mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-08 02:17:25 +02:00
API v1 no longer mints short-lived JWT access tokens. Clients send the grant secret from POST /auth/login or /auth/setup as `Authorization: Bearer` on every request. Every request already looked the grant up in the database, so the JWT gave no speed or revocation benefit and only added a refresh loop, which early client authors pushed back on. The grant already is an API key: one per client sign-in, scoped and revocable. Revocation is now immediate on every node; the contract promises "within one minute". Removed: POST /auth/token, the grantAuth scheme, the TokenRequest and AccessToken schemas, the token_expired problem code, the API v1 JWT signer and its signing key, the grant liveness cache, and PropertyRepository.PutIfAbsent. ResolveGrant is now Authenticate. Short-lived tokens return later only as narrow media tokens for ?access_token= on media URLs, together with the media endpoints. Signed-off-by: Deluan <deluan@navidrome.org>
41 lines
1.2 KiB
YAML
41 lines
1.2 KiB
YAML
type: object
|
|
description: A long-lived grant held by one client of one user.
|
|
required: [id, name, client, clientVersion, scopes, provider, createdAt, lastUsedAt, lastUsedIp, current]
|
|
properties:
|
|
id:
|
|
type: string
|
|
description: Grant id.
|
|
name:
|
|
type: string
|
|
description: Label shown to the user.
|
|
client:
|
|
type: string
|
|
description: Name of the client app that holds the grant.
|
|
clientVersion:
|
|
type: string
|
|
nullable: true
|
|
description: "Version of the client app, when it sent one."
|
|
scopes:
|
|
type: array
|
|
description: Scopes this grant carries.
|
|
items:
|
|
$ref: ./Scope.yaml
|
|
provider:
|
|
type: string
|
|
description: "How the grant was created, for example `password` or `setup`. Free-form; new values may appear."
|
|
createdAt:
|
|
type: string
|
|
format: date-time
|
|
description: When the grant was created.
|
|
lastUsedAt:
|
|
type: string
|
|
format: date-time
|
|
nullable: true
|
|
description: "When the grant was last used, at a coarse granularity. Null until first use."
|
|
lastUsedIp:
|
|
type: string
|
|
nullable: true
|
|
description: Client IP of the last use. Null until first use.
|
|
current:
|
|
type: boolean
|
|
description: True for the grant that made this request.
|