Compare commits
6 Commits
7325fbfc45
...
ec5fedec33
| Author | SHA1 | Date | |
|---|---|---|---|
| ec5fedec33 | |||
| 8c1a8ead56 | |||
| ed91e4534c | |||
| 8fc1c2641b | |||
| a9da813cb1 | |||
| 6f55d36085 |
+112
-10
@@ -1,7 +1,16 @@
|
||||
import asyncio
|
||||
import ipaddress
|
||||
import json
|
||||
import socket
|
||||
from urllib.parse import urlparse
|
||||
|
||||
import httpx
|
||||
from fastapi import APIRouter, HTTPException
|
||||
from fastapi import APIRouter, Depends, HTTPException
|
||||
from pydantic import BaseModel
|
||||
from typing import Optional, Any, Dict, List
|
||||
from typing import Any, Dict
|
||||
|
||||
from app.api.v1.auth import get_current_user
|
||||
from app.api.v1.user_config import _load_ai_configs, _get_default_providers
|
||||
|
||||
router = APIRouter()
|
||||
|
||||
@@ -10,17 +19,108 @@ class ProxyRequest(BaseModel):
|
||||
headers: Dict[str, str] = {}
|
||||
body: Dict[str, Any] = {}
|
||||
|
||||
import json
|
||||
|
||||
# Ranges that are never legitimate AI endpoints: cloud metadata + this host.
|
||||
_BLOCKED_NETWORKS = [
|
||||
ipaddress.ip_network("169.254.0.0/16"), # link-local / cloud metadata
|
||||
ipaddress.ip_network("0.0.0.0/8"),
|
||||
]
|
||||
# Private ranges: only reachable when the target host is one the user has
|
||||
# explicitly configured as an AI provider (e.g. local Ollama/LM Studio).
|
||||
_PRIVATE_NETWORKS = [
|
||||
ipaddress.ip_network("10.0.0.0/8"),
|
||||
ipaddress.ip_network("172.16.0.0/12"),
|
||||
ipaddress.ip_network("192.168.0.0/16"),
|
||||
ipaddress.ip_network("127.0.0.0/8"),
|
||||
ipaddress.ip_network("::1/128"),
|
||||
ipaddress.ip_network("fc00::/7"), # ULA
|
||||
]
|
||||
|
||||
_LOOPBACK_HOSTS = {"localhost", "127.0.0.1", "::1", "0.0.0.0"}
|
||||
|
||||
|
||||
def _configured_ai_hosts(user_id: str) -> set:
|
||||
"""Hosts the user has configured as AI providers (from saved config + defaults)."""
|
||||
hosts = set()
|
||||
configs = _load_ai_configs()
|
||||
providers = configs.get(user_id) or _get_default_providers()
|
||||
for p in providers:
|
||||
base = (p.get("api_base_url") or "").strip()
|
||||
if not base:
|
||||
continue
|
||||
try:
|
||||
host = urlparse(base).hostname
|
||||
if host:
|
||||
hosts.add(host.lower())
|
||||
except Exception:
|
||||
continue
|
||||
return hosts
|
||||
|
||||
|
||||
async def _resolve_host_ips(hostname: str):
|
||||
"""Resolve hostname to IPs (non-blocking). Returns list of ipaddress objects."""
|
||||
loop = asyncio.get_event_loop()
|
||||
try:
|
||||
infos = await loop.run_in_executor(None, socket.getaddrinfo, hostname, None)
|
||||
ips = []
|
||||
for info in infos:
|
||||
try:
|
||||
ips.append(ipaddress.ip_address(info[4][0]))
|
||||
except ValueError:
|
||||
continue
|
||||
return ips
|
||||
except Exception:
|
||||
return []
|
||||
|
||||
|
||||
async def _validate_target_url(url: str, user_id: str):
|
||||
parsed = urlparse(url)
|
||||
if parsed.scheme not in ("http", "https"):
|
||||
raise HTTPException(status_code=400, detail="URL chỉ hỗ trợ giao thức http/https")
|
||||
if parsed.username or parsed.password:
|
||||
raise HTTPException(status_code=400, detail="URL không được chứa thông tin đăng nhập")
|
||||
hostname = (parsed.hostname or "").lower()
|
||||
if not hostname:
|
||||
raise HTTPException(status_code=400, detail="URL không hợp lệ")
|
||||
|
||||
allowed_hosts = _configured_ai_hosts(user_id)
|
||||
|
||||
# Hostname-level fast path for loopback hosts
|
||||
if hostname in _LOOPBACK_HOSTS:
|
||||
if hostname in allowed_hosts:
|
||||
return
|
||||
raise HTTPException(status_code=403, detail="Target nội bộ không nằm trong danh sách AI provider đã cấu hình")
|
||||
|
||||
# Try direct IP parse (hostname may itself be an IP)
|
||||
try:
|
||||
ip = ipaddress.ip_address(hostname)
|
||||
ips = [ip]
|
||||
except ValueError:
|
||||
ips = await _resolve_host_ips(hostname)
|
||||
|
||||
if not ips:
|
||||
raise HTTPException(status_code=502, detail="Không phân giải được hostname")
|
||||
|
||||
for ip in ips:
|
||||
if any(ip in net for net in _BLOCKED_NETWORKS):
|
||||
raise HTTPException(status_code=403, detail="Target bị chặn (metadata/link-local không được phép)")
|
||||
if any(ip in net for net in _PRIVATE_NETWORKS):
|
||||
if hostname in allowed_hosts:
|
||||
continue
|
||||
raise HTTPException(status_code=403, detail="Target IP nội bộ không nằm trong danh sách AI provider đã cấu hình")
|
||||
|
||||
|
||||
@router.post("/proxy")
|
||||
async def proxy_llm(req: ProxyRequest):
|
||||
async def proxy_llm(req: ProxyRequest, current_user: dict = Depends(get_current_user)):
|
||||
await _validate_target_url(req.url, current_user["user_id"])
