Settings grows an Online Sources section. YouTube is a Video Source; NetEase is a Streaming Source. Both stay off until the singer turns them on.
When YouTube is on, a public watch or playlist link becomes yt: queue items. Playback loads https://www.youtube.com/watch?v=… in one incognito WebView and drives #movie_player video the same way Kaset does. Items never become library songs.
When NetEase is on, sign-in follows YesPlayMusic (QR first, then phone or email). Browse liked tracks, Streaming Playlists, and search. Import writes real library songs through the existing import path. A later import of the same Streaming Playlist updates the same Playlist via a Playlist Origin Stamp. A different file for the same Streaming Track Identity opens a Library Decision (Keep / Replace / Apply to Remaining). Grey songs stay visible and do not import.
__csrf only)yt: session transportyoutube-watch) for the public watch page; audience window reparents itTracked in #418 (69 user stories). Automated evidence at the four named seams:
play(yt:…) does not invoke local play; local play after YouTube tears down the WebView; ended dequeues the next id; pause/resume/seek/volume drive the video transportrole="img" + status; phone/email fields have sr-only names; Library Decision reuses the CDG pause-and-ask dialog. Evidence: jsx-a11y via pnpm lint; component tests for Settings, NeteasePanel, YoutubePasteLink, LibraryDecisionDialognode --run check:i18ndocs/references/contracts/{catalog,errors,library,playback,settings}.md updated with the new IPC/player stream URLs; no UNMnode --run lint — PASSnode --run check:i18n — PASSnode --run check:standards — PASSpnpm knip --no-progress — PASSpnpm test:coverage — PASS (2405 tests)cd src-tauri && cargo test -q — PASS (1282 lib tests + integration crates)cd src-tauri && cargo clippy --all-targets -- -D warnings — PASSdocs/references/contracts/*.md updatedpnpm build / pnpm tauri build — SKIPPED (CI)NetEase weapi and YouTube watch-page control match YesPlayMusic and Kaset. A first desktop pass (QR or password login, one import, one public watch link on host and audience) is still the cheapest confirmation that the live pages have not drifted.
Out of scope, unchanged: UNM, Google sign-in, YouTube download, Kugou/QQ/Spotify, Match Search, AirPlay of YouTube video.
Closes #418
[!IMPORTANT]
Review skipped
Too many files!
This PR contains 143 files, which is 43 over the limit of 100.
To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.
Upgrade to a paid plan to raise the limit.
This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.
⚙️ Run configuration
Configuration used: Repository: thedavidweng/OpenKara/.coderabbit.yaml
Review profile: CHILL
Plan: Advanced
Run ID:
b9ce6a3f-62ba-4da6-8f3a-f2a6ca137db6📥 Commits
Reviewing files that changed from the base of the PR and between 79866551240621b73eb094109d5b860c9e208081 and fce9dafe0c1fc9d6f8816eaf536b0b179fd69008.
