fix(guest): deny favorites + auth-status reads to guests; UI polish

Consolidated fix wave from the final whole-branch review of guest mode.

- FIX 1 (critical): gate /api/favorites mount with requireNotGuest — the
  router keys off req.user.id (shared __guest__ principal), so guests could
  read/write a shared favorites bucket. Added focused guest-deny tests.
- FIX 2: gate GET /api/auth/status and /api/auth/qrcode/status with
  requireNotGuest so config reads no longer leak to guests.
- FIX 3: requireAuthInline in createSessionRouter now rejects guest sessions
  with 401 once guest mode is disabled (mirrors createRequireAuth), so /me
  stops returning guest data after an admin disables the feature.
- FIX 4: Login guest button now sits BELOW the card (auth-page flex-direction
  column + guest-btn width 360px) instead of beside it.
- FIX 5: mobile mini-player transport buttons in App.vue are now per-button
  gated for guests (prev/play/next/mode/volume), mirroring Player.vue.
- FIX 6: refreshed stale "gated on player.control" seek comments in Player.vue
  and relabeled the now-stale quality-GET test.

npm test: 354/354 pass. npm run build: tsc + vue-tsc + vite all green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
saopig1andClaude Opus 4.8 committed 2026-06-25 12:44:07 +08:00
1 parent e47fc76529
commit f142c514cd
8 files changed
+113 -12

No files matched your search

+2 -2
View File
@@ -3,7 +3,7 @@
<Queue :open="showQueue" @close="showQueue = false" />
<div class="player-bar frosted-glass">
<!-- Progress bar (read-only display; seek interaction gated on player.control) -->
<!-- Progress bar (read-only display; seek interaction gated on transport / canTransport) -->
<div
class="progress-bar-container"
:class="{ 'no-seek': !canTransport }"
@@ -147,7 +147,7 @@ function updateProgress() {
}
async function onProgressClick(e: MouseEvent) {
if (!canTransport.value) return; // seek requires player.control
if (!canTransport.value) return; // seek gated on transport (canTransport)
const bar = progressBarRef.value;
if (!bar) return;
const rect = bar.getBoundingClientRect();