Skip to content

fix(dlna): drop DLNA_PSEUDO_USER, stream as the owner - #281

Merged
benders merged 1 commit into
mainfrom
feature/280-dlna-owner-attribution
Sep 14, 2026
Merged

benders merged 1 commit into
mainfrom
feature/280-dlna-owner-attribution

Conversation

@benders

@benders benders commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Summary

  • Removes the DLNA_PSEUDO_USER env var. DLNA cast tokens are now signed for the owner, the same user Browse already runs as.
  • Logs a boot error when DLNA_ENABLED=true and no POUTINE_OWNER_USERNAME is set (dev only; prod already requires one). Closes DLNA: fail-fast at boot when no pseudo-user is resolvable #188.
  • Docs: docs/dlna.md, docs/system-architecture.md, SECURITY.md, example.env, OpenSubsonic survey wording.
  • Regression test: Browse passes the owner as the stream-token user.

Why

The pseudo-user only changed which name showed up in stream_operations and in peer x-poutine-user headers. It didn't affect play counts, permissions or isolation, and kind='dlna' already separates DLNA activity. It did add failure modes: if the user was missing or deleted, every stream returned 401 while browse kept working, and the owner-delete guard from #274/#276 didn't cover it. With one identity, that guard now protects DLNA fully. Discussion: #280.

Operator impact

Installs that set DLNA_PSEUDO_USER will now see DLNA streams under the owner in Activity and on peers. The variable is ignored if it's still set.

Testing

  • pnpm verify: green.
  • pnpm test:federation: not run locally. The federation suite doesn't exercise DLNA and the Subsonic/federation contract is unchanged; the CI federation job gates it.

closes #280
closes #188

🤖 Generated with Claude Code

https://claude.ai/code/session_01CNTqdCoTsmaZ6cqH1x5VRn

@benders

benders commented Sep 14, 2026

Copy link
Copy Markdown
Owner Author

FROM @claude:

The federation failure here (test_get_cover_art, HTTP 400) is unrelated to this change. Navidrome 0.64.0 broke it on every PR. The fix is tracked in #283 / #284; once #284 merges, merging main into this branch should turn it green.

DLNA browsed as the owner but signed stream cast tokens for a separately
configurable pseudo-user. That user only changed the name on
stream_operations rows and on peer x-poutine-user headers. It gated
nothing, since kind='dlna' already separates DLNA activity, but it added
failure modes: a missing or deleted pseudo-user made every stream
return 401 while browse kept working, and the #274 owner guard did not
cover it.

Browse and stream now use one identity, the owner. Boot logs an error
when DLNA is enabled without an owner username, which can only happen
in dev because prod requires one.

closes #280
closes #188

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CNTqdCoTsmaZ6cqH1x5VRn
@benders
benders force-pushed the feature/280-dlna-owner-attribution branch from e8eecc8 to 0c21df1 Compare September 14, 2026 17:12
@benders
benders marked this pull request as ready for review September 14, 2026 17:36
@benders
benders merged commit 8cdde80 into main Sep 14, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DLNA: remove DLNA_PSEUDO_USER, attribute streams to the owner DLNA: fail-fast at boot when no pseudo-user is resolvable

1 participant