Home

dev / openkara

publicthedavidweng/OpenKara· sync paused
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

feat(catalog): add Online Sources for NetEase import and YouTube queue

open
Stack 1/2
#419 opened by devfeat/418-online-sources→main
Conversation58
devopened this pull requestAuthor· last month
Commits
0
Files changed…

Summary

Settings grows an Online Sources section. YouTube is a Video Source; NetEase is a Streaming Source. Both stay off until the singer turns them on.

When YouTube is on, a public watch or playlist link becomes yt: queue items. Playback loads https://www.youtube.com/watch?v=… in one incognito WebView and drives #movie_player video the same way Kaset does. Items never become library songs.

When NetEase is on, sign-in follows YesPlayMusic (QR first, then phone or email). Browse liked tracks, Streaming Playlists, and search. Import writes real library songs through the existing import path. A later import of the same Streaming Playlist updates the same Playlist via a Playlist Origin Stamp. A different file for the same Streaming Track Identity opens a Library Decision (Keep / Replace / Apply to Remaining). Grey songs stay visible and do not import.

Changes

  • Online Source registry with persisted YouTube and NetEase enable flags
  • Streaming Source port and NetEase adapter (weapi, China Client Address, MUSIC_U + __csrf only)
  • Streaming Import on the existing song import path, plus Library Decision
  • Video Source port: public watch and playlist resolve; yt: session transport
  • One labeled child WebView (youtube-watch) for the public watch page; audience window reparents it
  • Reveal Song File / Reveal Stems on the library song menu
  • ADRs 0031–0034, catalog/library/playback/settings/errors contracts, and README acknowledgements for AMLL, YesPlayMusic, and Kaset

Acceptance criteria

Tracked in #418 (69 user stories). Automated evidence at the four named seams:

  1. Registry — disabled source rejects browse/import; flags persist; Settings switches write enable flags
  2. Streaming Source — QR/password success stores credentials and not the password; sign-out clears credentials; disable does not; refusals for empty URL, trial clip, and no rights
  3. Existing import — first playlist import stamps origin; second import adds only missing tracks; same hash is silent; same identity + different bytes pauses on Library Decision; Keep/Replace/Apply to Remaining/cancel
  4. Existing playback session — play(yt:…) does not invoke local play; local play after YouTube tears down the WebView; ended dequeues the next id; pause/resume/seek/volume drive the video transport

Standards

  • Lifecycle, quality, and testing — ADRs 0031–0034; issue #418 acceptance; port and session tests
  • Interaction and accessibility — Settings checkboxes labeled; NetEase QR role="img" + status; phone/email fields have sr-only names; Library Decision reuses the CDG pause-and-ask dialog. Evidence: jsx-a11y via pnpm lint; component tests for Settings, NeteasePanel, YoutubePasteLink, LibraryDecisionDialog
  • Language, terminology, and data — CONTEXT.md terms only; locale-key parity via node --run check:i18n
  • Interfaces and compatibility — docs/references/contracts/{catalog,errors,library,playback,settings}.md updated with the new IPC
  • Security, privacy, and release — streaming keychain service separate from repository credentials; password never persisted; YouTube WebView is incognito and does not persist Google cookies; no /player stream URLs; no UNM

Test plan

  • node --run lint — PASS
  • node --run check:i18n — PASS
  • node --run check:standards — PASS
  • pnpm knip --no-progress — PASS
  • pnpm test:coverage — PASS (2405 tests)
  • pre-push patch coverage 83.9% (target 80%)
  • cd src-tauri && cargo test -q — PASS (1282 lib tests + integration crates)
  • cd src-tauri && cargo clippy --all-targets -- -D warnings — PASS
  • docs/references/contracts/*.md updated
  • pnpm build / pnpm tauri build — SKIPPED (CI)

Residual risk

NetEase weapi and YouTube watch-page control match YesPlayMusic and Kaset. A first desktop pass (QR or password login, one import, one public watch link on host and audience) is still the cheapest confirmation that the live pages have not drifted.

Out of scope, unchanged: UNM, Google sign-in, YouTube download, Kugou/QQ/Spotify, Match Search, AirPlay of YouTube video.

Related issues

Closes #418

coderabbitai[bot]commented· last month

[!IMPORTANT]

Review skipped

Too many files!

This PR contains 143 files, which is 43 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: Repository: thedavidweng/OpenKara/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: b9ce6a3f-62ba-4da6-8f3a-f2a6ca137db6

📥 Commits

Reviewing files that changed from the base of the PR and between 79866551240621b73eb094109d5b860c9e208081 and fce9dafe0c1fc9d6f8816eaf536b0b179fd69008.