⛔ Files ignored due to path filters (5)
docs/references/generated/db-schema.mdis excluded by!**/generated/**,!**/generated/**,!docs/references/generated/**packaging/flatpak/generated/cargo-sources.jsonis excluded by!**/generated/**,!**/generated/**,!packaging/flatpak/generated/**src-tauri/Cargo.lockis excluded by!**/*.lock,!src-tauri/Cargo.locksrc-tauri/icons/Assets.caris excluded by!src-tauri/icons/**src-tauri/icons/OpenKara.icon/Assets/OpenKara Mic.pngis excluded by!**/*.png,!src-tauri/icons/**📒 Files selected for processing (143)
.github/workflows/packaging.ymlCONTEXT.mdREADME.mdREADME_CN.mddocs/adr/0015-lyrics-acquisition-multi-source-fallback-chain.mddocs/adr/0026-put-amll-first-among-online-lyrics-sources.mddocs/adr/0027-upgrade-online-line-timed-lyrics-only-on-a-confident-amll-match.mddocs/adr/0031-keep-online-sources-distinct-from-remote-providers.mddocs/adr/0032-end-streaming-import-at-the-shared-import-path.mddocs/adr/0033-send-a-china-client-address-and-do-not-ship-unm.mddocs/adr/0034-play-youtube-from-the-public-watch-page.mddocs/adr/README.mddocs/references/contracts/catalog.mddocs/references/contracts/errors.mddocs/references/contracts/library.mddocs/references/contracts/lyrics.mddocs/references/contracts/playback.mddocs/references/contracts/settings.mdrust-toolchain.tomlsrc-tauri/Cargo.tomlsrc-tauri/capabilities/default.jsonsrc-tauri/migrations/015_streaming_identity.sqlsrc-tauri/src/app_runtime.rssrc-tauri/src/cache/mod.rssrc-tauri/src/catalog/credentials.rssrc-tauri/src/catalog/identity.rssrc-tauri/src/catalog/import.rssrc-tauri/src/catalog/mod.rssrc-tauri/src/catalog/netease/client.rssrc-tauri/src/catalog/netease/crypto.rssrc-tauri/src/catalog/netease/mod.rssrc-tauri/src/catalog/registry.rssrc-tauri/src/catalog/reveal.rssrc-tauri/src/catalog/streaming.rssrc-tauri/src/catalog/types.rssrc-tauri/src/catalog/video.rssrc-tauri/src/catalog/youtube.rssrc-tauri/src/commands/catalog.rssrc-tauri/src/commands/error.rssrc-tauri/src/commands/mod.rssrc-tauri/src/commands/settings.rssrc-tauri/src/commands/youtube_watch.rssrc-tauri/src/config/execution_provider.rssrc-tauri/src/config/library_registry.rssrc-tauri/src/config/mod.rssrc-tauri/src/config/persistence.rssrc-tauri/src/config/preferences.rssrc-tauri/src/hash.rssrc-tauri/src/lib.rssrc-tauri/src/lyrics/README.mdsrc-tauri/src/lyrics/acquisition.rssrc-tauri/src/remote/dropbox.rssrc-tauri/src/remote/google_drive.rssrc-tauri/src/remote/types.rssrc-tauri/src/services/playback.rssrc-tauri/src/state/catalog.rssrc-tauri/src/state/mod.rssrc-tauri/src/system_credentials.rssrc/components/Catalog/NeteasePanel.test.tsxsrc/components/Catalog/NeteasePanel.tsxsrc/components/Catalog/NeteaseSignIn.tsxsrc/components/Catalog/YoutubePasteLink.test.tsxsrc/components/Catalog/YoutubePasteLink.tsxsrc/components/Layout/AppLayout.preview.test.tsxsrc/components/Layout/AppLayout.test.tsxsrc/components/Layout/AppLayout.tsxsrc/components/Layout/Sidebar.catalog.test.tsxsrc/components/Layout/Sidebar.preview.test.tsxsrc/components/Layout/Sidebar.test.tsxsrc/components/Layout/Sidebar.tsxsrc/components/Layout/ToastContainer.test.tsxsrc/components/Layout/ToastContainer.tsxsrc/components/Library/ContextMenu.tsxsrc/components