|
||||
# Never forward the app's own auth token upstream.
|
||||
headers = {
|
||||
k: v for k, v in req.headers.items()
|
||||
if k.lower() not in ("host", "origin", "referer", "x-auth-token")
|
||||
}
|
||||
try:
|
||||
async with httpx.AsyncClient(timeout=180.0) as client:
|
||||
resp = await client.post(
|
||||
req.url,
|
||||
headers={k: v for k, v in req.headers.items() if k.lower() not in ('host', 'origin', 'referer')},
|
||||
json=req.body
|
||||
)
|
||||
async with httpx.AsyncClient(timeout=180.0, follow_redirects=False) as client:
|
||||
resp = await client.post(req.url, headers=headers, json=req.body)
|
||||
raw = resp.text
|
||||
try:
|
||||
return resp.json()
|
||||
@@ -36,5 +136,7 @@ async def proxy_llm(req: ProxyRequest):
|
||||
if 'localhost' in req.url or '127.0.0.1' in req.url:
|
||||
msg += "\nNếu app chạy trong Docker, localhost trỏ vào container, không ra host.\nHãy thay localhost bằng host.docker.internal hoặc IP bridge Docker (172.17.0.1)."
|
||||
raise HTTPException(status_code=502, detail=msg)
|
||||
except HTTPException:
|
||||
raise
|
||||
except Exception as e:
|
||||
raise HTTPException(status_code=500, detail=str(e))
|
||||
|
||||
+69
-73
@@ -8,12 +8,32 @@ from pydantic import BaseModel
|
||||
from typing import Optional, List
|
||||
import json
|
||||
from app.config import settings
|
||||
from app.api.v1.auth import get_current_user
|
||||
from app.api.v1.auth import get_current_user, enforce_password_changed
|
||||
from app.api.v1.projects import get_optional_user
|
||||
from app.models.user import get_db_connection
|
||||
|
||||
router = APIRouter()
|
||||
|
||||
MAX_AUDIO_UPLOAD_BYTES = 1024 * 1024 * 1024 # 1 GB
|
||||
|
||||
def _safe_file_id(file_id: str) -> str:
|
||||
"""Strip any path components from a client-supplied file id."""
|
||||
if not file_id:
|
||||
return ""
|
||||
return os.path.basename(file_id.replace("\\", "/"))
|
||||
|
||||
def _resolve_storage_path(file_id: str) -> str:
|
||||
"""Return the existing file path (processed first, then uploads) for a
|
||||
sanitized file id, or '' when not found."""
|
||||
fid = _safe_file_id(file_id)
|
||||
if not fid:
|
||||
return ""
|
||||
for d in (settings.PROCESSED_DIR, settings.UPLOADS_DIR):
|
||||
p = os.path.join(d, fid)
|
||||
if os.path.isfile(p):
|
||||
return p
|
||||
return ""
|
||||
|
||||
class EditRequest(BaseModel):
|
||||
file_id: str
|
||||
cut_start_ms: Optional[float] = None
|
||||
@@ -58,16 +78,32 @@ class PythonToolRequest(BaseModel):
|
||||
|
||||
@router.post("/upload")
|
||||
async def upload_audio(file: UploadFile = File(...), current_user: Optional[dict] = Depends(get_optional_user)):
|
||||
if current_user:
|
||||
enforce_password_changed(current_user)
|
||||
user_id = current_user["user_id"] if current_user else "anonymous"
|
||||
ext = os.path.splitext(file.filename)[1]
|
||||
ext = os.path.splitext(file.filename or "")[1]
|
||||
if not ext:
|
||||
ext = ".wav"
|
||||
file_id = f"user_{user_id}_{uuid.uuid4()}{ext}"
|
||||
file_path = os.path.join(settings.UPLOADS_DIR, file_id)