⛔ Files ignored due to path filters (5)
  • docs/references/generated/db-schema.md is excluded by !**/generated/**, !**/generated/**, !docs/references/generated/**
  • packaging/flatpak/generated/cargo-sources.json is excluded by !**/generated/**, !**/generated/**, !packaging/flatpak/generated/**
  • src-tauri/Cargo.lock is excluded by !**/*.lock, !src-tauri/Cargo.lock
  • src-tauri/icons/Assets.car is excluded by !src-tauri/icons/**
  • src-tauri/icons/OpenKara.icon/Assets/OpenKara Mic.png is excluded by !**/*.png, !src-tauri/icons/**
📒 Files selected for processing (143)
  • .github/workflows/packaging.yml
  • CONTEXT.md
  • README.md
  • README_CN.md
  • docs/adr/0015-lyrics-acquisition-multi-source-fallback-chain.md
  • docs/adr/0026-put-amll-first-among-online-lyrics-sources.md
  • docs/adr/0027-upgrade-online-line-timed-lyrics-only-on-a-confident-amll-match.md
  • docs/adr/0031-keep-online-sources-distinct-from-remote-providers.md
  • docs/adr/0032-end-streaming-import-at-the-shared-import-path.md
  • docs/adr/0033-send-a-china-client-address-and-do-not-ship-unm.md
  • docs/adr/0034-play-youtube-from-the-public-watch-page.md
  • docs/adr/README.md
  • docs/references/contracts/catalog.md
  • docs/references/contracts/errors.md
  • docs/references/contracts/library.md
  • docs/references/contracts/lyrics.md
  • docs/references/contracts/playback.md
  • docs/references/contracts/settings.md
  • rust-toolchain.toml
  • src-tauri/Cargo.toml
  • src-tauri/capabilities/default.json
  • src-tauri/migrations/015_streaming_identity.sql
  • src-tauri/src/app_runtime.rs
  • src-tauri/src/cache/mod.rs
  • src-tauri/src/catalog/credentials.rs
  • src-tauri/src/catalog/identity.rs
  • src-tauri/src/catalog/import.rs
  • src-tauri/src/catalog/mod.rs
  • src-tauri/src/catalog/netease/client.rs
  • src-tauri/src/catalog/netease/crypto.rs
  • src-tauri/src/catalog/netease/mod.rs
  • src-tauri/src/catalog/registry.rs
  • src-tauri/src/catalog/reveal.rs
  • src-tauri/src/catalog/streaming.rs
  • src-tauri/src/catalog/types.rs
  • src-tauri/src/catalog/video.rs
  • src-tauri/src/catalog/youtube.rs
  • src-tauri/src/commands/catalog.rs
  • src-tauri/src/commands/error.rs
  • src-tauri/src/commands/mod.rs
  • src-tauri/src/commands/settings.rs
  • src-tauri/src/commands/youtube_watch.rs
  • src-tauri/src/config/execution_provider.rs
  • src-tauri/src/config/library_registry.rs
  • src-tauri/src/config/mod.rs
  • src-tauri/src/config/persistence.rs
  • src-tauri/src/config/preferences.rs
  • src-tauri/src/hash.rs
  • src-tauri/src/lib.rs
  • src-tauri/src/lyrics/README.md
  • src-tauri/src/lyrics/acquisition.rs
  • src-tauri/src/remote/dropbox.rs
  • src-tauri/src/remote/google_drive.rs
  • src-tauri/src/remote/types.rs
  • src-tauri/src/services/playback.rs
  • src-tauri/src/state/catalog.rs
  • src-tauri/src/state/mod.rs
  • src-tauri/src/system_credentials.rs
  • src/components/Catalog/NeteasePanel.test.tsx
  • src/components/Catalog/NeteasePanel.tsx
  • src/components/Catalog/NeteaseSignIn.tsx
  • src/components/Catalog/YoutubePasteLink.test.tsx
  • src/components/Catalog/YoutubePasteLink.tsx
  • src/components/Layout/AppLayout.preview.test.tsx
  • src/components/Layout/AppLayout.test.tsx
  • src/components/Layout/AppLayout.tsx
  • src/components/Layout/Sidebar.catalog.test.tsx
  • src/components/Layout/Sidebar.preview.test.tsx
  • src/components/Layout/Sidebar.test.tsx
  • src/components/Layout/Sidebar.tsx
  • src/components/Layout/ToastContainer.test.tsx
  • src/components/Layout/ToastContainer.tsx
  • src/components/Library/ContextMenu.tsx
  • src/components/Library/LibraryDecisionDialog.test.tsx
  • src/components/Library/LibraryDecisionDialog.tsx
  • src/components/Library/SongListItem.tsx
  • src/components/Library/song-list-item-menu.test.ts
  • src/components/Library/song-list-item-menu.ts
  • src/components/Playback/PlaybackStage.test.tsx
  • src/components/Playback/PlaybackStage.tsx
  • src/components/Player/NowPlayingInfo.test.tsx
  • src/components/Player/NowPlayingInfo.tsx
  • src/components/Player/QueuePanel.test.tsx
  • src/components/Player/QueuePanel.tsx
  • src/components/Player/SeekBar.tsx
  • src/components/Player/VolumeSliders.tsx
  • src/components/Settings/SettingsOnlineSourcesSection.test.tsx
  • src/components/Settings/SettingsOnlineSourcesSection.tsx
  • src/components/Settings/SettingsOverlay.tsx
  • src/hooks/use-playback-runtime.test.tsx
  • src/lib/backend/index.ts
  • src/lib/backend/mock-backend.ts
  • src/lib/backend/tauri-backend.ts
  • src/lib/backend/types.ts
  • src/lib/debug-info.test.ts
  • src/lib/debug-info.ts
  • src/lib/i18n.test.ts
  • src/lib/i18n.ts
  • src/lib/native-context-menu.ts
  • src/lib/settings-controller/settings-controller.test.ts
  • src/lib/settings-controller/settings-controller.ts
  • src/lib/settings-controller/types.ts
  • src/lib/song-commands/song-commands.ts
  • src/lib/song-commands/types.ts
  • src/lib/tauri/catalog.ts
  • src/lib/tauri/settings.ts
  • src/lib/tauri/tauri-wrappers.test.ts
  • src/lib/tauri/youtube-watch.ts
  • src/locales/de.json
  • src/locales/en.json
  • src/locales/es.json
  • src/locales/fr.json
  • src/locales/id.json
  • src/locales/it.json
  • src/locales/ja.json
  • src/locales/ko.json
  • src/locales/nl.json
  • src/locales/pl.json
  • src/locales/pt-BR.json
  • src/locales/ru.json
  • src/locales/th.json
  • src/locales/tr.json
  • src/locales/vi.json
  • src/locales/zh-CN.json
  • src/locales/zh-TW.json
  • src/mock/tauri-mock-data.ts
  • src/mock/tauri-mock-impl.ts
  • src/playback/index.ts
  • src/playback/session.test.ts
  • src/playback/session.ts
  • src/playback/youtube-transport.test.ts
  • src/playback/youtube-transport.ts
  • src/playback/youtube-watch-host.tauri.test.ts
  • src/playback/youtube-watch-host.ts
  • src/playback/youtube-watch-native.ts
  • src/runtime/airplay-runtime.ts
  • src/stores/catalog-store.test.ts
  • src/stores/catalog-store.ts
  • src/stores/player-store.ts
  • src/stores/settings-store.test.ts
  • src/stores/settings-store.ts
  • src/types/ipc-contract.test.ts
  • src/types/ipc.ts