/Library/LibraryDecisionDialog.test.tsxsrc/components/Library/LibraryDecisionDialog.tsxsrc/components/Library/SongListItem.tsxsrc/components/Library/song-list-item-menu.test.tssrc/components/Library/song-list-item-menu.tssrc/components/Playback/PlaybackStage.test.tsxsrc/components/Playback/PlaybackStage.tsxsrc/components/Player/NowPlayingInfo.test.tsxsrc/components/Player/NowPlayingInfo.tsxsrc/components/Player/QueuePanel.test.tsxsrc/components/Player/QueuePanel.tsxsrc/components/Player/SeekBar.tsxsrc/components/Player/VolumeSliders.tsxsrc/components/Settings/SettingsOnlineSourcesSection.test.tsxsrc/components/Settings/SettingsOnlineSourcesSection.tsxsrc/components/Settings/SettingsOverlay.tsxsrc/hooks/use-playback-runtime.test.tsxsrc/lib/backend/index.tssrc/lib/backend/mock-backend.tssrc/lib/backend/tauri-backend.tssrc/lib/backend/types.tssrc/lib/debug-info.test.tssrc/lib/debug-info.tssrc/lib/i18n.test.tssrc/lib/i18n.tssrc/lib/native-context-menu.tssrc/lib/settings-controller/settings-controller.test.tssrc/lib/settings-controller/settings-controller.tssrc/lib/settings-controller/types.tssrc/lib/song-commands/song-commands.tssrc/lib/song-commands/types.tssrc/lib/tauri/catalog.tssrc/lib/tauri/settings.tssrc/lib/tauri/tauri-wrappers.test.tssrc/lib/tauri/youtube-watch.tssrc/locales/de.jsonsrc/locales/en.jsonsrc/locales/es.jsonsrc/locales/fr.jsonsrc/locales/id.jsonsrc/locales/it.jsonsrc/locales/ja.jsonsrc/locales/ko.jsonsrc/locales/nl.jsonsrc/locales/pl.jsonsrc/locales/pt-BR.jsonsrc/locales/ru.jsonsrc/locales/th.jsonsrc/locales/tr.jsonsrc/locales/vi.jsonsrc/locales/zh-CN.jsonsrc/locales/zh-TW.jsonsrc/mock/tauri-mock-data.tssrc/mock/tauri-mock-impl.tssrc/playback/index.tssrc/playback/session.test.tssrc/playback/session.tssrc/playback/youtube-transport.test.tssrc/playback/youtube-transport.tssrc/playback/youtube-watch-host.tauri.test.tssrc/playback/youtube-watch-host.tssrc/playback/youtube-watch-native.tssrc/runtime/airplay-runtime.tssrc/stores/catalog-store.test.tssrc/stores/catalog-store.tssrc/stores/player-store.tssrc/stores/settings-store.test.tssrc/stores/settings-store.tssrc/types/ipc-contract.test.tssrc/types/ipc.tsYou can disable this status message by setting the
reviews.review_statustofalsein the CodeRabbit configuration file.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
Comment [@coderabbitai](/coderabbitai) help to get the list of available commands.
:x: Patch coverage is 88.70558% with 89 lines in your changes missing coverage. Please review.
:white_check_mark: Project coverage is 88.6%. Comparing base (ee2338d) to head (fce9daf).
:warning: Report is 1 commits behind head on main.
:white_check_mark: All tests successful. No failed tests found.
@@ Coverage Diff @@ ## main #419 +/- ## ====================================== Coverage 88.5% 88.6% ====================================== Files 211 220 +9 Lines 10913 11697 +784 Branches 3338 3531 +193 ====================================== + Hits 9662 10365 +703 - Misses 1200 1279 +79 - Partials 51 53 +2
| Flag | Coverage Δ | |
|---|---|---|
| frontend | 88.6% <88.7%> (+<0.1%) | :arrow_up: |
Flags with carried forward coverage won't be shown. Click here to find out more.
