2026-07-27 08:16:20 +12:00
|
|
|
package api
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"encoding/json"
|
|
|
|
|
"net/http"
|
|
|
|
|
"strings"
|
2026-08-02 22:10:19 +12:00
|
|
|
"time"
|
2026-07-27 08:16:20 +12:00
|
|
|
|
|
|
|
|
"github.com/ponzischeme89/memby/server/internal/cache"
|
2026-07-27 21:06:51 +12:00
|
|
|
"github.com/ponzischeme89/memby/server/internal/emby"
|
2026-07-27 08:16:20 +12:00
|
|
|
"github.com/ponzischeme89/memby/server/internal/store"
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
type loginRequest struct {
|
2026-07-27 21:06:51 +12:00
|
|
|
Username string `json:"username"`
|
|
|
|
|
Password string `json:"password"`
|
|
|
|
|
DeviceID string `json:"deviceId"`
|
|
|
|
|
DeviceName string `json:"deviceName"`
|
2026-07-27 08:16:20 +12:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
type loginResponse struct {
|
2026-08-02 22:10:19 +12:00
|
|
|
Token string `json:"token"`
|
|
|
|
|
UserID string `json:"userId"`
|
|
|
|
|
Username string `json:"username"`
|
|
|
|
|
ServerID string `json:"serverId"`
|
2026-07-27 21:06:51 +12:00
|
|
|
}
|
|
|
|
|
|
2026-08-02 22:10:19 +12:00
|
|
|
type deviceSessionResponse struct {
|
|
|
|
|
DeviceID string `json:"deviceId"`
|
|
|
|
|
DeviceName string `json:"deviceName"`
|
|
|
|
|
ClientVersion string `json:"clientVersion,omitempty"`
|
|
|
|
|
LastSeenAt time.Time `json:"lastSeenAt"`
|
|
|
|
|
Current bool `json:"current"`
|
2026-07-27 21:06:51 +12:00
|
|
|
}
|
|
|
|
|
|
2026-08-02 22:10:19 +12:00
|
|
|
type renameDeviceRequest struct {
|
|
|
|
|
DeviceName string `json:"deviceName"`
|
2026-07-27 08:16:20 +12:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// handleLogin exchanges Emby credentials for a gateway token.
|
|
|
|
|
//
|
|
|
|
|
// The Emby access token stays here: the TV only ever holds the gateway token, so
|
|
|
|
|
// revoking a device is a DELETE in Postgres rather than an Emby-side cleanup.
|
|
|
|
|
func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
|
|
|
|
|
var req loginRequest
|
|
|
|
|
if err := json.NewDecoder(http.MaxBytesReader(w, r.Body, 8<<10)).Decode(&req); err != nil {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "malformed request body")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
req.Username = strings.TrimSpace(req.Username)
|
|
|
|
|
if req.Username == "" {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "username is required")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
if req.DeviceID == "" {
|
|
|
|
|
req.DeviceID = "memby-tv"
|
|
|
|
|
}
|
2026-07-27 21:06:51 +12:00
|
|
|
req.DeviceName = strings.TrimSpace(req.DeviceName)
|
|
|
|
|
if req.DeviceName == "" {
|
|
|
|
|
// Compatibility for APKs released before device naming. New clients require an
|
|
|
|
|
// editable name in their UI, but an older TV must still be able to sign in while
|
|
|
|
|
// the household rollout is in progress.
|
|
|
|
|
req.DeviceName = "Memby TV"
|
|
|
|
|
}
|
|
|
|
|
if len([]rune(req.DeviceName)) > 80 {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "device name is too long")
|
|
|
|
|
return
|
|
|
|
|
}
|
2026-07-27 08:16:20 +12:00
|
|
|
|
2026-07-27 21:06:51 +12:00
|
|
|
auth, err := s.emby.Authenticate(
|
|
|
|
|
r.Context(), req.Username, req.Password, req.DeviceID, req.DeviceName,
|
|
|
|
|
)
|
2026-07-27 08:16:20 +12:00
|
|
|
if err != nil {
|
|
|
|
|
// Never echo Emby's body here: a failed sign-in is the one place a wrong
|
|
|
|
|
// password could be reflected back.