|
||||
|
||||
# Stream upload in chunks with a hard size cap (avoids loading a multi-GB
|
||||
# WAV into RAM and bounds disk usage).
|
||||
with open(file_path, "wb") as f:
|
||||
content = await file.read()
|
||||
f.write(content)
|
||||
size = 0
|
||||
while True:
|
||||
chunk = await file.read(1024 * 1024)
|
||||
if not chunk:
|
||||
break
|
||||
size += len(chunk)
|
||||
if size > MAX_AUDIO_UPLOAD_BYTES:
|
||||
f.close()
|
||||
try:
|
||||
os.remove(file_path)
|
||||
except OSError:
|
||||
pass
|
||||
raise HTTPException(status_code=413, detail="File âm thanh quá lớn (giới hạn 1GB)")
|
||||
f.write(chunk)
|
||||
|
||||
# Save original filename as sidecar metadata
|
||||
import json
|
||||
@@ -90,15 +126,12 @@ async def upload_audio(file: UploadFile = File(...), current_user: Optional[dict
|
||||
|
||||
@router.post("/edit")
|
||||
async def edit_audio(req: EditRequest):
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, req.file_id)
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, req.file_id)
|
||||
|
||||
# Use uploaded file if it exists, or look in processed if it was already edited
|
||||
if not os.path.exists(upload_path) and not os.path.exists(processed_path):
|
||||
if not _resolve_storage_path(req.file_id):
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
|
||||
from app.tasks.worker import edit_audio_task
|
||||
task = edit_audio_task.delay(req.dict())
|
||||
task = edit_audio_task.delay(req.model_dump())
|
||||
|
||||
return {
|
||||
"task_id": task.id
|
||||
@@ -106,15 +139,10 @@ async def edit_audio(req: EditRequest):
|
||||
|
||||
@router.get("/download/{file_id}")
|
||||
async def download_audio(file_id: str):
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, file_id)
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, file_id)
|
||||
|
||||
if os.path.exists(processed_path):
|
||||
return FileResponse(processed_path, media_type="audio/wav", filename=file_id)
|
||||
elif os.path.exists(upload_path):
|
||||
return FileResponse(upload_path, media_type="audio/wav", filename=file_id)
|
||||
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
path = _resolve_storage_path(file_id)
|
||||
if not path:
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
return FileResponse(path, media_type="audio/wav", filename=os.path.basename(path))
|
||||
|
||||
@router.get("/waveform/{file_id}")
|
||||
async def get_waveform(file_id: str, num_peaks: int = Query(default=800, ge=50, le=4000)):
|
||||
@@ -122,14 +150,8 @@ async def get_waveform(file_id: str, num_peaks: int = Query(default=800, ge=50,
|
||||
API endpoint vẽ Peak Waveform đồng bộ (Week 2).
|
||||
Trả về dữ liệu peak waveform cho hiển thị đồ thị sóng âm trên Frontend.
|
||||
"""
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, file_id)
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, file_id)
|
||||
|
||||
if os.path.exists(processed_path):
|
||||
file_path = processed_path
|
||||
elif os.path.exists(upload_path):
|
||||
file_path = upload_path
|
||||
else:
|
||||
file_path = _resolve_storage_path(file_id)
|
||||
if not file_path:
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
|
||||
from app.core.dsp_utils import generate_peak_waveform
|
||||
@@ -140,14 +162,8 @@ async def get_waveform_rms(file_id: str, num_points: int = Query(default=800, ge
|
||||
"""
|
||||
API endpoint vẽ RMS Waveform (mượt hơn peak).
|
||||
"""
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, file_id)
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, file_id)
|
||||
|
||||
if os.path.exists(processed_path):
|
||||
file_path = processed_path
|
||||
elif os.path.exists(upload_path):
|
||||
file_path = upload_path
|
||||
else:
|
||||
file_path = _resolve_storage_path(file_id)
|
||||
if not file_path:
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
|
||||
from app.core.dsp_utils import generate_rms_waveform
|
||||
@@ -159,26 +175,20 @@ async def analyze_audio_with_ai(req: AIAnalysisRequest):
|
||||
API endpoint phân tích cấu trúc khuôn nhạc bằng AI (Week 4).
|
||||
Gọi OpenAI Compatible API (DeepSeek/Ollama) để phân đoạn bố cục.
|
||||
"""
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, req.file_id)
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, req.file_id)
|
||||
|
||||
if os.path.exists(processed_path):
|
||||
file_path = processed_path
|
||||
elif os.path.exists(upload_path):
|
||||
file_path = upload_path
|
||||
else:
|
||||
file_path = _resolve_storage_path(req.file_id)
|
||||
if not file_path:
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
|
||||
from app.tasks.worker import analyze_ai_task
|
||||
task = analyze_ai_task.delay(
|
||||
file_id=req.file_id,
|
||||
file_id=_safe_file_id(req.file_id),
|
||||
api_base_url=req.api_base_url,
|
||||
model=req.model
|
||||
)
|
||||
|
||||
return {
|
||||
"task_id": task.id,
|
||||
"file_id": req.file_id
|
||||
"file_id": _safe_file_id(req.file_id)
|
||||
}
|
||||
|
||||
@router.post("/export")
|
||||
@@ -186,19 +196,13 @@ async def export_audio(req: ExportRequest):
|
||||
"""
|
||||
API endpoint xuất tệp âm thanh sang nhiều định dạng (WAV/MP3/OGG).
