package api import ( "encoding/json" "errors" "net/http" "strings" "github.com/ponzischeme89/memby/server/internal/cache" "github.com/ponzischeme89/memby/server/internal/emby" "github.com/ponzischeme89/memby/server/internal/store" ) type loginRequest struct { Username string `json:"username"` Password string `json:"password"` DeviceID string `json:"deviceId"` DeviceName string `json:"deviceName"` } type loginResponse struct { Token string `json:"token"` UserID string `json:"userId"` Username string `json:"username"` ServerID string `json:"serverId"` ActiveClients int `json:"activeClients,omitempty"` MaxClientsPerUser int `json:"maxClientsPerUser"` } type authPolicyResponse struct { MaxClientsPerUser int `json:"maxClientsPerUser"` } func (s *Server) handleAuthPolicy(w http.ResponseWriter, _ *http.Request) { writeJSON(w, http.StatusOK, authPolicyResponse{ MaxClientsPerUser: s.cfg.MaxClientsPerUser, }) } // handleLogin exchanges Emby credentials for a gateway token. // // The Emby access token stays here: the TV only ever holds the gateway token, so // revoking a device is a DELETE in Postgres rather than an Emby-side cleanup. func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { var req loginRequest if err := json.NewDecoder(http.MaxBytesReader(w, r.Body, 8<<10)).Decode(&req); err != nil { writeError(w, http.StatusBadRequest, "malformed request body") return } req.Username = strings.TrimSpace(req.Username) if req.Username == "" { writeError(w, http.StatusBadRequest, "username is required") return } if req.DeviceID == "" { req.DeviceID = "memby-tv" } req.DeviceName = strings.TrimSpace(req.DeviceName) if req.DeviceName == "" { // Compatibility for APKs released before device naming. New clients require an // editable name in their UI, but an older TV must still be able to sign in while // the household rollout is in progress. req.DeviceName = "Memby TV" } if len([]rune(req.DeviceName)) > 80 { writeError(w, http.StatusBadRequest, "device name is too long") return } auth, err := s.emby.Authenticate( r.Context(), req.Username, req.Password, req.DeviceID, req.DeviceName, ) if err != nil { // Never echo Emby's body here: a failed sign-in is the one place a wrong // password could be reflected back. s.log.Warn("emby authentication failed", "username", req.Username) writeError(w, http.StatusUnauthorized, "sign-in failed") return } token, err := newToken() if err != nil { s.log.Error("token generation failed", "error", err) writeError(w, http.StatusInternalServerError, "could not issue a token") return } sess := store.Session{ TokenHash: hashToken(token), EmbyUserID: auth.User.ID, EmbyToken: auth.AccessToken, Username: auth.User.Name, ServerID: auth.ServerID, DeviceID: req.DeviceID, DeviceName: req.DeviceName, } if sess.Username == "" { sess.Username = req.Username } replacedHash, activeClients, err := s.store.CreateSession( r.Context(), sess, s.cfg.MaxClientsPerUser, ) if errors.Is(err, store.ErrDeviceLimit) { if revokeErr := s.emby.Logout(r.Context(), emby.Credentials{ UserID: auth.User.ID, Token: auth.AccessToken, DeviceID: req.DeviceID, DeviceName: req.DeviceName, }); revokeErr != nil { s.log.Warn("could not retire refused emby session", "error", revokeErr) } s.log.Warn("device allowance reached", "username", sess.Username, "active_clients", activeClients, "max_clients", s.cfg.MaxClientsPerUser, ) writeJSON(w, http.StatusConflict, map[string]any{ "error": "device_limit_reached", "message": "This account has reached its Memby device allowance.", "activeClients": activeClients, "maxClientsPerUser": s.cfg.MaxClientsPerUser, }) return } if err != nil { _ = s.emby.Logout(r.Context(), emby.Credentials{ UserID: auth.User.ID, Token: auth.AccessToken, DeviceID: req.DeviceID, DeviceName: req.DeviceName, }) s.log.Error("session persist failed", "error", err) writeError(w, http.StatusInternalServerError, "could not start a session") return } if len(replacedHash) > 0 { _ = s.cache.Delete(r.Context(), cache.SessionKey(hexHash(replacedHash))) } writeJSON(w, http.StatusOK, loginResponse{ Token: token, UserID: sess.EmbyUserID, Username: sess.Username, ServerID: sess.ServerID, ActiveClients: activeClients, MaxClientsPerUser: s.cfg.MaxClientsPerUser, }) } func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request, sess store.Session) { if err := s.store.DeleteSession(r.Context(), sess.TokenHash); err != nil { s.log.Error("session delete failed", "error", err) } _ = s.cache.Delete(r.Context(), cache.SessionKey(hexHash(sess.TokenHash))) _ = s.cache.InvalidateUser(r.Context(), sess.EmbyUserID) w.WriteHeader(http.StatusNoContent) } // handleSession lets the TV confirm a stored token is still good before rendering. func (s *Server) handleSession(w http.ResponseWriter, _ *http.Request, sess store.Session) { writeJSON(w, http.StatusOK, loginResponse{ UserID: sess.EmbyUserID, Username: sess.Username, ServerID: sess.ServerID, MaxClientsPerUser: s.cfg.MaxClientsPerUser, }) }