|
|
|
|
|
s.log.Warn("emby authentication failed", "username", req.Username)
|
|
|
|
|
writeError(w, http.StatusUnauthorized, "sign-in failed")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
token, err := newToken()
|
|
|
|
|
if err != nil {
|
|
|
|
|
s.log.Error("token generation failed", "error", err)
|
|
|
|
|
writeError(w, http.StatusInternalServerError, "could not issue a token")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
sess := store.Session{
|
2026-08-02 22:10:19 +12:00
|
|
|
TokenHash: hashToken(token),
|
|
|
|
|
EmbyUserID: auth.User.ID,
|
|
|
|
|
EmbyToken: auth.AccessToken,
|
|
|
|
|
Username: auth.User.Name,
|
|
|
|
|
ServerID: auth.ServerID,
|
|
|
|
|
DeviceID: req.DeviceID,
|
|
|
|
|
DeviceName: req.DeviceName,
|
|
|
|
|
ClientVersion: clientVersion(r),
|
|
|
|
|
ClientProtocol: clientProtocol(r),
|
|
|
|
|
ClientCapabilities: clientCapabilities(r),
|
2026-07-27 08:16:20 +12:00
|
|
|
}
|
|
|
|
|
if sess.Username == "" {
|
|
|
|
|
sess.Username = req.Username
|
|
|
|
|
}
|
2026-08-02 22:10:19 +12:00
|
|
|
replacedHash, err := s.store.CreateSession(r.Context(), sess)
|
2026-07-27 21:06:51 +12:00
|
|
|
if err != nil {
|
|
|
|
|
_ = s.emby.Logout(r.Context(), emby.Credentials{
|
|
|
|
|
UserID: auth.User.ID, Token: auth.AccessToken,
|
|
|
|
|
DeviceID: req.DeviceID, DeviceName: req.DeviceName,
|
|
|
|
|
})
|
2026-07-27 08:16:20 +12:00
|
|
|
s.log.Error("session persist failed", "error", err)
|
|
|
|
|
writeError(w, http.StatusInternalServerError, "could not start a session")
|
|
|
|
|
return
|
|
|
|
|
}
|
2026-07-27 21:06:51 +12:00
|
|
|
if len(replacedHash) > 0 {
|
|
|
|
|
_ = s.cache.Delete(r.Context(), cache.SessionKey(hexHash(replacedHash)))
|
|
|
|
|
}
|
2026-07-29 15:26:27 +12:00
|
|
|
if s.forYou != nil {
|
|
|
|
|
s.forYou.MarkDirty(r.Context(), sess)
|
|
|
|
|
s.forYou.RefreshAsync(sess, false)
|
|
|
|
|
}
|
2026-07-27 08:16:20 +12:00
|
|
|
|
|
|
|
|
writeJSON(w, http.StatusOK, loginResponse{
|
2026-08-02 22:10:19 +12:00
|
|
|
Token: token, UserID: sess.EmbyUserID, Username: sess.Username, ServerID: sess.ServerID,
|
2026-07-27 08:16:20 +12:00
|
|
|
})
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request, sess store.Session) {
|
|
|
|
|
if err := s.store.DeleteSession(r.Context(), sess.TokenHash); err != nil {
|
|
|
|
|
s.log.Error("session delete failed", "error", err)
|
|
|
|
|
}
|
|
|
|
|
_ = s.cache.Delete(r.Context(), cache.SessionKey(hexHash(sess.TokenHash)))
|
|
|
|
|
_ = s.cache.InvalidateUser(r.Context(), sess.EmbyUserID)
|
|
|
|
|
w.WriteHeader(http.StatusNoContent)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// handleSession lets the TV confirm a stored token is still good before rendering.