|
||||
"""
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, req.file_id)
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, req.file_id)
|
||||
|
||||
if os.path.exists(processed_path):
|
||||
source_path = processed_path
|
||||
elif os.path.exists(upload_path):
|
||||
source_path = upload_path
|
||||
else:
|
||||
source_path = _resolve_storage_path(req.file_id)
|
||||
if not source_path:
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
|
||||
from app.tasks.worker import export_audio_task
|
||||
task = export_audio_task.delay(
|
||||
file_id=req.file_id,
|
||||
file_id=_safe_file_id(req.file_id),
|
||||
format=req.format,
|
||||
sample_rate=req.sample_rate,
|
||||
bit_depth=req.bit_depth
|
||||
@@ -206,29 +210,24 @@ async def export_audio(req: ExportRequest):
|
||||
|
||||
return {
|
||||
"task_id": task.id,
|
||||
"file_id": req.file_id
|
||||
"file_id": _safe_file_id(req.file_id)
|
||||
}
|
||||
|
||||
@router.post("/ai-scan")
|
||||
async def ai_scan_audio(req: AIScanRequest):
|
||||
async def ai_scan_audio(req: AIScanRequest, current_user: Optional[dict] = Depends(get_optional_user)):
|
||||
"""
|
||||
17_AI_SCAN.md Feature 1: AI Loop Scan & Automated Marker Labeling.
|
||||
Uses AIDSPEngine to find optimal recurring loop region with zero-crossing alignment.
|
||||
"""
|
||||
if current_user:
|
||||
enforce_password_changed(current_user)
|
||||
from app.core.ai_dsp_engine import AIDSPEngine
|
||||
import soundfile as sf
|
||||
import numpy as np
|
||||
|
||||
file_path = None
|
||||
if req.file_id:
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, req.file_id)
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, req.file_id)
|
||||
if os.path.exists(processed_path):
|
||||
file_path = processed_path
|
||||
elif os.path.exists(upload_path):
|
||||
file_path = upload_path
|
||||
file_path = _resolve_storage_path(req.file_id) if req.file_id else ""
|
||||
|
||||
if file_path and os.path.exists(file_path):
|
||||
if file_path:
|
||||
data, sr = sf.read(file_path)
|
||||
if data.ndim > 1:
|
||||
data = data.T
|
||||
@@ -252,6 +251,8 @@ async def ai_cut_audio(req: AICutRequest, current_user: Optional[dict] = Depends
|
||||
Executes raw binary sample slice at exact zero-crossing coordinates.
|
||||
"""
|
||||
user_id = current_user["user_id"] if current_user else "anonymous"
|
||||
if current_user:
|
||||
enforce_password_changed(current_user)
|
||||
from app.core.ai_dsp_engine import AIDSPEngine
|
||||
import soundfile as sf
|
||||
import numpy as np
|
||||
@@ -259,16 +260,9 @@ async def ai_cut_audio(req: AICutRequest, current_user: Optional[dict] = Depends
|
||||
output_file_id = f"user_{user_id}_ai_cut_{uuid.uuid4().hex[:8]}.wav"
|
||||
out_path = os.path.join(settings.PROCESSED_DIR, output_file_id)
|
||||
|
||||
file_path = None
|
||||
if req.file_id:
|
||||
upload_path = os.path.join(settings.UPLOADS_DIR, req.file_id)
|
||||
processed_path = os.path.join(settings.PROCESSED_DIR, req.file_id)
|
||||
if os.path.exists(processed_path):
|
||||
file_path = processed_path
|
||||
elif os.path.exists(upload_path):
|
||||
file_path = upload_path
|
||||
file_path = _resolve_storage_path(req.file_id) if req.file_id else ""
|
||||
|
||||
if file_path and os.path.exists(file_path):
|
||||
if file_path:
|
||||
data, sr = sf.read(file_path)
|
||||
if data.ndim > 1:
|
||||
data = data.T
|
||||
@@ -295,6 +289,8 @@ async def run_python_dsp_tool(req: PythonToolRequest, current_user: Optional[dic
|
||||
Handles normalize peak, invert phase, swap channels, zero-crossing align, and synth wave generation.
|
||||
"""
|
||||
user_id = current_user["user_id"] if current_user else "anonymous"
|
||||
if current_user:
|
||||
enforce_password_changed(current_user)
|
||||
from app.core.python_tools_engine import PythonToolsEngine
|
||||
from app.core.ai_dsp_engine import AIDSPEngine
|
||||
import soundfile as sf
|
||||
|
||||
+79
-14
@@ -1,10 +1,15 @@
|
||||
import uuid
|
||||
import time
|
||||
from fastapi import APIRouter, HTTPException, Header, Depends
|
||||
import threading
|
||||
from fastapi import APIRouter, HTTPException, Header, Depends, Request, Response
|
||||
from fastapi.responses import JSONResponse
|
||||
from pydantic import BaseModel, EmailStr
|
||||
from typing import Optional
|
||||
from app.models.user import get_db_connection
|
||||
from app.core.auth import hash_password, verify_password, create_token, decode_token, seed_admin
|
||||
from app.core.auth import (
|
||||
hash_password, verify_password, create_token, decode_token, seed_admin,
|
||||
COOKIE_NAME, X_AUTH_HEADER,
|
||||
)
|
||||
|
||||
router = APIRouter()
|
||||
|
||||
@@ -21,10 +26,49 @@ class ChangePasswordRequest(BaseModel):
|
||||
old_password: str
|
||||
new_password: str
|
||||
|
||||
def get_current_user(authorization: Optional[str] = Header(None)):
|
||||
if not authorization or not authorization.startswith("Bearer "):
|
||||
# ── Brute-force guard: in-memory per-IP failed-login limiter ──
|
||||
_LOGIN_FAILURES = {} # ip -> [timestamps]
|
||||
_LOGIN_LOCK = threading.Lock()
|
||||
MAX_LOGIN_ATTEMPTS = 10
|
||||
LOGIN_WINDOW_SEC = 900 # 15 min
|
||||
LOGIN_BLOCK_SEC = 900
|
||||
|
||||
def _check_login_ratelimit(ip: str):
|
||||
now = time.time()
|
||||
with _LOGIN_LOCK:
|
||||
stamps = [t for t in _LOGIN_FAILURES.get(ip, []) if now - t < LOGIN_WINDOW_SEC]
|
||||
if len(stamps) >= MAX_LOGIN_ATTEMPTS:
|
||||
raise HTTPException(status_code=429, detail="Quá nhiều lần đăng nhập thất bại. Vui lòng thử lại sau 15 phút.")