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
  • X
  • Mastodon
  • Reddit
  • LinkedIn

Comment [@coderabbitai](/coderabbitai) help to get the list of available commands.

codecov[bot]commented· last month

Codecov Report

:x: Patch coverage is 88.70558% with 89 lines in your changes missing coverage. Please review. :white_check_mark: Project coverage is 88.6%. Comparing base (ee2338d) to head (fce9daf). :warning: Report is 1 commits behind head on main. :white_check_mark: All tests successful. No failed tests found.

Files with missing linesPatch %Lines
src/playback/youtube-watch-host.ts81.5%27 Missing :warning:
src/stores/player-store.ts13.3%13 Missing :warning:
src/lib/song-commands/song-commands.ts0.0%12 Missing :warning:
src/playback/youtube-transport.ts92.3%8 Missing :warning:
src/components/Layout/Sidebar.tsx69.5%6 Missing and 1 partial :warning:
src/components/Playback/PlaybackStage.tsx88.2%4 Missing :warning:
src/components/Library/SongListItem.tsx75.0%3 Missing :warning:
src/playback/session.ts93.0%3 Missing :warning:
src/components/Catalog/NeteasePanel.tsx96.1%1 Missing and 1 partial :warning:
src/components/Library/song-list-item-menu.ts75.0%2 Missing :warning:
... and 6 more
Additional details and impacted files
@@          Coverage Diff           @@
##            main    #419    +/-   ##
======================================
  Coverage   88.5%   88.6%
======================================
  Files        211     220     +9
  Lines      10913   11697   +784
  Branches    3338    3531   +193
======================================
+ Hits        9662   10365   +703
- Misses      1200    1279    +79
- Partials      51      53     +2
FlagCoverage Δ
frontend88.6% <88.7%> (+<0.1%):arrow_up:

Flags with carried forward coverage won't be shown. Click here to find out more.

