New JellyfinMediaSourcesController (/api/media-sources/jellyfin, J1-J9) and EmbyMediaSourcesController (/api/media-sources/emby, E1-E9), wrapping the existing Jellyfin/Emby MediatR commands per the #202 design doc §A.3/§A.4. Secure connection contract (§C3/§B, finding 1): the connection GET returns only { address, hasApiKey } — the API key never crosses the wire. The PUT retains the existing key when the incoming key is blank, sets a new one when non-blank, and 422s "API key is required" on a blank first connect. Finding 7 (lock-release discipline): DisconnectJellyfinHandler and DisconnectEmbyHandler now wrap their work in try/finally so a throw from any awaited dependency (repo delete, search-index commit, secret store) still releases the family lock instead of wedging every future disconnect at 409. Findings 2c/8 (path-replacement cross-source guard): UpdateJellyfinPathReplacementsHandler and UpdateEmbyPathReplacementsHandler now reject, before any write, an incoming positive Id that isn't owned by the route's media source, a null item, or a blank RemotePath/LocalPath — all 422 with no partial mutation. Defense-in-depth repo fix: the Jellyfin/Emby path-replacement UPDATE SQL in MediaSourceRepository now scopes by {Jellyfin,Emby}MediaSourceId (was previously unscoped by Id alone, allowing a PUT to one source to silently overwrite another source's row). The Plex path-replacement method (~line 397) is untouched — that's slice S2's file. Library preferences (§C4a): the controller validates the incoming id set against the source's known libraries (reject foreign ids, require full coverage, no Id=0) before dispatch, then — for §C7 — LockLibrary + enqueues the SynchronizeXLibraries/SynchronizeXLibraryByIdIfNeeded pair per enabled library (compensating unlock if the enqueue throws), and returns the reloaded list (ids are not stable across a disable). 404s on id-taking endpoints come from a controller pre-check (GetXMediaSourceById is None), not a handler NotFoundError, since Either.Apply/ToEitherAsync join any NotFoundError into a flat 422 (finding 9). Tests: controller route/404/409/422 tests for both families; disconnect fault-injection tests proving the lock releases even when a dependency throws; path-replacement handler tests for cross-source-id/blank/null-item rejection and correct add/update/delete merge; a repository-level test proving the SQL fix stops a same-family cross-source path-replacement overwrite. No new commands, no DB migration, no OpenAPI regen (gated until S1-S3 merge per the design doc's build-slice plan). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
92 lines
3.7 KiB
C#
92 lines
3.7 KiB
C#
using ErsatzTV.Core;
|
|
using ErsatzTV.Core.Domain;
|
|
using ErsatzTV.Core.Interfaces.Repositories;
|
|
|
|
namespace ErsatzTV.Application.Emby;
|
|
|
|
public class UpdateEmbyPathReplacementsHandler : IRequestHandler<UpdateEmbyPathReplacements,
|
|
Either<BaseError, Unit>>
|
|
{
|
|
private readonly IMediaSourceRepository _mediaSourceRepository;
|
|
|
|
public UpdateEmbyPathReplacementsHandler(IMediaSourceRepository mediaSourceRepository) =>
|
|
_mediaSourceRepository = mediaSourceRepository;
|
|
|
|
public async Task<Either<BaseError, Unit>> Handle(
|
|
UpdateEmbyPathReplacements request,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
Option<EmbyMediaSource> maybeSource =
|
|
await _mediaSourceRepository.GetEmby(request.EmbyMediaSourceId, cancellationToken);
|
|
|
|
return await maybeSource.Match(
|
|
Some: async embyMediaSource =>
|
|
{
|
|
Option<BaseError> maybeError = ValidateItems(request, embyMediaSource);
|
|
return await maybeError.Match(
|
|
Some: error => Task.FromResult(Left<BaseError, Unit>(error)),
|
|
None: async () =>
|
|
{
|
|
await MergePathReplacements(request, embyMediaSource);
|
|
return Right<BaseError, Unit>(Unit.Default);
|
|
});
|
|
},
|
|
None: () => Task.FromResult(
|
|
Left<BaseError, Unit>(
|
|
BaseError.New($"Emby media source {request.EmbyMediaSourceId} does not exist."))));
|
|
}
|
|
|
|
private Task<Unit> MergePathReplacements(
|
|
UpdateEmbyPathReplacements request,
|
|
EmbyMediaSource embyMediaSource)
|
|
{
|
|
embyMediaSource.PathReplacements ??= new List<EmbyPathReplacement>();
|
|
|
|
var incoming = request.PathReplacements.Map(Project).ToList();
|
|
|
|
var toAdd = incoming.Filter(r => r.Id < 1).ToList();
|
|
var toRemove = embyMediaSource.PathReplacements.Filter(r => incoming.All(pr => pr.Id != r.Id)).ToList();
|
|
var toUpdate = incoming.Except(toAdd).ToList();
|
|
|
|
return _mediaSourceRepository.UpdatePathReplacements(embyMediaSource.Id, toAdd, toUpdate, toRemove);
|
|
}
|
|
|
|
private static EmbyPathReplacement Project(EmbyPathReplacementItem vm) =>
|
|
new() { Id = vm.Id, EmbyPath = vm.EmbyPath, LocalPath = vm.LocalPath };
|
|
|
|
// Defense-in-depth for design #202 findings 2c/8 — the repo UPDATE is scoped by
|
|
// EmbyMediaSourceId, but reject a foreign/blank/null row here too, before any write, so the
|
|
// mutation is all-or-nothing.
|
|
private static Option<BaseError> ValidateItems(
|
|
UpdateEmbyPathReplacements request,
|
|
EmbyMediaSource embyMediaSource)
|
|
{
|
|
List<EmbyPathReplacementItem> items = request.PathReplacements ?? [];
|
|
|
|
if (items.Any(item => item is null))
|
|
{
|
|
return BaseError.New("Path replacement items must not be null.");
|
|
}
|
|
|
|
if (items.Any(item => string.IsNullOrWhiteSpace(item.EmbyPath) || string.IsNullOrWhiteSpace(item.LocalPath)))
|
|
{
|
|
return BaseError.New("Each path replacement requires a non-blank Emby path and local path.");
|
|
}
|
|
|
|
var existingIds = (embyMediaSource.PathReplacements ?? new List<EmbyPathReplacement>())
|
|
.Map(pr => pr.Id)
|
|
.ToList();
|
|
var foreignIds = items.Filter(item => item.Id > 0 && !existingIds.Contains(item.Id))
|
|
.Map(item => item.Id)
|
|
.ToList();
|
|
if (foreignIds.Count > 0)
|
|
{
|
|
return BaseError.New(
|
|
$"Path replacement id(s) {string.Join(", ", foreignIds)} do not belong to Emby media source " +
|
|
$"{request.EmbyMediaSourceId}.");
|
|
}
|
|
|
|
return Option<BaseError>.None;
|
|
}
|
|
}
|