|
||||
_LOGIN_FAILURES[ip] = stamps
|
||||
|
||||
def _record_login_failure(ip: str):
|
||||
now = time.time()
|
||||
with _LOGIN_LOCK:
|
||||
stamps = _LOGIN_FAILURES.setdefault(ip, [])
|
||||
stamps.append(now)
|
||||
_LOGIN_FAILURES[ip] = [t for t in stamps if now - t < LOGIN_WINDOW_SEC]
|
||||
|
||||
def _record_login_success(ip: str):
|
||||
with _LOGIN_LOCK:
|
||||
_LOGIN_FAILURES.pop(ip, None)
|
||||
|
||||
def _set_auth_cookie(response: Response, token: str):
|
||||
response.set_cookie(
|
||||
COOKIE_NAME, token,
|
||||
max_age=7 * 24 * 3600, httponly=True, samesite="lax",
|
||||
# path="/" (default); secure flag set by proxy when behind TLS
|
||||
)
|
||||
|
||||
def get_current_user(request: Request, authorization: Optional[str] = Header(None), x_auth_token: Optional[str] = Header(None)):
|
||||
token = None
|
||||
if authorization and authorization.startswith("Bearer "):
|
||||
token = authorization.split(" ")[1]
|
||||
elif x_auth_token:
|
||||
token = x_auth_token
|
||||
elif request.cookies.get(COOKIE_NAME):
|
||||
token = request.cookies.get(COOKIE_NAME)
|
||||
if not token:
|
||||
raise HTTPException(status_code=401, detail="Thiếu Token xác thực hoặc Token không hợp lệ")
|
||||
token = authorization.split(" ")[1]
|
||||
payload = decode_token(token)
|
||||
if not payload:
|
||||
raise HTTPException(status_code=401, detail="Token đã hết hạn hoặc không hợp lệ")
|
||||
@@ -39,7 +83,10 @@ def enforce_password_changed(user: dict):
|
||||
)
|
||||
|
||||
@router.post("/login")
|
||||
async def login(req: LoginRequest):
|
||||
async def login(req: LoginRequest, request: Request):
|
||||
client_ip = request.client.host if request.client else "unknown"
|
||||
_check_login_ratelimit(client_ip)
|
||||
|
||||
conn = get_db_connection()
|
||||
cursor = conn.cursor()
|
||||
|
||||
@@ -65,14 +112,17 @@ async def login(req: LoginRequest):
|
||||
conn.close()
|
||||
|
||||
if not user or not user["is_active"]:
|
||||
_record_login_failure(client_ip)
|
||||
raise HTTPException(status_code=400, detail="Tài khoản hoặc mật khẩu không chính xác")
|
||||
|
||||
if not verify_password(password, user["hashed_password"]):
|
||||
_record_login_failure(client_ip)
|
||||
raise HTTPException(status_code=400, detail="Tài khoản hoặc mật khẩu không chính xác")
|
||||
|
||||
token = create_token(user["id"], user["username"], user["role"], user["must_change_password"])
|
||||
|
||||
return {
|
||||
_record_login_success(client_ip)
|
||||
|
||||
resp = JSONResponse({
|
||||
"access_token": token,
|
||||
"user": {
|
||||
"id": user["id"],
|
||||
@@ -81,13 +131,24 @@ async def login(req: LoginRequest):
|
||||
"role": user["role"],
|
||||
"must_change_password": bool(user["must_change_password"])
|
||||
}
|
||||
}
|
||||
})
|
||||
_set_auth_cookie(resp, token)
|
||||
return resp
|
||||
|
||||
def _validate_password_strength(password: str):
|
||||
"""Minimal strength policy: >= 8 chars and not trivially common."""
