Gateway: SQLite credential store for the Apple user token #4
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
Gateway service (see #18). The gateway stores exactly one Apple user token
(the
media-user-tokenfrom the login flow) in SQLite.Task
app/credential_store.py: aCredentialStore(path) class withload() -> str | None,save(token: str),clear() -> bool:apple_auth (id INTEGER PRIMARY KEY CHECK (id = 1), media_user_token TEXT NOT NULL, updated_at TEXT NOT NULL)— STRICTos.open(O_CREAT|O_EXCL)pattern; existing files never chmodded, but warn if group/other bits are
set (mirror
beets-playlistmanager/database.py::open_database)playlistmanager's
PlaylistStore)Acceptance criteria
warning on a world-readable existing file,
load()returns None on amissing file.
Done in
coop/apple-music-gateway(commitc8db51c):app/credential_store.py—CredentialStore(path)withload() -> str | None,save(token) -> updated_at,clear() -> bool. Single-row STRICT tableapple_auth (id CHECK (id = 1), media_user_token, updated_at); transactional writes (BEGIN IMMEDIATE/commit/rollback); new files created owner-only viaos.open(O_CREAT|O_EXCL); existing files never chmodded but warn (InsecureCredentialStoreWarning) when group/other bits are set; lazy store —load()on a missing file returns None and creates nothing. 11 unit tests cover round-trip, clear, 0600 creation, warning on world/group-readable files (mode left untouched), missing-file load, idempotent schema on an existing file, single-row upsert, empty-token rejection, and:memory:.