Step 7.5a: Spotify client credentials in config/UI, write-only secrets
- Core config: cfg_mark_secret(group, key). GET /api/config returns ""
for secret keys; a POST with "" keeps the stored value, null clears it;
cfg_get() returns the real value. Documented in aes67-core-base.md.
- source.spotify_client_id / spotify_client_secret (secret write-only):
each user's own Spotify developer app, needed by the maintained cspot
fork (philippe44/cspot) since Spotify's 2025 API restrictions.
- UI: client ID field, password field for the secret ("leave empty to
keep"), link to developer.spotify.com; enabled for spotify/auto modes.
- status.spotify_state: "no client credentials" while either is missing.
- Verified: secret never appears in GET; UI-style re-save keeps it;
survives reboot; null clears it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
+5
-1
@@ -95,7 +95,11 @@ static void player_status(cJSON *st)
|
||||
s_src == SRC_SPOTIFY ? "not implemented" : s_playing ? "playing" : "buffering";
|
||||
cJSON_AddStringToObject(st, "active_source", SRC_NAME[s_src]);
|
||||
cJSON_AddStringToObject(st, "source_state", state);
|
||||
cJSON_AddStringToObject(st, "spotify_state", "not implemented");
|
||||
cJSON *src = cfg_get("source");
|
||||
bool creds = cJSON_GetObjectItemCaseSensitive(src, "spotify_client_id")->valuestring[0] &&
|
||||
cJSON_GetObjectItemCaseSensitive(src, "spotify_client_secret")->valuestring[0];
|
||||
cJSON_Delete(src);
|
||||
cJSON_AddStringToObject(st, "spotify_state", creds ? "not implemented" : "no client credentials");
|
||||
cJSON_AddNumberToObject(st, "buffer_ms", (double)(audio_ring_level() * 1000 / RATE));
|
||||
}
|
||||
|
||||
|
||||
+6
-1
@@ -7,7 +7,8 @@
|
||||
|
||||
static const char SOURCE_DEFAULTS[] =
|
||||
"{\"mode\":\"spotify\",\"spotify_name\":\"P4 AES67\",\"spotify_bitrate\":320,\"hls_url\":\"\","
|
||||
"\"autoplay\":false,\"gain_db\":0,\"failover_delay_s\":5,\"failover_on_pause\":false}";
|
||||
"\"autoplay\":false,\"gain_db\":0,\"failover_delay_s\":5,\"failover_on_pause\":false,"
|
||||
"\"spotify_client_id\":\"\",\"spotify_client_secret\":\"\"}";
|
||||
|
||||
static bool source_validate(const cJSON *g, char *err, size_t n)
|
||||
{
|
||||
@@ -17,6 +18,8 @@ static bool source_validate(const cJSON *g, char *err, size_t n)
|
||||
cfg_check_str(g, "spotify_name", 1, 63, err, n) &&
|
||||
cfg_check_num_in(g, "spotify_bitrate", bitrates, 3, err, n) &&
|
||||
cfg_check_str(g, "hls_url", 0, 255, err, n) &&
|
||||
cfg_check_str(g, "spotify_client_id", 0, 64, err, n) &&
|
||||
cfg_check_str(g, "spotify_client_secret", 0, 64, err, n) &&
|
||||
cfg_check_num(g, "gain_db", -60, 12, err, n) &&
|
||||
cfg_check_int(g, "failover_delay_s", 0, 3600, err, n);
|
||||
}
|
||||
@@ -31,4 +34,6 @@ void project_cfg_defaults(void)
|
||||
void project_cfg_register(void)
|
||||
{
|
||||
ESP_ERROR_CHECK(cfg_register("source", SOURCE_DEFAULTS, source_validate, player_apply));
|
||||
// Each user's own Spotify developer app (developer.spotify.com); the secret is write-only.
|
||||
ESP_ERROR_CHECK(cfg_mark_secret("source", "spotify_client_secret"));
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user