|
||||
if len(password) < 8:
|
||||
raise HTTPException(status_code=400, detail="Mật khẩu phải có ít nhất 8 ký tự")
|
||||
lowered = password.lower()
|
||||
if lowered in ("admin123", "password", "12345678", "123456789", "qwerty123"):
|
||||
raise HTTPException(status_code=400, detail="Mật khẩu quá dễ đoán, vui lòng chọn mật khẩu khác")
|
||||
|
||||
@router.post("/register")
|
||||
async def register(req: RegisterRequest):
|
||||
async def register(req: RegisterRequest, request: Request):
|
||||
username = req.username.strip()
|
||||
email = req.email.strip()
|
||||
password = req.password.strip()
|
||||
_validate_password_strength(password)
|
||||
|
||||
conn = get_db_connection()
|
||||
cursor = conn.cursor()
|
||||
@@ -115,7 +176,7 @@ async def register(req: RegisterRequest):
|
||||
conn.close()
|
||||
|
||||
token = create_token(user_id, username, "standard", False)
|
||||
return {
|
||||
resp = JSONResponse({
|
||||
"access_token": token,
|
||||
"user": {
|
||||
"id": user_id,
|
||||
@@ -124,7 +185,9 @@ async def register(req: RegisterRequest):
|
||||
"role": "standard",
|
||||
"must_change_password": False
|
||||
}
|
||||
}
|
||||
})
|
||||
_set_auth_cookie(resp, token)
|
||||
return resp
|
||||
|
||||
@router.post("/change-password")
|
||||
async def change_password(req: ChangePasswordRequest, current_user: dict = Depends(get_current_user)):
|
||||
@@ -153,10 +216,12 @@ async def change_password(req: ChangePasswordRequest, current_user: dict = Depen
|
||||
conn.close()
|
||||
|
||||
new_token = create_token(updated_user["id"], updated_user["username"], updated_user["role"], False)
|
||||
return {
|
||||
resp = JSONResponse({
|
||||
"message": "Đổi mật khẩu thành công!",
|
||||
"access_token": new_token
|
||||
}
|
||||
})
|
||||
_set_auth_cookie(resp, new_token)
|
||||
return resp
|
||||
|
||||
@router.get("/profile")
|
||||
async def get_profile(current_user: dict = Depends(get_current_user)):
|
||||
|
||||
+6
-4
@@ -2,9 +2,11 @@ import os
|
||||
import platform
|
||||
from typing import List, Optional
|
||||
|
||||
from fastapi import APIRouter, HTTPException, Query
|
||||
from fastapi import APIRouter, Depends, HTTPException, Query
|
||||
from fastapi.responses import FileResponse
|
||||
|
||||
from app.api.v1.auth import get_current_user
|
||||
|
||||
router = APIRouter()
|
||||
|
||||
MEDIA_EXTS = {
|
||||
@@ -39,7 +41,7 @@ PSEUDO_FS_TYPES = {
|
||||
|
||||
|
||||
@router.get("/computer")
|
||||
async def list_computer_roots():
|
||||
async def list_computer_roots(current_user: dict = Depends(get_current_user)):
|
||||
"""Liệt kê các ổ đĩa / mount point thật của máy (My Computer)."""
|
||||
system = platform.system()
|
||||
roots = []
|
||||
@@ -97,7 +99,7 @@ async def list_computer_roots():
|
||||
|
||||
|
||||
@router.get("/browse")
|
||||
async def browse_directory(path: str = Query(...)):
|
||||
async def browse_directory(path: str = Query(...), current_user: dict = Depends(get_current_user)):
|
||||
"""Liệt kê nội dung một thư mục trên máy: thư mục con + file audio/MIDI."""
|
||||
resolved = _safe_path(path)
|
||||
if not os.path.isdir(resolved):
|
||||
@@ -146,7 +148,7 @@ async def browse_directory(path: str = Query(...)):
|
||||
|
||||
|
||||
@router.get("/file")
|
||||
async def serve_local_file(path: str = Query(...)):
|
||||
async def serve_local_file(path: str = Query(...), current_user: dict = Depends(get_current_user)):
|
||||
"""Phục vụ file audio/MIDI cục bộ để preview."""
|
||||
resolved = _safe_path(path)
|
||||
if not os.path.isfile(resolved):
|
||||
|
||||
@@ -54,7 +54,7 @@ async def mix_multitrack_session(req: MultitrackSessionRequest):
|
||||
|
||||
# Gửi task xuống Celery Worker
|
||||
from app.tasks.worker import mix_multitrack_task
|
||||
task = mix_multitrack_task.delay(req.dict())
|
||||
task = mix_multitrack_task.delay(req.model_dump())
|
||||
|
||||
return {
|
||||
"task_id": task.id,
|
||||
@@ -69,7 +69,7 @@ async def process_session(req: MultitrackSessionRequest):
|
||||
Xử lý từng clip, sau đó hòa âm tất cả tracks lại với nhau.
