docs(spotify): document known limitations (token CLI arg, gapless elapsed) [whole-branch d1,d2]

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
saopig1andClaude Opus 4.8 committed 2026-07-03 01:55:34 +08:00
1 parent 0914cfeb2f
commit 11c0948330
3 files changed
+13

No files matched your search

+4
View File
@@ -725,6 +725,10 @@ export class BotInstance extends EventEmitter {
// (so NO player.stop() here). On the gapless auto-advance path the
// player is still attached (isExternalActive() === true) so we do NOT
// re-attach — the sidecar rolls the SAME FIFO into the next track.
// KNOWN LIMITATION: on a gapless spotify->spotify advance the player's
// frame counter is not reset, so player.getElapsed() over-reads for the
// 2nd+ consecutive Spotify track. Cosmetic only — the authoritative
// elapsed shown to users is status.track.position from the backend poll.
if (!this.player.isExternalActive()) {
this.player.playPcmStream(this.spotifyController.getPcmStream(), {
// The sidecar PCM pipe is long-lived; per-track end arrives via the
+4
View File
@@ -149,6 +149,10 @@ export class RustLibrespotBackend extends EventEmitter implements SpotifyAudioBa
"--format", "S16",
"--cache", this.opts.cacheDir,
"--device-type", "speaker",
// KNOWN LIMITATION (CWE-214): the live Spotify access token is passed in
// the child argv, so on a shared/multi-tenant host a co-located local
// process could read it via `ps` / /proc/<pid>/cmdline. Bounded (~1h token,
// needs local access) and `--access-token` is librespot's supported bootstrap.
"--access-token", token,
],
{ stdio: ["ignore", "pipe", "pipe"] },