mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-09 19:07:12 +02:00
API v1 no longer mints short-lived JWT access tokens. Clients send the grant secret from POST /auth/login or /auth/setup as `Authorization: Bearer` on every request. Every request already looked the grant up in the database, so the JWT gave no speed or revocation benefit and only added a refresh loop, which early client authors pushed back on. The grant already is an API key: one per client sign-in, scoped and revocable. Revocation is now immediate on every node; the contract promises "within one minute". Removed: POST /auth/token, the grantAuth scheme, the TokenRequest and AccessToken schemas, the token_expired problem code, the API v1 JWT signer and its signing key, the grant liveness cache, and PropertyRepository.PutIfAbsent. ResolveGrant is now Authenticate. Short-lived tokens return later only as narrow media tokens for ?access_token= on media URLs, together with the media endpoints. Signed-off-by: Deluan <deluan@navidrome.org>
43 lines
1.5 KiB
YAML
43 lines
1.5 KiB
YAML
type: object
|
|
description: RFC 9457 problem details, returned for every 4xx and 5xx response.
|
|
required: [title, status, code]
|
|
properties:
|
|
type:
|
|
type: string
|
|
description: |
|
|
URI reference identifying the problem type. Omitted while the problem carries no semantics
|
|
beyond its HTTP status code, which RFC 9457 defines as `about:blank`. Problems with their
|
|
own semantics get their own URI; switch on `code` instead.
|
|
title:
|
|
type: string
|
|
description: Short human-readable summary, the same for all occurrences of this problem type.
|
|
status:
|
|
type: integer
|
|
description: HTTP status code of this response.
|
|
detail:
|
|
type: string
|
|
description: Human-readable explanation specific to this occurrence. Omitted unless the server marked the text as safe to show clients.
|
|
code:
|
|
type: string
|
|
description: Machine-readable error code, and the value clients switch on. New codes may be added.
|
|
enum:
|
|
- validation
|
|
- unauthorized
|
|
- forbidden
|
|
- insufficient_scope
|
|
- not_found
|
|
- method_not_allowed
|
|
- setup_complete
|
|
- password_managed_externally
|
|
- payload_too_large
|
|
- rate_limited
|
|
- unavailable
|
|
- internal
|
|
referenceId:
|
|
type: string
|
|
description: Present on internal errors. Quote it when reporting a problem; it tags the server's log lines for this request.
|
|
errors:
|
|
type: array
|
|
description: Per-field failures. Present only when `code` is `validation`.
|
|
items:
|
|
$ref: ./ValidationError.yaml
|