|
||||
"""
|
||||
from app.tasks.worker import process_multitrack_session_task
|
||||
task = process_multitrack_session_task.delay(req.dict())
|
||||
task = process_multitrack_session_task.delay(req.model_dump())
|
||||
|
||||
return {
|
||||
"task_id": task.id,
|
||||
|
||||
+21
-4
@@ -9,7 +9,7 @@ from app.core.render_engine import PythonRenderEngine
|
||||
from app.core.soundfont_inspector import SoundFontInspector
|
||||
from app.core.soundfont_converter import SoundFontConverter
|
||||
from app.core.soundfont_scanner import SoundFontAutoScanner
|
||||
from app.api.v1.auth import get_current_user
|
||||
from app.api.v1.auth import get_current_user, enforce_password_changed
|
||||
|
||||
router = APIRouter()
|
||||
|
||||
@@ -79,11 +79,23 @@ async def upload_soundfont(
|
||||
background_tasks: BackgroundTasks = None,
|
||||
current_user: dict = Depends(get_current_user)
|
||||
):
|
||||
enforce_password_changed(current_user)
|
||||
if not (file.filename and (file.filename.endswith(".sf2") or file.filename.endswith(".sf3"))):
|
||||
raise HTTPException(status_code=400, detail="Only .sf2 / .sf3 files are allowed")
|
||||
|
||||
contents = await file.read()
|
||||
if not PluginManager.validate_sf2_header(contents):
|
||||
# Stream upload in chunks with a hard size cap (SGM-class fonts can exceed
|
||||
# 500MB; reading the whole body into RAM would OOM the server).
|
||||
MAX_SF_UPLOAD_BYTES = 2 * 1024 * 1024 * 1024 # 2 GB
|
||||
contents = bytearray()
|
||||
while True:
|
||||
chunk = await file.read(1024 * 1024)
|
||||
if not chunk:
|
||||
break
|
||||
contents.extend(chunk)
|
||||
if len(contents) > MAX_SF_UPLOAD_BYTES:
|
||||
raise HTTPException(status_code=413, detail="SoundFont quá lớn (giới hạn 2GB)")
|
||||
|
||||
if not PluginManager.validate_sf2_header(bytes(contents[:4096])):
|
||||
raise HTTPException(status_code=400, detail="Invalid SoundFont file: missing RIFF/sfbk header")
|
||||
|
||||
file_ext = os.path.splitext(file.filename)[1]
|
||||
@@ -178,8 +190,13 @@ async def render_project(
|
||||
req: RenderRequest,
|
||||
current_user: dict = Depends(get_current_user)
|
||||
):
|
||||
enforce_password_changed(current_user)
|
||||
engine = PythonRenderEngine()
|
||||
output_path = os.path.join(settings.PROCESSED_DIR, req.output_filename or "render_output.wav")
|
||||
# Prevent path traversal: strip any directory components and force .wav.
|
||||
safe_name = os.path.basename((req.output_filename or "render_output.wav").replace("\\", "/"))
|
||||
if not safe_name.lower().endswith(".wav"):
|
||||
safe_name += ".wav"
|
||||
output_path = os.path.join(settings.PROCESSED_DIR, safe_name)
|
||||
try:
|
||||
result_path = engine.render_project(req.project_json, output_path)
|
||||
return {"url": f"/static/audio/processed/{os.path.basename(result_path)}", "path": result_path}
|
||||
|
||||
+31
-9
@@ -18,6 +18,11 @@ def upgrade_project_json_if_needed(project_data: dict) -> dict:
|
||||
return project_data
|
||||
|
||||
tracks = project_data.get("tracks", [])
|
||||
# Legacy format stores item start times in SECONDS; convert using the real
|
||||
# seconds-per-bar (old code hardcoded /4.0 which shifted every item's
|
||||
# position for any tempo other than the one where 1 bar = 4s).
|
||||
bpm_val = float(project_data.get("bpm", 120.0) or 120.0)
|
||||
seconds_per_bar = (60.0 / bpm_val) * 4
|
||||
upgraded_tracks = []
|
||||
for t in tracks:
|
||||
track_id = str(t.get("id", ""))
|
||||
@@ -33,8 +38,8 @@ def upgrade_project_json_if_needed(project_data: dict) -> dict:
|
||||
"id": c.get("id"),
|
||||
"name": c.get("name", "Audio Clip"),
|
||||
"type": "AUDIO_ITEM",
|
||||
"start_bar": c.get("startTime", 0.0) / 4.0,
|
||||
"duration_bars": 4.0,
|
||||
"start_bar": round(c.get("startTime", 0.0) / seconds_per_bar, 6),
|
||||
"duration_bars": round((c.get("duration", 4.0) if c.get("duration") else 4.0) / seconds_per_bar, 6),
|
||||
"clip_start_offset_bars": 0.0,
|
||||
"source_data": {
|
||||
"audio_file_url": f"/static/audio/uploads/{t.get('serverFileId')}" if t.get("serverFileId") else "",
|
||||
@@ -49,11 +54,11 @@ def upgrade_project_json_if_needed(project_data: dict) -> dict:
|
||||
"id": m.get("id"),
|
||||
"name": m.get("name", "MIDI Item"),
|
||||
"type": "MIDI_ITEM",
|
||||
"start_bar": m.get("startTime", 0.0) / 4.0,
|
||||
"duration_bars": m.get("duration", 4.0),
|
||||
"start_bar": round(m.get("startTime", 0.0) / seconds_per_bar, 6),
|
||||
"duration_bars": round((m.get("duration", 4.0) or 4.0) / seconds_per_bar, 6),
|
||||
"clip_start_offset_bars": 0.0,
|
||||
"source_data": {
|
||||
"total_buffer_bars": m.get("duration", 8.0),
|
||||
"total_buffer_bars": round((m.get("duration", 8.0) or 8.0) / seconds_per_bar, 6),
|
||||
"notes": m.get("notes", [])
|
||||
}
|
||||
})
|
||||
@@ -283,13 +288,30 @@ async def update_cloud_project(project_id: str, req: SaveProjectRequest, current
|
||||
conn = get_db_connection()
|
||||
cursor = conn.cursor()
|
||||
|
||||
cursor.execute("SELECT id FROM projects WHERE id = ? AND user_id = ? AND is_temp = 0", (project_id, user_id))
|
||||
exists = cursor.fetchone()
|
||||
if not exists:
|
||||
cursor.execute("SELECT id, size_bytes FROM projects WHERE id = ? AND user_id = ? AND is_temp = 0", (project_id, user_id))
|
||||
existing = cursor.fetchone()
|
||||
if not existing:
|
||||
conn.close()
|
||||
raise HTTPException(status_code=404, detail="Không tìm thấy dự án để cập nhật")
|
||||
|
||||
|
||||
new_size_bytes = len(validated_data_json.encode("utf-8"))
