Senko-san 7a17e3babd feat(subsonic): per-user encrypted app-password foundation
Subsonic auth (t=md5(password+salt), legacy p=) needs a recoverable secret,
but login passwords are stored as a one-way argon2 hash. Add a separate,
per-user app-password: high-entropy, random, and encrypted at rest with a
Fernet key derived from SUBSONIC_SECRET_KEY (never stored in the DB).

- SubsonicPasswordCipher + generate_subsonic_password in core.security
- users.subsonic_password_enc column (+ Alembic migration), repo + port methods
- SubsonicAuthService: verify (t+s / p / p=enc:) and rotate/reveal lifecycle
- self-service GET/POST /users/me/subsonic-password + admin rotate endpoint
- domain SubsonicCredentials + SubsonicCipher port; deps wiring

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-08 18:23:19 +03:00
2026-06-07 21:37:30 +03:00
2026-06-06 12:30:49 +03:00
2026-06-01 18:47:59 +03:00
2026-06-01 18:47:59 +03:00
2026-06-01 18:47:59 +03:00
2026-06-01 18:47:59 +03:00
2026-06-01 18:47:59 +03:00
2026-06-03 10:40:00 +03:00
2026-06-03 10:40:00 +03:00

mcma-backend

Self-hosted, offline-first music service — backend. Searches/downloads music from external sources, stores files + metadata, streams to clients, and serves a native REST API plus a Subsonic-compatible API.

Status: Phase 1 (core/MVP) — project skeleton in place. See the implementation plan for the full roadmap.

Architecture — hexagonal (ports & adapters)

app/
├── domain/          pure core: entities, value objects, errors, ports (Protocols)
├── application/     use cases / services — orchestrate domain via ports
├── infrastructure/  driven adapters: ORM, repositories, db, redis, sources, ML client
│   ├── db/          declarative base, async engine, session factory
│   └── cache/       redis client
├── api/             driving adapter: FastAPI routers, schemas, deps, middleware
├── workers/         arq background tasks (download, enrich, transcode)
└── core/            cross-cutting: config, logging, security

Rule: dependencies point inward. domain imports nothing framework-specific; application depends on domain ports; infrastructure/api are the outer ring and are wired together at the composition root (app/main.py, app/api/deps.py).

Build (Docker)

This repo ships only its own Dockerfile — the image runs anywhere and gets every peer (Postgres, Redis, media path) from env. It carries no orchestration. Full-stack wiring lives in the workspace compose one level up (../docker-compose.yml, alongside mcma-webui):

docker build -t mcma-backend .                  # build just this service
# or, from the workspace root, the whole stack:
docker compose --profile app up --build         # db, redis, api, worker, webui

Local dev (without Docker)

uv sync                       # install deps (uses managed Python 3.14)
# start backing services from the workspace root: `docker compose up -d` (db + redis)
cp .env.example .env          # then set a real JWT_SECRET
uv run uvicorn app.main:app --reload

Tooling

uv run ruff check .           # lint
uv run ruff format .          # format
uv run mypy app               # type-check (strict)
uv run pytest                 # tests

Database migrations (Alembic)

uv run alembic revision --autogenerate -m "message"   # after model changes
uv run alembic upgrade head                            # apply

The DB URL is injected from app settings — never hardcoded in alembic.ini.

Configuration

All settings come from environment variables (or .env in dev). See .env.example. External services (ML, AcoustID, MusicBrainz) are optional — the backend degrades gracefully when they are absent.

S
Description
💾 Backend for self-hosted, offline-first music service - MCMA
Readme 3.1 MiB
Languages
Python 99.9%
Mako 0.1%