diff --git a/README.md b/README.md index 833c7b1..945c799 100644 --- a/README.md +++ b/README.md @@ -636,6 +636,11 @@ OAuth 相关端点:`/api/spotify/login`、`/api/spotify/callback`、`/api/spot | Windows 上无法使用 go-librespot | 属预期行为(FIFO 仅限 POSIX,官方无 Windows 资产);请把 `backend` 设为 `librespot` 或 `auto` | | 完全没有声音 | 确认账号为 **Spotify Premium**;免费账号无法通过 Spotify Connect 输出音频 | +### 已知限制 + +- 在多租户/共享主机上,librespot 通过命令行参数接收访问令牌,同机其他本地进程理论上可读取(令牌约 1 小时有效,需本地访问权限)。 +- Spotify 连续播放(gapless spotify→spotify)时,网页进度条的"已播放时间"可能不准确(以后端上报的播放进度为准)。 + ## 配置文件 配置文件位于 **`data/config.json`**(与数据库、Cookie、日志同在持久化的 `data/` 目录,Docker 部署对应挂载卷),首次运行时自动生成,可手动编辑: diff --git a/src/bot/instance.ts b/src/bot/instance.ts index aed5988..af774be 100755 --- a/src/bot/instance.ts +++ b/src/bot/instance.ts @@ -725,6 +725,10 @@ export class BotInstance extends EventEmitter { // (so NO player.stop() here). On the gapless auto-advance path the // player is still attached (isExternalActive() === true) so we do NOT // re-attach — the sidecar rolls the SAME FIFO into the next track. + // KNOWN LIMITATION: on a gapless spotify->spotify advance the player's + // frame counter is not reset, so player.getElapsed() over-reads for the + // 2nd+ consecutive Spotify track. Cosmetic only — the authoritative + // elapsed shown to users is status.track.position from the backend poll. if (!this.player.isExternalActive()) { this.player.playPcmStream(this.spotifyController.getPcmStream(), { // The sidecar PCM pipe is long-lived; per-track end arrives via the diff --git a/src/music/spotify/rust-librespot.ts b/src/music/spotify/rust-librespot.ts index a2081fc..fc3a72e 100644 --- a/src/music/spotify/rust-librespot.ts +++ b/src/music/spotify/rust-librespot.ts @@ -149,6 +149,10 @@ export class RustLibrespotBackend extends EventEmitter implements SpotifyAudioBa "--format", "S16", "--cache", this.opts.cacheDir, "--device-type", "speaker", + // KNOWN LIMITATION (CWE-214): the live Spotify access token is passed in + // the child argv, so on a shared/multi-tenant host a co-located local + // process could read it via `ps` / /proc//cmdline. Bounded (~1h token, + // needs local access) and `--access-token` is librespot's supported bootstrap. "--access-token", token, ], { stdio: ["ignore", "pipe", "pipe"] },