ComponentsCoverage Δ
frontend88.6% <88.7%> (+<0.1%):arrow_up:
rust∅ <ø> (∅)
Files with missing linesCoverage Δ
src/components/Catalog/YoutubePasteLink.tsx100.0% <100.0%> (ø)
src/components/Layout/AppLayout.tsx95.8% <100.0%> (+<0.1%):arrow_up:
src/components/Layout/ToastContainer.tsx94.4% <ø> (ø)
src/components/Player/NowPlayingInfo.tsx64.7% <100.0%> (+1.4%):arrow_up:
src/components/Player/SeekBar.tsx92.4% <100.0%> (ø)
src/components/Player/VolumeSliders.tsx76.5% <100.0%> (+0.1%):arrow_up:
...mponents/Settings/SettingsOnlineSourcesSection.tsx100.0% <100.0%> (ø)
src/components/Settings/SettingsOverlay.tsx100.0% <ø> (ø)
src/lib/backend/mock-backend.ts100.0% <ø> (ø)
src/lib/backend/tauri-backend.ts100.0% <ø> (ø)
... and 39 more
:rocket: New features to boost your workflow:
  • :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Review

github-advanced-security[bot] · last month · 4 file comments

4 open

Review

kilo-code-bot[bot] · last month · 9 file comments

9 open
kilo-code-bot[bot]commented· last month

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (28 files)
  • docs/references/contracts/errors.md
  • src-tauri/src/catalog/netease/client.rs
  • src-tauri/src/catalog/netease/mod.rs
  • src-tauri/src/catalog/types.rs
  • src-tauri/src/commands/error.rs
  • src/components/Layout/ToastContainer.test.tsx
  • src/components/Layout/ToastContainer.tsx
  • src/lib/debug-info.test.ts
  • src/lib/debug-info.ts
  • src/locales/de.json
  • src/locales/en.json
  • src/locales/es.json
  • src/locales/fr.json
  • src/locales/id.json
  • src/locales/it.json
  • src/locales/ja.json
  • src/locales/ko.json
  • src/locales/nl.json
  • src/locales/pl.json
  • src/locales/pt-BR.json
  • src/locales/ru.json
  • src/locales/th.json
  • src/locales/tr.json
  • src/locales/vi.json
  • src/locales/zh-CN.json
  • src/locales/zh-TW.json
  • src/types/ipc-contract.test.ts
  • src/types/ipc.ts
Previous Review Summaries (6 snapshots, latest commit ece4a78)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit ece4a78)

Status: No Issues Found | Recommendation: Merge

Files Reviewed (28 files)
  • docs/references/contracts/errors.md
  • src-tauri/src/catalog/netease/client.rs
  • src-tauri/src/catalog/netease/mod.rs
  • src-tauri/src/catalog/types.rs
  • src-tauri/src/commands/error.rs
  • src/components/Layout/ToastContainer.test.tsx
  • src/components/Layout/ToastContainer.tsx
  • src/lib/debug-info.test.ts
  • src/lib/debug-info.ts
  • src/locales/de.json
  • src/locales/en.json
  • src/locales/es.json
  • src/locales/fr.json
  • src/locales/id.json
  • src/locales/it.json
  • src/locales/ja.json
  • src/locales/ko.json
  • src/locales/nl.json
  • src/locales/pl.json
  • src/locales/pt-BR.json
  • src/locales/ru.json
  • src/locales/th.json
  • src/locales/tr.json
  • src/locales/vi.json
  • src/locales/zh-CN.json
  • src/locales/zh-TW.json
  • src/types/ipc-contract.test.ts
  • src/types/ipc.ts

Previous review (commit 2599a86)

Status: No Issues Found | Recommendation: Merge

Files Reviewed (19 files)
  • .github/dependabot.yml - rust-dependencies grouping added
  • .github/workflows/ci.yml - rust-toolchain SHA updated
  • .github/workflows/dependabot-automerge.yml - new auto-merge workflow for Dependabot
  • .github/workflows/dependabot-sync.yml - approve all action_required workflow runs
  • .github/workflows/release.yml - rust-toolchain SHA updated
  • .github/workflows/reusable-linux-installed-app-smoke.yml - rust-toolchain SHA updated
  • .github/workflows/reusable-macos-installed-app-smoke.yml - rust-toolchain SHA updated
  • .github/workflows/reusable-separation-smoke.yml - rust-toolchain SHA updated
  • .github/workflows/reusable-windows-installed-app.yml - rust-toolchain SHA updated
  • .github/workflows/spectral-candidate.yml - rust-toolchain SHA updated
  • package.json - zustand bumped to 5.0.15
  • scripts/ci/classify-changes.mjs - dependabot-automerge.yml added to other_workflow
  • src-tauri/Cargo.lock - dependency updates
  • src-tauri/deny.toml - removed resolved quick-xml advisory ignores
  • src-tauri/src/cache/waveforms.rs - replaced chunks_exact with as_chunks
  • tests/ci/dependabot-automerge-contract.test.ts - new contract tests for automerge workflow
  • packaging/flatpak/generated/cargo-sources.json - regenerated
  • packaging/flatpak/generated/node-sources.0.json - regenerated
  • pnpm-lock.yaml - dependency updates

