Step 7.5a: Spotify client credentials in config/UI, write-only secrets
- Core config: cfg_mark_secret(group, key). GET /api/config returns ""
for secret keys; a POST with "" keeps the stored value, null clears it;
cfg_get() returns the real value. Documented in aes67-core-base.md.
- source.spotify_client_id / spotify_client_secret (secret write-only):
each user's own Spotify developer app, needed by the maintained cspot
fork (philippe44/cspot) since Spotify's 2025 API restrictions.
- UI: client ID field, password field for the secret ("leave empty to
keep"), link to developer.spotify.com; enabled for spotify/auto modes.
- status.spotify_state: "no client credentials" while either is missing.
- Verified: secret never appears in GET; UI-style re-save keeps it;
survives reboot; null clears it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -18,6 +18,9 @@ esp_err_t cfg_override_defaults(const char *group, const char *json);
|
||||
// Register a group. Stored values (NVS) are loaded immediately, merged over the defaults.
|
||||
esp_err_t cfg_register(const char *group, const char *defaults_json,
|
||||
cfg_validate_cb_t validate, cfg_apply_cb_t apply);
|
||||
// Write-only key (e.g. a password): GET /api/config returns "" for it; a POST with "" keeps the
|
||||
// stored value, null clears it. cfg_get() still returns the real value. Call after cfg_register().
|
||||
esp_err_t cfg_mark_secret(const char *group, const char *key);
|
||||
// Copy of a group's current values; caller frees with cJSON_Delete. NULL if not registered.
|
||||
cJSON *cfg_get(const char *group);
|
||||
// Firmware-side change of one number (e.g. aes67.session_ver): stored like a POST, no validation.
|
||||
|
||||
Reference in New Issue
Block a user