navidrome/server/jellyfin/audiomuse.go
Deluan Quintão c66ef04dd3
refactor(jellyfin): emit real 128-bit GUIDs as item ids (#5942)
* test(jellyfin): use canonical ids in dto fixtures

Fixtures used short placeholder strings, which are not valid Navidrome ids. Deriving them from
id.NewHash keeps the labels readable while exercising the real id shape.

* test(jellyfin): use canonical ids in handler fixtures

Fixtures used short placeholder strings, which are not valid Navidrome ids. Deriving them from
id.NewHash keeps the labels readable while exercising the real id shape. Playlist entry positions
stay decimal, matching the integer playlist_tracks.id column.

* test(jellyfin): use canonical ids in e2e fixtures

Fixtures used short placeholder strings, which are not valid Navidrome ids. Deriving them from
id.NewHash keeps the labels readable while exercising the real id shape.

* test(jellyfin): use canonical ids in audiomuse fixtures

audiomuse_test.go passes ids as bare function args (mf(id, ...), call(query, user)) rather than
via ID: struct-literal fields, so the original grep-built file list missed it. Same conversion as
the rest of the fixtures: fake labels through id.NewHash via testID.

* test(jellyfin): convert remaining nonexistent-id sentinels in e2e tests

Reviewer swept for enc("literal") sites the brief's dto.EncodeID grep missed. These "does not
exist" fixtures must stay well-formed GUIDs under the strict codec, or the test degrades from
"resolves to nothing" to "empty path segment".

* refactor(jellyfin): emit real 128-bit GUIDs as item ids

Navidrome ids are now a canonical 22-char base62 encoding of exactly 128 bits, so they map
losslessly onto Jellyfin GUIDs. Previously the API hex-encoded the id string itself, producing
44 hex chars where Jellyfin uses 32.

Integer library ids, the synthetic playlists folder, and playlist entry positions (a
playlist_tracks.id, an integer column) aren't 128-bit values, so they get a reserved GUID space
tagged by kind. DecodeID is now strict: malformed input returns an empty string instead of
passing through unchanged.

BREAKING: Jellyfin clients see entirely new item ids.

* fix(jellyfin): 404 malformed playlist ids instead of silently creating

updatePlaylist decoded a malformed playlistId to "", the same sentinel core/playlists.Create
uses to mean "make a new playlist" — the overload createPlaylist deliberately relies on. A
malformed id now 404s before reaching Create.

Also tightens id-codec test fixtures: several tests set chi params to a raw canonical id, which
now decodes to "" and only passed because the fakes ignore the id argument; and a batch of
not-found sentinels now use well-formed-but-nonexistent GUIDs so they exercise the intended path
instead of the malformed-id path. READMEs "lossless" claim softened to note the reserved space.

* refactor(jellyfin): drop the id truncation workaround

Finamp's saved-queue packing keeps the first 16 bytes of each item id. That was lossy only
because our ids were 44 hex chars; now they are 32, so the packing round-trips exactly and the
server-side prefix recovery is dead code.

Removes an indexed range scan per restored queue and the ambiguous-prefix path that could
resolve to the wrong item.

* fix(jellyfin): emit ServerId and PlaySessionId in Jellyfin's id format

Jellyfin serializes GUIDs without dashes; ServerId was emitting the dashed UUID form. A
ServerId persisted before this change is normalized on read rather than rewritten.

PlaySessionId was emitting a raw internal id instead of the encoded form.

BREAKING: the ServerId change makes clients treat the server as new, so users re-login once.

* fix(jellyfin): 404 on undecodable id filters instead of widening the query

DecodeID collapsed an absent param and an undecodable one into the empty string, and downstream
an empty id means no filter. A client sending a stale pre-upgrade id therefore had its filter
silently dropped: ParentId, ArtistIds and AlbumArtistIds each returned the whole library instead
of a scoped result. Every existing client hits this on first launch after the id format changes.

Scalar id params now distinguish the two cases and report not-found. List-valued params already
failed closed. EncodeID logs a diagnostic when a non-empty id is not canonical, which should not
happen post-migration and would otherwise ship an unaddressable item silently.

* test(jellyfin): drop comments that restate the spec names

* refactor(jellyfin): decode reserved GUIDs from bytes, not hex strings

DecodeID already had the 16 decoded bytes, then re-derived the kind tag and payload by slicing the
hex string and parsing it a second time. Reading them off the byte slice matches how the format is
specified and removes the duplicate parse.

Bounding the payload inside encodeReserved gives both encoders the 32-char guarantee, which only
EncodePlaylistEntryID enforced before.

Playlist entries now decode through DecodePlaylistEntryID, which rejects other kinds. The tag was
being encoded and then discarded, so a song id passed as an EntryId reached RemoveTracks as a
playlist_tracks position.

Drops the per-field log.Warn from EncodeID: it sat in a leaf codec without a ctx and would emit
once per item per request on exactly the bad-data population it was meant to surface.

* refactor(jellyfin): make DecodeID report whether the id was decodable

DecodeID returned the empty string for both an absent param and an undecodable one, and
downstream an empty id means no filter. That conflation is what let a stale id widen /Items to
the whole library; it had been patched at two call sites, leaving three different policies for an
undecodable id in one package and ~16 handlers correct only because a repo Get("") happens to fail.

Returning (string, bool) makes the ambiguity unrepresentable, and the compiler forces each of the
~22 sites to decide. URL params share one itemIDParam helper that 404s; id lists go through
DecodeIDs, which is all-or-nothing because dropping bad entries would empty a list and make its
len() > 0 filter gate vanish — the original bug by another route.