Previous review (commit 0750d38)

Status: No Issues Found | Recommendation: Merge

Files Reviewed (2 files)
  • src/components/Catalog/NeteasePanel.test.tsx - test updates for visible labels
  • src/components/Catalog/NeteaseSignIn.tsx - visible labels, responsive QR container, layout restructure

Previous review (commit 4805a60)

Status: No Issues Found | Recommendation: Merge

Files Reviewed (4 files)
  • src/lib/tauri/catalog.ts - parameter key alignment with Tauri v2 camelCase conversion
  • src/lib/tauri/settings.ts - parameter key alignment with Tauri v2 camelCase conversion
  • src/lib/tauri/tauri-wrappers.test.ts - test expectations updated for camelCase keys
  • src/mock/tauri-mock-impl.ts - mock input parameter types updated to camelCase

Previous review (commit 0df7326)

Status: No Issues Found | Recommendation: Merge

Files Reviewed (25 files)
  • .github/workflows/packaging.yml - WinGet release resolution fix
  • docs/references/contracts/playback.md - type alignment fix
  • docs/references/generated/db-schema.md - migration schema update
  • src-tauri/Cargo.toml - removed unused cipher dependency
  • src-tauri/src/catalog/import.rs - transaction wrapping fix
  • src-tauri/src/catalog/streaming.rs - test password fixture fix
  • src/locales/*.json (18 files) - translated new Online Sources surfaces
  • src/mock/tauri-mock-impl.ts - mock parameter handling fix

Previous review (commit 8eb9aa1)

Status: 7 Issues Found | Recommendation: Address before merge

Overview

SeverityCount
CRITICAL0
WARNING5
SUGGESTION2
Issue Details (click to expand)

WARNING

FileLineIssue
src/locales/de.json194New locale keys hardcoded in English instead of translated
src/locales/fr.json195New locale keys hardcoded in English instead of translated
src/locales/es.json195New locale keys hardcoded in English instead of translated
src/locales/ja.json194New locale keys hardcoded in English instead of translated
src/mock/tauri-mock-impl.ts820Mock implementation ignores command parameters
src/mock/tauri-mock-impl.ts847Mock implementation ignores action parameter
src-tauri/src/catalog/import.rs307apply_replace not wrapped in a transaction

SUGGESTION

FileLineIssue
docs/references/contracts/playback.md10resolve_video_source_url type inconsistent with catalog contract
docs/references/contracts/catalog.md226resolve_video_source_url type inconsistent with playback contract
Files Reviewed (9 files)
  • src/locales/de.json - hardcoded English locale keys
  • src/locales/fr.json - hardcoded English locale keys
  • src/locales/es.json - hardcoded English locale keys
  • src/locales/ja.json - hardcoded English locale keys
  • src/mock/tauri-mock-impl.ts - mock parameter handling
  • docs/references/contracts/playback.md - type inconsistency
  • docs/references/contracts/catalog.md - type inconsistency
  • src-tauri/src/catalog/import.rs - missing transaction wrapping

Fix these issues in Kilo Cloud


Reviewed by free · Input: 190.2K · Output: 24.6K · Cached: 116.4K

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

Review

dev · last month

devcommented· last month

Pushed 0df73261 for the failed required checks and every review thread.

CI

  • JS quality: regenerate docs/references/generated/db-schema.md for 015_streaming_identity.sql
  • App frontend / Flatpak: error titles now use snake-case locale keys that match ErrorCode (errors.online_source_disabled)
  • Dependency surface: drop unused direct cipher crate (cbc::cipher is enough)
  • WinGet: resolve gh release list with isLatest so the nightly prerelease is not treated as vnightly

Review threads

  • CodeQL hard-coded passwords: test fixtures only; passwords are built at runtime
  • Kilo locales: translated the new Online Sources surfaces in every locale
  • Kilo mocks: sign-in and continue-import now honor command arguments
  • Kilo contracts: playback source_id is OnlineSourceId
  • Kilo apply_replace: one SQLite transaction, files deleted after commit

Not a code change

  • CodeRabbit skipped because this PR is over the 100-file review limit. Splitting would break the #418 seam (registry + import + YouTube transport).
  • Codecov’s “JUnit XML file not found” is an upload-config warning on the frontend job, not a required gate.
github-actions[bot]commented· last month