| Components | Coverage Δ | |
|---|---|---|
| frontend | 88.6% <88.7%> (+<0.1%) | :arrow_up: |
| rust | ∅ <ø> (∅) |
| Files with missing lines | Coverage Δ | |
|---|---|---|
| src/components/Catalog/YoutubePasteLink.tsx | 100.0% <100.0%> (ø) | |
| src/components/Layout/AppLayout.tsx | 95.8% <100.0%> (+<0.1%) | :arrow_up: |
| src/components/Layout/ToastContainer.tsx | 94.4% <ø> (ø) | |
| src/components/Player/NowPlayingInfo.tsx | 64.7% <100.0%> (+1.4%) | :arrow_up: |
| src/components/Player/SeekBar.tsx | 92.4% <100.0%> (ø) | |
| src/components/Player/VolumeSliders.tsx | 76.5% <100.0%> (+0.1%) | :arrow_up: |
| ...mponents/Settings/SettingsOnlineSourcesSection.tsx | 100.0% <100.0%> (ø) | |
| src/components/Settings/SettingsOverlay.tsx | 100.0% <ø> (ø) | |
| src/lib/backend/mock-backend.ts | 100.0% <ø> (ø) | |
| src/lib/backend/tauri-backend.ts | 100.0% <ø> (ø) | |
| ... and 39 more |
github-advanced-security[bot] · · 4 file comments
kilo-code-bot[bot] · · 9 file comments
Status: No Issues Found | Recommendation: Merge
docs/references/contracts/errors.mdsrc-tauri/src/catalog/netease/client.rssrc-tauri/src/catalog/netease/mod.rssrc-tauri/src/catalog/types.rssrc-tauri/src/commands/error.rssrc/components/Layout/ToastContainer.test.tsxsrc/components/Layout/ToastContainer.tsxsrc/lib/debug-info.test.tssrc/lib/debug-info.tssrc/locales/de.jsonsrc/locales/en.jsonsrc/locales/es.jsonsrc/locales/fr.jsonsrc/locales/id.jsonsrc/locales/it.jsonsrc/locales/ja.jsonsrc/locales/ko.jsonsrc/locales/nl.jsonsrc/locales/pl.jsonsrc/locales/pt-BR.jsonsrc/locales/ru.jsonsrc/locales/th.jsonsrc/locales/tr.jsonsrc/locales/vi.jsonsrc/locales/zh-CN.jsonsrc/locales/zh-TW.jsonsrc/types/ipc-contract.test.tssrc/types/ipc.tsCurrent summary above is authoritative. Previous snapshots are kept for context only.
Status: No Issues Found | Recommendation: Merge
docs/references/contracts/errors.mdsrc-tauri/src/catalog/netease/client.rssrc-tauri/src/catalog/netease/mod.rssrc-tauri/src/catalog/types.rssrc-tauri/src/commands/error.rssrc/components/Layout/ToastContainer.test.tsxsrc/components/Layout/ToastContainer.tsxsrc/lib/debug-info.test.tssrc/lib/debug-info.tssrc/locales/de.jsonsrc/locales/en.jsonsrc/locales/es.jsonsrc/locales/fr.jsonsrc/locales/id.jsonsrc/locales/it.jsonsrc/locales/ja.jsonsrc/locales/ko.jsonsrc/locales/nl.jsonsrc/locales/pl.jsonsrc/locales/pt-BR.jsonsrc/locales/ru.jsonsrc/locales/th.jsonsrc/locales/tr.jsonsrc/locales/vi.jsonsrc/locales/zh-CN.jsonsrc/locales/zh-TW.jsonsrc/types/ipc-contract.test.tssrc/types/ipc.tsStatus: No Issues Found | Recommendation: Merge
.github/dependabot.yml - rust-dependencies grouping added.github/workflows/ci.yml - rust-toolchain SHA updated.github/workflows/dependabot-automerge.yml - new auto-merge workflow for Dependabot.github/workflows/dependabot-sync.yml - approve all action_required workflow runs.github/workflows/release.yml - rust-toolchain SHA updated.github/workflows/reusable-linux-installed-app-smoke.yml - rust-toolchain SHA updated.github/workflows/reusable-macos-installed-app-smoke.yml - rust-toolchain SHA updated.github/workflows/reusable-separation-smoke.yml - rust-toolchain SHA updated.github/workflows/reusable-windows-installed-app.yml - rust-toolchain SHA updated.github/workflows/spectral-candidate.yml - rust-toolchain SHA updatedpackage.json - zustand bumped to 