The Audiobookshelf-compat surface sits outside the monitoring and kill design
entirely — neither architecture matrix mentioned it. Three routes pour full
media and none consulted the kill switch:
- /(abs/)api/items/{id}/file/{ino} and /download — bearer auth, no revocation
check, no in-flight cut.
- /(abs/)public/session/{sid}/track/{idx} — mounted outside bearerAuth (the
session id is the capability); it held a transport marker but was unkillable.
- /feed/{slug}/file/{ino} — no auth at all, the slug is the capability;
invisible and unkillable, and closing a feed only blocked the next request
rather than cutting a pour already in flight.
Each surface now passes its real credential-issue time, because a user
revocation is a cutoff, not a ban: it matches only streams whose credential
predates it. ABS bearer tokens are stateless JWTs that OnUserSessionsRevoked
does not delete, so passing request-entry time (as the jellycompat login path
safely does) would have meant a user kill never refused a later ABS request.
- bearerAuth carries the JWT's iat into ctxAuth; the authenticated file route
uses it.
- The public track uses the persisted playback session's StartedAt and passes
the native session id so session-level kills land too, plus the shared
metered writer for byte accounting.
- The feed file uses the feed's CreatedAt for an owner cutoff — a feed opened
before the revocation dies, one opened after re-authenticating serves — and
arms the in-flight cut.
The authenticated file route stays download-class: like the native and
jellycompat download routes it is exempt from the live-stream cap and from
streammonitor, and is covered by no download quota. It is now killable and
explicitly documented rather than quietly invisible. Bringing all three
download-class routes under one quota and one monitor record is tracked as a
follow-up rather than adding a fourth per-route model here.
Part of the stream monitoring & kill-switch epic.