Coverage Report

Status Category Percentage Covered / Total
🟢 Lines 84.7% (🎯 65%) 8160 / 9633
🟢 Statements 83.9% (🎯 65%) 8653 / 10313
🟢 Functions 80.23% (🎯 60%) 2058 / 2565
🟢 Branches 76.6% (🎯 60%) 4634 / 6049
File Coverage
File Stmts Branches Functions Lines Uncovered Lines
Changed Files
src/components/Catalog/NeteasePanel.tsx 100% 83.33% 100% 100%
src/components/Catalog/NeteaseSignIn.tsx 98.43% 97.67% 100% 98.24% 60
src/components/Catalog/YoutubePasteLink.tsx 100% 100% 100% 100%
src/components/Layout/AppLayout.tsx 95.65% 94.44% 88.23% 94.59% 65, 107
src/components/Layout/Sidebar.tsx 77.65% 73.46% 72.22% 75.34% 69-72, 92, 93, 94, 111-114, 134, 231, 248-376
src/components/Layout/ToastContainer.tsx 92.3% 96.42% 83.33% 91.66% 61, 64, 121
src/components/Library/ContextMenu.tsx 86.4% 75.83% 85.71% 86.73% 50-51, 56-66, 86-90, 120, 147, 218, 253, 280, 317-318, 352, 362, 365, 381
src/components/Library/LibraryDecisionDialog.tsx 93.75% 83.33% 88.88% 92.85% 33
src/components/Library/SongListItem.tsx 68.03% 65.25% 57.14% 67.54% 69-70, 87-88, 98, 131, 151-152, 159, 163-208, 228-229, 419-425, 441-463
src/components/Library/song-list-item-menu.ts 75% 95.55% 45.45% 75% 160, 165, 224, 229, 282-287
src/components/Playback/PlaybackStage.tsx 92.98% 88.46% 88.88% 92% 88, 98, 112-113
src/components/Player/NowPlayingInfo.tsx 56.41% 50% 66.66% 54.54% 24-29, 80-98
src/components/Player/QueuePanel.tsx 63.8% 41.66% 53.65% 57.77% 251-267, 299-300, 307-310, 316-319, 323, 344, 349-350, 355-374, 386-427, 435-437, 441, 446-453, 551-560
src/components/Player/SeekBar.tsx 90.29% 71.73% 92.5% 93.92% 99, 108, 117, 125-126, 156-158, 171, 184, 200, 228, 281, 288-289, 295-297, 309
src/components/Player/VolumeSliders.tsx 74.47% 76% 58.13% 74.72% 58, 63, 117, 143-151, 160-168, 199, 244-245, 254-255, 268-272, 277-290, 295-299, 304-308, 313-317, 346-366, 381-428, 504
src/components/Settings/SettingsOnlineSourcesSection.tsx 100% 100% 100% 100%
src/components/Settings/SettingsOverlay.tsx 100% 100% 100% 100%
src/lib/debug-info.ts 100% 88.23% 100% 100%
src/lib/i18n.ts 88% 100% 75% 87.5% 14-15, 48
src/lib/backend/index.ts 100% 100% 100% 100%
src/lib/backend/mock-backend.ts 100% 100% 100% 100%
src/lib/backend/tauri-backend.ts 100% 100% 100% 100%
src/lib/backend/types.ts 100% 100% 100% 100%
src/lib/settings-controller/settings-controller.ts 96.08% 91.48% 98.05% 96.28% 48, 99, 137, 258, 319, 335-336, 363, 559, 588-589, 684, 698, 992-994
src/lib/settings-controller/types.ts 100% 100% 100% 100%
src/lib/song-commands/song-commands.ts 85.91% 81.69% 73.17% 84.96% 282-299, 331, 334-336, 339-343, 353-357
src/lib/song-commands/types.ts 100% 100% 100% 100%
src/locales/de.json 100% 100% 100% 100%
src/locales/en.json 100% 100% 100% 100%
src/locales/es.json 100% 100% 100% 100%
src/locales/fr.json 100% 100% 100% 100%
src/locales/id.json 100% 100% 100% 100%
src/locales/it.json 100% 100% 100% 100%
src/locales/ja.json 100% 100% 100% 100%
src/locales/ko.json 100% 100% 100% 100%
src/locales/nl.json 100% 100% 100% 100%
src/locales/pl.json 100% 100% 100% 100%
src/locales/pt-BR.json 100% 100% 100% 100%
src/locales/ru.json 100% 100% 100% 100%
src/locales/th.json 100% 100% 100% 100%
src/locales/tr.json 100% 100% 100% 100%
src/locales/vi.json 100% 100% 100% 100%
src/locales/zh-CN.json 100% 100% 100% 100%
src/locales/zh-TW.json 100% 100% 100% 100%
src/mock/tauri-mock-data.ts 100% 50% 100% 100%
src/playback/index.ts 100% 100% 100% 100%
src/playback/session.ts 95.03% 92% 100% 94.81% 220-224, 293, 317-318
src/playback/youtube-transport.ts 86.51% 81.48% 81.57% 90.24% 93-94, 95, 96, 111-116, 148
src/playback/youtube-watch-host.ts 81.51% 71.42% 81.48% 81.35% 46, 53, 56, 61, 105-108, 131, 135, 153, 211-217, 227, 256, 277, 282-284, 317
src/playback/youtube-watch-native.ts 100% 87.5% 100% 100%
src/runtime/airplay-runtime.ts 53.96% 55.55% 47.82% 61.81% 30-74, 94, 140
src/stores/catalog-store.ts 98.33% 80% 100% 100% 101
src/stores/player-store.ts 80.53% 63.15% 80% 82.72% 152, 177-194, 202-204, 242, 250, 303, 311, 319, 343, 349, 357, 365, 421-422
src/stores/settings-store.ts 100% 73.33% 100% 100%
Generated in workflow #1886 for commit fce9daf by the Vitest Coverage Report Action