5.0.15scripts/ci/classify-changes.mjs - dependabot-automerge.yml added to other_workflowsrc-tauri/Cargo.lock - dependency updatessrc-tauri/deny.toml - removed resolved quick-xml advisory ignoressrc-tauri/src/cache/waveforms.rs - replaced chunks_exact with as_chunkstests/ci/dependabot-automerge-contract.test.ts - new contract tests for automerge workflowpackaging/flatpak/generated/cargo-sources.json - regeneratedpackaging/flatpak/generated/node-sources.0.json - regeneratedpnpm-lock.yaml - dependency updatesStatus: No Issues Found | Recommendation: Merge
src/components/Catalog/NeteasePanel.test.tsx - test updates for visible labelssrc/components/Catalog/NeteaseSignIn.tsx - visible labels, responsive QR container, layout restructureStatus: No Issues Found | Recommendation: Merge
src/lib/tauri/catalog.ts - parameter key alignment with Tauri v2 camelCase conversionsrc/lib/tauri/settings.ts - parameter key alignment with Tauri v2 camelCase conversionsrc/lib/tauri/tauri-wrappers.test.ts - test expectations updated for camelCase keyssrc/mock/tauri-mock-impl.ts - mock input parameter types updated to camelCaseStatus: No Issues Found | Recommendation: Merge
.github/workflows/packaging.yml - WinGet release resolution fixdocs/references/contracts/playback.md - type alignment fixdocs/references/generated/db-schema.md - migration schema updatesrc-tauri/Cargo.toml - removed unused cipher dependencysrc-tauri/src/catalog/import.rs - transaction wrapping fixsrc-tauri/src/catalog/streaming.rs - test password fixture fixsrc/locales/*.json (18 files) - translated new Online Sources surfacessrc/mock/tauri-mock-impl.ts - mock parameter handling fixStatus: 7 Issues Found | Recommendation: Address before merge
| Severity | Count |
|---|---|
| CRITICAL | 0 |
| WARNING | 5 |
| SUGGESTION | 2 |
| File | Line | Issue |
|---|---|---|
src/locales/de.json | 194 | New locale keys hardcoded in English instead of translated |
src/locales/fr.json | 195 | New locale keys hardcoded in English instead of translated |
src/locales/es.json | 195 | New locale keys hardcoded in English instead of translated |
src/locales/ja.json | 194 | New locale keys hardcoded in English instead of translated |
src/mock/tauri-mock-impl.ts | 820 | Mock implementation ignores command parameters |
src/mock/tauri-mock-impl.ts | 847 | Mock implementation ignores action parameter |
src-tauri/src/catalog/import.rs | 307 | apply_replace not wrapped in a transaction |
| File | Line | Issue |
|---|---|---|
docs/references/contracts/playback.md | 10 | resolve_video_source_url type inconsistent with catalog contract |
docs/references/contracts/catalog.md | 226 | resolve_video_source_url type inconsistent with playback contract |
src/locales/de.json - hardcoded English locale keyssrc/locales/fr.json - hardcoded English locale keyssrc/locales/es.json - hardcoded English locale keyssrc/locales/ja.json - hardcoded English locale keyssrc/mock/tauri-mock-impl.ts - mock parameter handlingdocs/references/contracts/playback.md - type inconsistencydocs/references/contracts/catalog.md - type inconsistencysrc-tauri/src/catalog/import.rs - missing transaction wrappingFix these issues in Kilo Cloud
Reviewed by free · Input: 190.2K · Output: 24.6K · Cached: 116.4K
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
dev ·
Pushed 0df73261 for the failed required checks and every review thread.
