Gateway: MusicKit login page + callback route #5
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
Gateway service (see #18). This is the one interactive piece: a browser
flow that yields the Apple Music user token. The exact HTML to port already
exists in the plugin repo.
Task
Two routes in the FastAPI app:
GET /login— serve an HTML page that loadshttps://js-cdn.music.apple.com/musickit/v3/musickit.js, callsMusicKit.configure({developerToken: <fresh dev token>}), and on buttonclick runs
MusicKit.getInstance().authorize()then redirects to{GATEWAY_BASE_URL}/callback?media-user-token=....Port the page from
beets-appleplaylists/beetsplug/appleplaylists/auth.py(
_login_page). Embed the token withjson.dumps.GET /callback— parsemedia-user-tokenfrom the query string, store itvia
CredentialStore.save, render a plain success page ("Linked, you canclose this tab"). Never log the query string (the token would leak
into logs); the page must not echo the token either.
Deployment note (for the README, not code): the registered redirect URI on
the MusicKit Services ID must be the deployed https URL of
/callback.Acceptance criteria
containing a
MusicKit.configurecall; GET /callback with?media-user-token=abcstores "abc" and returns the success page; acallback without the parameter does not crash and stores nothing.
Done in
coop/apple-music-gateway(commitc8db51c):GET /loginserves the MusicKit JS login page (ported from the plugin'sauth.py::_login_page; dev token and{GATEWAY_BASE_URL}/callbackredirect embedded viajson.dumps);GET /callbackcapturesmedia-user-token(Query alias) into the CredentialStore and renders a success page that never echoes it. Query strings are scrubbed from the uvicorn access log (?[REDACTED]) so the token cannot leak via access logs either. README gained the deployment note (register the deployed https/callbackas the MusicKit redirect URI). 6 route tests incl. log-capture; behaviour also verified with a real uvicorn run (0600 DB, redacted access log).