Review

github-advanced-security[bot] · 4 weeks ago · 3 file comments

3 open

Review

github-advanced-security[bot] · 3 weeks ago · 2 file comments

2 open

Review

github-advanced-security[bot] · last week · 1 file comment

1 open

Review

github-advanced-security[bot] · last week · 2 file comments

2 open
This branch can’t be merged automatically yet
Branch comparison failed — verify branches still exist in storage.
0 approving reviews
None yet
Checks
No checks recorded
Fast-forward
Source must contain the target branch tip
main ← feat/418-online-sources

Sign in to comment.

Stack

1/2
1

Merge readiness

Checking mergeability after the indexing worker computes the current branch state.

Autopilot

Debug

Reviews

Approved0
ReviewersNone yet

Configure an OpenRouter key in repository settings.

src-tauri/src/catalog/streaming.rs
line 539
View file
  1. github-advanced-security[bot]· last month
  • src-tauri/src/catalog/streaming.rsline 519
  • src-tauri/src/catalog/import.rsline 558
  • src-tauri/src/catalog/streaming.rsline 502
  • src/locales/de.json
    line 194
    View file
    1. kilo-code-bot[bot]· last month
  • src/locales/fr.jsonline 195
  • docs/references/contracts/catalog.mdline 226
  • src/locales/ja.jsonline 194
  • src/mock/tauri-mock-impl.tsline 847
  • src/locales/es.jsonline 195
  • docs/references/contracts/playback.mdline 10
  • src/mock/tauri-mock-impl.tsline 820
  • src-tauri/src/catalog/import.rsline 307
  • src-tauri/src/catalog/netease/mod.rs
    line 758
    View file
    1. github-advanced-security[bot]· 4 weeks ago
  • src-tauri/src/catalog/netease/mod.rsline 831
  • src-tauri/src/catalog/netease/mod.rsline 798
  • src-tauri/src/catalog/types.rs
    line 322
    View file
    1. github-advanced-security[bot]· 3 weeks ago
  • src-tauri/src/catalog/types.rsline 323
  • src-tauri/src/catalog/netease/crypto.rs
    line 11
    View file
    1. github-advanced-security[bot]· last week
    src-tauri/src/catalog/netease/crypto.rs
    lines 16-19
    View file
    1. github-advanced-security[bot]· last week
  • src-tauri/src/catalog/netease/crypto.rslines 23-26
  • feat(catalog): add Online Sources for NetEase import and YouTube queue

    #419 main ← feat/418-online-sources

    Updated last month

    open
    2

    CodeQL / Hard-coded cryptographic value

    This hard-coded value is used as a password.

    Show more details

  • dev· last month

    Addressed in 0df73261. The resolve/refusal test now uses the same runtime-built fixture password.

  • View file
    1. github-advanced-security[bot]· last month

      CodeQL / Hard-coded cryptographic value

      This hard-coded value is used as a password.

      Show more details

    2. dev· last month

      Addressed in 0df73261. The email sign-in test now uses the same runtime-built fixture password.

    View file
    1. github-advanced-security[bot]· last month

      CodeQL / Hard-coded cryptographic value

      This hard-coded value is used as a password.

      Show more details

    2. dev· last month

      Addressed in 0df73261. That string was a unit-test login fixture, not a shipped secret. Tests now build the password at runtime so CodeQL does not treat a hard-coded literal as a credential.