CI
docs/references/generated/db-schema.md for 015_streaming_identity.sqlErrorCode (errors.online_source_disabled)cipher crate (cbc::cipher is enough)gh release list with isLatest so the nightly prerelease is not treated as vnightlyReview threads
source_id is OnlineSourceIdapply_replace: one SQLite transaction, files deleted after commitNot a code change
| Status | Category | Percentage | Covered / Total |
|---|---|---|---|
| 🟢 | Lines | 84.7% (🎯 65%) | 8160 / 9633 |
| 🟢 | Statements | 83.9% (🎯 65%) | 8653 / 10313 |
| 🟢 | Functions | 80.23% (🎯 60%) | 2058 / 2565 |
| 🟢 | Branches | 76.6% (🎯 60%) | 4634 / 6049 |
github-advanced-security[bot] · · 3 file comments
github-advanced-security[bot] · · 2 file comments
github-advanced-security[bot] · · 1 file comment
github-advanced-security[bot] · · 2 file comments
Sign in to comment.
feat(catalog): add Online Sources for NetEase import and YouTube queue
#419 main ← feat/418-online-sources
Updated last month
This hard-coded value is used as a password.
Addressed in 0df73261. The resolve/refusal test now uses the same runtime-built fixture password.
This hard-coded value is used as a password.
Addressed in 0df73261. The email sign-in test now uses the same runtime-built fixture password.
This hard-coded value is used as a password.
Addressed in 0df73261. That string was a unit-test login fixture, not a shipped secret. Tests now build the password at runtime so CodeQL does not treat a hard-coded literal as a credential.
This hard-coded value is used as a password.
Addressed in 0df73261. Same test-only sink: the FakeStreamingSource password is assembled at runtime and then asserted not to land in stored credentials.
WARNING: New locale keys are hardcoded in English instead of translated
Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. Online Sources, NetEase, YouTube, Library Decision, and error titles are now translated in every locale, not left as English copies.
WARNING: New locale keys are hardcoded in English instead of translated
Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. French copy for the new catalog, YouTube, decision, settings, and error strings is in this commit.
SUGGESTION: resolve_video_source_url type is inconsistent with playback contract
This documents source_id: OnlineSourceId, but docs/references/contracts/playback.md line 10 documents source_id: String. Align the type across both contracts.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. Catalog already used OnlineSourceId; playback.md is now aligned to that type.
WARNING: New locale keys are hardcoded in English instead of translated
Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. Japanese copy for the new catalog, YouTube, decision, settings, and error strings is in this commit.
WARNING: Mock implementation ignores command parameters
continue_streaming_import ignores the action parameter and always returns status: "completed". Tests that don't override this command will miss conflict-resolution logic (Keep/Replace/Apply to Remaining/Cancel).
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. continue_streaming_import now inspects action. Cancel records a cancelled failure; keep/replace complete without a conflict.
WARNING: New locale keys are hardcoded in English instead of translated
Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. Spanish copy for the new catalog, YouTube, decision, settings, and error strings is in this commit.
SUGGESTION: resolve_video_source_url type is inconsistent with catalog contract
This documents source_id: String, but docs/references/contracts/catalog.md line 226 documents source_id: OnlineSourceId. Align the type across both contracts.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. Playback now documents source_id: OnlineSourceId, matching the catalog contract.
WARNING: Mock implementation ignores command parameters
sign_in_streaming_source only reads args.identifier and silently drops source_id, method, password, and country_code. Tests using the base mock cannot verify password handling, method validation, or country-code forwarding.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. The preview mock now reads source_id, method, identifier, and country_code, and forgets password after the call — the same rule as the real command.
WARNING: apply_replace performs multiple database and filesystem mutations without a transaction
If the process crashes after import_file but before stamp_identity, the new song exists in the library, old stems/waveforms/songs are deleted, and playlists are partially updated — leaving an inconsistent state.
Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.
Addressed in 0df73261. apply_replace now imports, retargets lyrics/playlists, and deletes the old song rows in one SQLite transaction, then removes files after commit.
This hard-coded value is used as a password.
This hard-coded value is used as a password.
This hard-coded value is used as a password.
This hard-coded value is used as a password.
This hard-coded value is used as a password.
This hard-coded value is used as an initialization vector.
chore(tooling): upgrade pnpm to 12.5.1
#457 feat/418-online-sources ← cursor/pnpm-12-27b8
Updated last week