Gateway: ES256 developer-token signer with expiry refresh #3
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
Gateway service (see #18). The gateway signs the MusicKit developer JWT that
both the login page and Apple API calls need.
Task
app/apple_auth.py: aDevTokenSigner(or similar) that.p8key (PEM EC P-256) and signs{"iss": team_id, "iat": now, "exp": now + 15777000}with ES256 viaPyJWT, header
{"kid": key_id}—jwt.encode(payload, key_pem, algorithm="ES256", headers={"kid": key_id})expis less than30 days away (Apple caps lifetime at ~6 months)
team/key ids are missing.
Never log the token. Thread-safety: the app is async (FastAPI); protect the
cache with a lock or make signing cheap enough to do per-call.
Acceptance criteria
iss/kidarecorrect,
exp - iat == 15777000.re-signing; past the threshold a new token is minted.
Done in
coop/apple-music-gateway(commit37d3fa7):app/apple_auth.py—DevTokenSignersigns ES256 JWT (iss=team id, iat=now, exp=now+15777000, kid header) from the .p8 key; in-memory cache under a lock re-signs only when expiry is <30 days away; clearDevTokenErrorfor missing ids / unreadable key / bad key material; token never logged, excluded from repr. 22 tests pass with a real generated P-256 key (verified decode incl. signature, iss/kid, exp-iat, cache/refresh boundaries, concurrency).