookmarks, collections, playlists, smart collections, RSS,
author/series detail, listening stats.
Phase 2: socket.io full event parity (~30 events) with cross-package
publisher hooks.
Phase 3: hardening — media tokens, device tracking, audit log.
Each phase ships as its own PR with its own implementation plan.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
origin/main adds 139_media_requests at the same number our local
audiobook branch had used for abs_sessions. Renumber ours to 147 to
free up 139 for the upstream migration. The schema_versions row is
updated in lockstep on the running database so the migrator sees the
abs_sessions migration as already applied at its new version.
Migrations 140-146 (podcast feeds, media_folders kind noop, audiobook
feature flag, abs playback sessions, podcast episode guid, audiobook
series, audiobook title cleanup) stay where they are — they don't
collide with anything on origin/main.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Detail page:
- collapse Chapters section behind header toggle (73-chapter pages no
longer push content below the fold)
- square cover frames throughout (audiobook covers are Audible-style 1:1,
not 2:3 book portrait)
- narrator picker dropdown when multiple narrations of the same book exist
- clickable genre badges (route to /audiobooks?genre=X)
- reordered so credits/rails sit above the chapter list
- Play-from-Start button forces remount via playToken counter (was a
no-op when player was already at position 0)
- regression test for the Play-from-Start fix
Mini bar / Now Listening:
- mini bar respects --app-sidebar-offset so it stops getting covered by
the desktop sidebar
- Now Listening adds overflow scroll + a labeled "Back to player" button
so controls are never inaccessible on short viewports
Library page:
- infinite scroll (replaces Previous/Next pagination)
- genre filter chip with X-to-clear
Scanner:
- 8-worker parallel reconcile (env SILO_AUDIOBOOK_SCAN_WORKERS to override)
- file-path-first dedup so cleaned titles don't collapse separate
narrations
- title cleanup at write time (strips "Read by X" / "(unabridged)"
suffixes; original tag preserved in original_title)
- audiobook_series upsert from tag-derived series_name/series_position
- secondary dedup check (author + narrator + year + duration ±0.5% +
title-prefix) so two folders of the same book attach to one row
Backend detail handler:
- new fetchAlsoByAuthor, fetchInSeries (with series row > 1 entry guard),
fetchSimilar (embedding-first with shared-genre fallback),
fetchOtherNarrations (regex-strips narrator suffix to group siblings)
- audiobookDetailResponse gained also_by_author, in_series,
similar_audiobooks, other_narrations fields
- list endpoint accepts a genre query param
Embeddings:
- BuildEmbeddingText branches on item.Type == "audiobook" to use
author/narrator credits instead of cast/director/writer
- mediaTypeLabel helper centralizes movie / "TV series" / audiobook
- ListEmbeddingTextCandidates SQL mirrors the Go branching exactly
- ItemsNeedingEmbedding and TotalMediaItemCount loosen status='matched'
gate to also include audiobooks (which don't go through TMDB match)
- FindSimilar gains a mediaType filter so cross-type results never appear
- callers in similar.go and personal.go pass the source item's type
Collections:
- MediaAudiobook MediaKind + audiobook(s) case in templateEligibleForLibrary
(stops offering broken movie/TV templates to audiobook libraries)
- useAddItemToCollection hook (user + admin/library endpoints)
- AddToCollectionDialog wired into audiobook detail and movie/series
ActionBar overflow menu
- ManualCollectionItemsEditor gained a search-and-add panel with
debounced live results
- QueryDefinition.media_scope, QuerySortRelevanceScope, ALL_MEDIA_SCOPES
extended to include "audiobook"
- CatalogFilterBar gained an Audiobooks media scope option
- parseCatalogMediaScope (backend) accepts "audiobook"
Migrations:
- 145_audiobook_series: per-book series_name/series_index with a
best-effort title-pattern backfill for the existing corpus
- 146_audiobook_title_cleanup: strips narrator suffix / (unabridged)
noise from existing titles, preserving raw in original_title
Scripts:
- scripts/dedup_audiobooks.py: one-shot merge for "Title" vs
"Title: Subtitle" duplicates, file-path-stable, dry-run by default
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- Always apply stats CTE + CROSS JOIN so single-word queries no longer flood results with description-only hits
- Require overview_rank >= 0.15 for overview-only fallback rows
- Switch title gate from contiguous LIKE to title_rank > 0 so reordered-token title matches aren't demoted
- Persist tab, query, media type, and page in the URL so requests views are shareable and survive reloads
- Rename the "mine" tab to "yours" with backward-compatible normalization
- Require at least 2 characters before submitting a search
- Add TTL caches with singleflight for DiscoverSection, DiscoverPage, and GetExternalIDs to reduce upstream TMDB calls
- Reuse CastCarousel with a fullBleed variant on RequestDetail and drop the bespoke RequestCastRow
- GetExternalIDs now uses the dedicated /movie/{id}/external_ids and
/tv/{id}/external_ids endpoints instead of fetching the full detail
with append_to_response=external_ids. The dedicated payload is
one or two orders of magnitude smaller for the same fields.
- Document PosterPath/BackdropPath on MediaResult as raw TMDB path
fragments that callers must prefix with the image base URL.
