Repository navigation
fix(dlna): drop DLNA_PSEUDO_USER, stream as the owner - #281
Merged
Merged
Conversation
This was referenced Sep 14, 2026
DLNA browsed as the owner but signed stream cast tokens for a separately configurable pseudo-user. That user only changed the name on stream_operations rows and on peer x-poutine-user headers. It gated nothing, since kind='dlna' already separates DLNA activity, but it added failure modes: a missing or deleted pseudo-user made every stream return 401 while browse kept working, and the #274 owner guard did not cover it. Browse and stream now use one identity, the owner. Boot logs an error when DLNA is enabled without an owner username, which can only happen in dev because prod requires one. closes #280 closes #188 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CNTqdCoTsmaZ6cqH1x5VRn
benders
force-pushed
the
feature/280-dlna-owner-attribution
branch
from
September 14, 2026 17:12
e8eecc8 to
0c21df1
Compare
benders
marked this pull request as ready for review
September 14, 2026 17:36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
DLNA_PSEUDO_USERenv var. DLNA cast tokens are now signed for the owner, the same user Browse already runs as.DLNA_ENABLED=trueand noPOUTINE_OWNER_USERNAMEis set (dev only; prod already requires one). Closes DLNA: fail-fast at boot when no pseudo-user is resolvable #188.docs/dlna.md,docs/system-architecture.md,SECURITY.md,example.env, OpenSubsonic survey wording.Why
The pseudo-user only changed which name showed up in
stream_operationsand in peerx-poutine-userheaders. It didn't affect play counts, permissions or isolation, andkind='dlna'already separates DLNA activity. It did add failure modes: if the user was missing or deleted, every stream returned 401 while browse kept working, and the owner-delete guard from #274/#276 didn't cover it. With one identity, that guard now protects DLNA fully. Discussion: #280.Operator impact
Installs that set
DLNA_PSEUDO_USERwill now see DLNA streams under the owner in Activity and on peers. The variable is ignored if it's still set.Testing
pnpm verify: green.pnpm test:federation: not run locally. The federation suite doesn't exercise DLNA and the Subsonic/federation contract is unchanged; the CIfederationjob gates it.closes #280
closes #188
🤖 Generated with Claude Code
https://claude.ai/code/session_01CNTqdCoTsmaZ6cqH1x5VRn