mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-08 02:17:25 +02:00
API v1 no longer mints short-lived JWT access tokens. Clients send the grant secret from POST /auth/login or /auth/setup as `Authorization: Bearer` on every request. Every request already looked the grant up in the database, so the JWT gave no speed or revocation benefit and only added a refresh loop, which early client authors pushed back on. The grant already is an API key: one per client sign-in, scoped and revocable. Revocation is now immediate on every node; the contract promises "within one minute". Removed: POST /auth/token, the grantAuth scheme, the TokenRequest and AccessToken schemas, the token_expired problem code, the API v1 JWT signer and its signing key, the grant liveness cache, and PropertyRepository.PutIfAbsent. ResolveGrant is now Authenticate. Short-lived tokens return later only as narrow media tokens for ?access_token= on media URLs, together with the media endpoints. Signed-off-by: Deluan <deluan@navidrome.org>
16 lines
581 B
YAML
16 lines
581 B
YAML
get:
|
|
operationId: getCapabilities
|
|
x-module: core
|
|
x-stability-level: alpha
|
|
tags: [server]
|
|
summary: List implemented capability modules
|
|
description: The capability modules this server implements. Any valid grant may read it, whatever its scopes.
|
|
security: [{bearerAuth: []}]
|
|
responses:
|
|
'200':
|
|
description: Implemented modules.
|
|
content:
|
|
application/json:
|
|
schema: {$ref: ../components/schemas/Capabilities.yaml}
|
|
'401': {$ref: ../components/responses/Unauthorized.yaml}
|
|
'500': {$ref: ../components/responses/InternalError.yaml}
|