    View file
    1. github-advanced-security[bot]· last month

      CodeQL / Hard-coded cryptographic value

      This hard-coded value is used as a password.

      Show more details

    2. dev· last month

      Addressed in 0df73261. Same test-only sink: the FakeStreamingSource password is assembled at runtime and then asserted not to land in stored credentials.

    WARNING: New locale keys are hardcoded in English instead of translated

    Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.


    Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

  • dev· last month

    Addressed in 0df73261. Online Sources, NetEase, YouTube, Library Decision, and error titles are now translated in every locale, not left as English copies.

  • View file
    1. kilo-code-bot[bot]· last month

      WARNING: New locale keys are hardcoded in English instead of translated

      Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. French copy for the new catalog, YouTube, decision, settings, and error strings is in this commit.

    View file
    1. kilo-code-bot[bot]· last month

      SUGGESTION: resolve_video_source_url type is inconsistent with playback contract

      This documents source_id: OnlineSourceId, but docs/references/contracts/playback.md line 10 documents source_id: String. Align the type across both contracts.


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. Catalog already used OnlineSourceId; playback.md is now aligned to that type.

    View file
    1. kilo-code-bot[bot]· last month

      WARNING: New locale keys are hardcoded in English instead of translated

      Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. Japanese copy for the new catalog, YouTube, decision, settings, and error strings is in this commit.

    View file
    1. kilo-code-bot[bot]· last month

      WARNING: Mock implementation ignores command parameters

      continue_streaming_import ignores the action parameter and always returns status: "completed". Tests that don't override this command will miss conflict-resolution logic (Keep/Replace/Apply to Remaining/Cancel).


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. continue_streaming_import now inspects action. Cancel records a cancelled failure; keep/replace complete without a conflict.

    View file
    1. kilo-code-bot[bot]· last month

      WARNING: New locale keys are hardcoded in English instead of translated

      Non-English users will see untranslated UI strings for the new catalog and decision surfaces. Only zh-CN.json and zh-TW.json provide translations for these new keys.


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. Spanish copy for the new catalog, YouTube, decision, settings, and error strings is in this commit.

    View file
    1. kilo-code-bot[bot]· last month

      SUGGESTION: resolve_video_source_url type is inconsistent with catalog contract

      This documents source_id: String, but docs/references/contracts/catalog.md line 226 documents source_id: OnlineSourceId. Align the type across both contracts.


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. Playback now documents source_id: OnlineSourceId, matching the catalog contract.

    View file
    1. kilo-code-bot[bot]· last month

      WARNING: Mock implementation ignores command parameters

      sign_in_streaming_source only reads args.identifier and silently drops source_id, method, password, and country_code. Tests using the base mock cannot verify password handling, method validation, or country-code forwarding.


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. The preview mock now reads source_id, method, identifier, and country_code, and forgets password after the call — the same rule as the real command.

    View file
    1. kilo-code-bot[bot]· last month

      WARNING: apply_replace performs multiple database and filesystem mutations without a transaction

      If the process crashes after import_file but before stamp_identity, the new song exists in the library, old stems/waveforms/songs are deleted, and playlists are partially updated — leaving an inconsistent state.


      Reply with [@kilocode-bot](/kilocode-bot) fix it to have Kilo Code address this issue.

    2. dev· last month

      Addressed in 0df73261. apply_replace now imports, retargets lyrics/playlists, and deletes the old song rows in one SQLite transaction, then removes files after commit.

    CodeQL / Hard-coded cryptographic value

    This hard-coded value is used as a password.

    Show more details

    View file
    1. github-advanced-security[bot]· 4 weeks ago

      CodeQL / Hard-coded cryptographic value

      This hard-coded value is used as a password.

      Show more details

    View file
    1. github-advanced-security[bot]· 4 weeks ago

      CodeQL / Hard-coded cryptographic value

      This hard-coded value is used as a password.

      Show more details

    CodeQL / Hard-coded cryptographic value

    This hard-coded value is used as a password.

    Show more details

    View file
    1. github-advanced-security[bot]· 3 weeks ago

      CodeQL / Hard-coded cryptographic value

      This hard-coded value is used as a password.

      Show more details

    CodeQL / Hard-coded cryptographic value

    This hard-coded value is used as a key.

    Show more details

    CodeQL / Hard-coded cryptographic value

    This hard-coded value is used as a key.

    Show more details

    View file
    1. github-advanced-security[bot]· last week

      CodeQL / Hard-coded cryptographic value

      This hard-coded value is used as an initialization vector.

      Show more details

    chore(tooling): upgrade pnpm to 12.5.1

    #457 feat/418-online-sources ← cursor/pnpm-12-27b8

    Updated last week

    open