|
|
|
|
|
func (s *Server) handleSession(w http.ResponseWriter, _ *http.Request, sess store.Session) {
|
|
|
|
|
writeJSON(w, http.StatusOK, loginResponse{
|
2026-08-02 22:10:19 +12:00
|
|
|
UserID: sess.EmbyUserID, Username: sess.Username, ServerID: sess.ServerID,
|
2026-07-27 08:16:20 +12:00
|
|
|
})
|
|
|
|
|
}
|
2026-08-02 22:10:19 +12:00
|
|
|
|
|
|
|
|
func (s *Server) handleDevices(w http.ResponseWriter, r *http.Request, current store.Session) {
|
|
|
|
|
sessions, err := s.store.SessionsForUser(r.Context(), current.EmbyUserID)
|
|
|
|
|
if err != nil {
|
|
|
|
|
s.log.Error("device list failed", "error", err)
|
|
|
|
|
writeError(w, http.StatusInternalServerError, "could not list devices")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
devices := make([]deviceSessionResponse, 0, len(sessions))
|
|
|
|
|
for _, sess := range sessions {
|
|
|
|
|
devices = append(devices, deviceSessionResponse{
|
|
|
|
|
DeviceID: sess.DeviceID, DeviceName: sess.DeviceName,
|
|
|
|
|
ClientVersion: sess.ClientVersion, LastSeenAt: sess.LastSeenAt,
|
|
|
|
|
Current: string(sess.TokenHash) == string(current.TokenHash),
|
|
|
|
|
})
|
|
|
|
|
}
|
|
|
|
|
writeJSON(w, http.StatusOK, map[string]any{"devices": devices})
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func (s *Server) handleDeleteDevice(w http.ResponseWriter, r *http.Request, current store.Session) {
|
|
|
|
|
deviceID := strings.TrimSpace(r.PathValue("deviceID"))
|
|
|
|
|
if deviceID == "" {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "device id is required")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
if deviceID == current.DeviceID {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "sign out to remove the current device")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
tokenHash, err := s.store.DeleteUserDevice(r.Context(), current.EmbyUserID, deviceID)
|
|
|
|
|
if err == store.ErrNotFound {
|
|
|
|
|
writeError(w, http.StatusNotFound, "device not found")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
if err != nil {
|
|
|
|
|
s.log.Error("device revoke failed", "error", err)
|
|
|
|
|
writeError(w, http.StatusInternalServerError, "could not remove device")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
_ = s.cache.Delete(r.Context(), cache.SessionKey(hexHash(tokenHash)))
|
|
|
|
|
w.WriteHeader(http.StatusNoContent)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func (s *Server) handleRenameDevice(w http.ResponseWriter, r *http.Request, current store.Session) {
|
|
|
|
|
deviceID := strings.TrimSpace(r.PathValue("deviceID"))
|
|
|
|
|
var req renameDeviceRequest
|
|
|
|
|
if deviceID == "" || json.NewDecoder(http.MaxBytesReader(w, r.Body, 2<<10)).Decode(&req) != nil {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "device id and name are required")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
req.DeviceName = strings.TrimSpace(req.DeviceName)
|
|
|
|
|
if req.DeviceName == "" {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "device name is required")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
if len([]rune(req.DeviceName)) > 80 {
|
|
|
|
|
writeError(w, http.StatusBadRequest, "device name is too long")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
if err := s.store.RenameUserDevice(r.Context(), current.EmbyUserID, deviceID, req.DeviceName); err == store.ErrNotFound {
|
|
|
|
|
writeError(w, http.StatusNotFound, "device not found")
|
|
|
|
|
return
|
|
|
|
|
} else if err != nil {
|
|
|
|
|
s.log.Error("device rename failed", "error", err)
|
|
|
|
|
writeError(w, http.StatusInternalServerError, "could not rename device")
|
|
|
|
|
return
|
|
|
|
|
}
|
|
|
|
|
w.WriteHeader(http.StatusNoContent)
|
|
|
|
|
}
|