A well-formed but unknown id is still 200 with zero results; only malformed ids 404. Malformed
ids now also 404 on the image and similar/instant-mix routes, which previously answered with a
placeholder or an empty list.
2026-08-12 19:02:34 -04:00

168 lines
4.7 KiB
Go

package jellyfin
import (
"net/http"
"strings"
"github.com/navidrome/navidrome/consts"
"github.com/navidrome/navidrome/model/request"
"github.com/navidrome/navidrome/server/jellyfin/dto"
"github.com/navidrome/navidrome/utils/req"
)
// audioMuseEndpoints is what /AudioMuseAI/info advertises; it omits info itself, like the plugin,
// and is sorted the same way (the plugin builds it with OrderBy).
var audioMuseEndpoints = []string{
"GET /AudioMuseAI/find_path",
"GET /AudioMuseAI/health",
"GET /AudioMuseAI/similar_tracks",
}
type audioMuseInfoResponse struct {
Version string `json:"Version"`
AvailableEndpoints []string `json:"AvailableEndpoints"`
}
func (api *Router) audioMuseInfo(w http.ResponseWriter, r *http.Request) {
endpoints := []string{} // non-nil so an empty list serializes as [], not null
if api.sonic != nil && api.sonic.HasProvider() {
endpoints = audioMuseEndpoints
}
api.ok(w, r, audioMuseInfoResponse{
Version: consts.Version,
AvailableEndpoints: endpoints,
})
}
// audioMuseHealth is a liveness probe: 200 with an empty body when a sonic provider is loaded, else
// 404 — mirroring the reference plugin, which returns 200 when its backend is reachable.
func (api *Router) audioMuseHealth(w http.ResponseWriter, r *http.Request) {
if api.sonic == nil || !api.sonic.HasProvider() {
api.notFound(w, r)
return
}
w.WriteHeader(http.StatusOK)
}
type audioMuseSimilarTrack struct {
Author string `json:"author"`
Distance float64 `json:"distance"`
ItemID string `json:"item_id"`
Title string `json:"title"`
}
func (api *Router) audioMuseSimilarTracks(w http.ResponseWriter, r *http.Request) {
ctx := r.Context()
// 404 without a provider, like the Subsonic sonicSimilarity handlers.
if api.sonic == nil || !api.sonic.HasProvider() {
api.notFound(w, r)
return
}
p := req.Params(r)
tracks := []audioMuseSimilarTrack{}
itemID := p.StringOr("item_id", "")
id, ok := dto.DecodeID(itemID)
if !ok {
// Every other failure here (no provider, no match) degrades to an empty list rather than an
// error, so a malformed id does too instead of being the one path that 404s.
api.ok(w, r, tracks)
return
}
n := min(p.IntOr("n", 10), maxSimilarLimit) // cap a user-controlled count, like clampLimit
eliminateDuplicates := p.BoolOr("eliminate_duplicates", true)
matches, err := api.sonic.GetSonicSimilarTracks(ctx, id, n)
if err != nil {
api.ok(w, r, tracks)
return
}
u, _ := request.UserFrom(ctx)
seenArtists := make(map[string]bool, len(matches))
for _, m := range matches {
mf := m.MediaFile
if !u.HasLibraryAccess(mf.LibraryID) {
continue
}
if eliminateDuplicates {
key := strings.ToLower(mf.Artist)
if seenArtists[key] {
continue
}
seenArtists[key] = true
}
tracks = append(tracks, audioMuseSimilarTrack{
Author: mf.Artist,
Distance: m.Similarity,
ItemID: dto.EncodeID(mf.ID),
Title: mf.Title,
})
}
api.ok(w, r, tracks)
}
type audioMusePathTrack struct {
Author string `json:"author"`
ItemID string `json:"item_id"`
Title string `json:"title"`
Tempo *float64 `json:"tempo,omitempty"`
}
type audioMusePathResponse struct {
Path []audioMusePathTrack `json:"path"`
TotalDistance float64 `json:"total_distance"`
}
func (api *Router) audioMuseFindPath(w http.ResponseWriter, r *http.Request) {
ctx := r.Context()
if api.sonic == nil || !api.sonic.HasProvider() {
api.notFound(w, r)
return
}
p := req.Params(r)
startID := p.StringOr("start_song_id", "")
endID := p.StringOr("end_song_id", "")
if startID == "" || endID == "" {
http.Error(w, "start_song_id and end_song_id are required.", http.StatusBadRequest)
return
}
resp := audioMusePathResponse{Path: []audioMusePathTrack{}}
startDecoded, startOk := dto.DecodeID(startID)
endDecoded, endOk := dto.DecodeID(endID)
if !startOk || !endOk {
// This endpoint already 400s when an endpoint id is absent, so an unusable one reports the
// same way rather than looking like a successful search that found no path.
http.Error(w, "start_song_id and end_song_id must be valid item ids.", http.StatusBadRequest)
return
}
maxSteps := min(p.IntOr("max_steps", 25), maxSimilarLimit) // cap a user-controlled count
matches, err := api.sonic.FindSonicPath(ctx, startDecoded, endDecoded, maxSteps)
if err != nil {
api.ok(w, r, resp)
return
}
u, _ := request.UserFrom(ctx)
for _, m := range matches {
mf := m.MediaFile
if !u.HasLibraryAccess(mf.LibraryID) {
continue
}
track := audioMusePathTrack{
Author: mf.Artist,
ItemID: dto.EncodeID(mf.ID),
Title: mf.Title,
}
if mf.BPM != nil {
tempo := float64(*mf.BPM)
track.Tempo = &tempo
}
resp.Path = append(resp.Path, track)
resp.TotalDistance += m.Similarity
}
api.ok(w, r, resp)
}