- normalizeCast switches from inline insertion sort to sort.SliceStable.
The output is identical; the new form is one line and O(n log n).
- normalizeIntegration no longer reuses integration.Tags' backing
array via Tags[:0]; the slice is callable code, so reusing the
array would silently corrupt the caller's slice if it kept a
reference. Allocate a fresh slice instead.
- HandleGet now requires a profile, matching the rest of the
/requests user-group handlers. Router middleware enforces this
already, but the inline check is defense-in-depth for any future
remount.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- Narrow the worktree-id/T3-path check to docs/superpowers/specs and
docs/superpowers/plans. Scanning the whole repo flagged any
legitimate reference to .t3/worktrees or t3code-<hex> (fixtures,
example configs) and would block unrelated commits.
- Switch the pre-commit hook shebang to bash and call the check via
an absolute path derived from git rev-parse so the hook works
regardless of the cwd git happens to invoke it from.
- install-hooks now warns when it overwrites an existing
core.hooksPath rather than silently clobbering a custom setup.
- Add make verify-local-paths to the AGENTS.md pre-MR checklist so
contributors run it explicitly even when --no-verify is used.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
window.prompt for the admin decline reason was inaccessible (screen
reader announcements are inconsistent), unstylable, and blocked in
hardened environments. Replace with a controlled Dialog and a small
textarea so the decline UX matches the rest of the admin pages.
buildListQuery used a truthiness check on params.offset/params.limit
that silently dropped explicit zero values, leaving the URL out of
sync with the query key. Compare against null and positive numbers
instead.
Poster <img> elements had alt="" with no surrounding aria-label, so
screen readers reaching the cards via image-mode browsing got no
title. Use the poster's own title as the alt text.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The client previously fell back to a hardcoded project-level API key
when the caller passed an empty string. Once committed the key cannot
be rotated without a rebuild, and the silent fallback meant that
misconfiguration produced unattributed traffic against a shared key.
Remove the default. Clients constructed with an empty key now return
ErrMissingAPIKey from every API call so operators see the
configuration problem immediately.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The radarr and sonarr clients carried byte-identical copies of
rootFolderResource, qualityProfileResource, tagResource (and the
corresponding list helpers) plus acceptedWithoutResponse and
statusFromQueueEvaluation. Move the shared wire types and helpers
into the arrclient package and update the callers to use the
exported helpers. No behavior change.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Each homepage discovery section fired a serial TMDB round trip with
its own presence lookup, so the response time grew linearly with the
number of sections (~1.2 s at 6 sections * 200 ms). Fan the calls out
across a bounded errgroup using the same concurrency cap as
external-id hydration. The first section to error cancels the rest
via the group context.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
syncRefreshDebtFailure unconditionally set RefreshDebtReasonRefreshFailure
on matched items, even when the refresh failed because the item is
missing a provider id. The priority logic already preferred
ProviderIDIncomplete (priority 240) over RefreshFailure (priority
190), so scheduling was correct — but the persisted reason mask
combined both bits and the reason-count metric reported these items
as "refresh failures" instead of "provider id incomplete". Guard the
OR so the failure bit only lands on items that actually have a
provider id and failed for a different reason.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Owners can now POST /requests/{id}/cancel to withdraw a pending
request; admins can cancel any active request that has not entered
the fulfillment pipeline. The route is mounted on both the user
group (with profile required) and the admin group. The cancelled
outcome was already reserved in the migration's CHECK constraint
but was unreachable from any handler.
Decline now also rejects approved requests — between Approve setting
StatusApproved and the reconciler picking the request up, an admin
could declare the request declined while submission was about to
fire. The reconciler's outcome filter would skip the request, but
the narrow window meant external state could diverge from Silo's
view. Refuse decline once a request is approved; callers should
wait for completion or use the failed/retry path.
Reconcile now emits a slog.WarnContext at the per-request failure
site with request id, media type, tmdb id, status, and integration
kind. Aggregated counters in ReconcileResult are unchanged.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Radarr and Sonarr can return HTTP 201 with no body when a movie or
series is added. The previous code returned an "accepted_without_response"
result with an empty ExternalID, which trapped the reconciler: every
subsequent CheckStatus call short-circuited on the empty ID and the
request never advanced past queued.
When the add POST decodes empty, look the freshly-added record up by
TMDB or TVDB ID via the standard list endpoints and use the resulting
Arr ID. Fall back to the previous accepted-without-response result
only when the lookup also returns no match, preserving the original
behavior as a safety net.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
CreateRequest previously read the user's request count outside the
insert transaction, so two concurrent submissions at MaxRequests-1
could both pass the quota gate and end up at MaxRequests+1. Move the
count inside the same transaction as the insert and acquire a per-user
advisory lock so concurrent inserts serialize. The store reports
ErrQuotaExceeded when the racing path catches the user at the limit
and the service maps it back to QuotaError.
normalizeListFilter previously reset limit to 50 when callers asked
for more than 100, which is surprising. Clamp to the cap instead so a
request for 150 returns 100 and a request for 1_000_000 still cannot
hit the database with an unbounded scan.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>