|
||||
|
||||
# Enforce storage quota (same rule as save_cloud_project — previously
|
||||
# update bypassed the quota entirely).
|
||||
cursor.execute("SELECT storage_limit_mb FROM user_quotas WHERE user_id = ?", (user_id,))
|
||||
quota_row = cursor.fetchone()
|
||||
storage_limit_mb = quota_row["storage_limit_mb"] if quota_row else 500
|
||||
cursor.execute("SELECT SUM(size_bytes) as total_used FROM projects WHERE user_id = ? AND is_temp = 0", (user_id,))
|
||||
used_row = cursor.fetchone()
|
||||
used_bytes = (used_row["total_used"] if used_row and used_row["total_used"] else 0) - (existing["size_bytes"] or 0)
|
||||
max_bytes = storage_limit_mb * 1024 * 1024
|
||||
if used_bytes + new_size_bytes > max_bytes:
|
||||
conn.close()
|
||||
raise HTTPException(
|
||||
status_code=400,
|
||||
detail=f"Dung lượng dự án vượt quá hạn mức Quota ({storage_limit_mb}MB). Vui lòng dọn dẹp hoặc nâng cấp tài khoản."
|
||||
)
|
||||
|
||||
now = time.time()
|
||||
|
||||
cursor.execute("""
|
||||
|
||||
@@ -96,7 +96,7 @@ async def get_user_ai_config(authorization: Optional[str] = Header(None)):
|
||||
async def save_user_ai_config(req: SaveAIConfigRequest, authorization: Optional[str] = Header(None)):
|
||||
uid = _get_user_id(authorization)
|
||||
configs = _load_ai_configs()
|
||||
configs[uid] = [p.dict() for p in req.providers]
|
||||
configs[uid] = [p.model_dump() for p in req.providers]
|
||||
_save_all(ai_configs=configs)
|
||||
return {
|
||||
"success": True,
|
||||
|
||||
+30
-1
@@ -10,7 +10,36 @@ from typing import Optional, Dict, Any
|
||||
from app.models.user import get_db_connection
|
||||
from app.config import settings
|
||||
|
||||
SECRET_KEY = os.getenv("SECRET_KEY", "sonicforge_secret_key_super_secure_2026")
|
||||
COOKIE_NAME = "sf_token"
|
||||
X_AUTH_HEADER = "X-Auth-Token"
|
||||
|
||||
def _load_or_create_secret_key() -> str:
|
||||
"""Persistent random SECRET_KEY.
|
||||
|
||||
Priority: env SECRET_KEY > {STORAGE_DIR}/.secret_key (auto-generated on
|
||||
first run). Never falls back to a hardcoded value: a known secret lets
|
||||
anyone forge admin tokens.
|
||||
"""
|
||||
env_key = os.getenv("SECRET_KEY", "").strip()
|
||||
if env_key:
|
||||
return env_key
|
||||
key_file = os.path.join(settings.STORAGE_DIR, ".secret_key")
|
||||
try:
|
||||
os.makedirs(settings.STORAGE_DIR, exist_ok=True)
|
||||
if os.path.exists(key_file):
|
||||
with open(key_file, "r") as f:
|
||||
key = f.read().strip()
|
||||
if len(key) >= 32:
|
||||
return key
|
||||
key = secrets.token_hex(32)
|
||||
with open(key_file, "w") as f:
|
||||
f.write(key)
|
||||
return key
|
||||
except Exception:
|
||||
# Last resort: ephemeral random key (all tokens invalid on restart).
|
||||
return secrets.token_hex(32)
|
||||
|
||||
SECRET_KEY = _load_or_create_secret_key()
|
||||
|
||||
def hash_password(password: str, salt: Optional[str] = None) -> str:
|
||||
"""
|
||||
|
||||
+43
-21
@@ -1,4 +1,4 @@
|
||||
import os, logging
|
||||
import os, logging, math
|
||||
import numpy as np
|
||||
import soundfile as sf
|
||||
import scipy.signal as signal
|
||||
@@ -87,12 +87,18 @@ class PythonRenderEngine:
|
||||
return url_or_id
|
||||
return url_or_id
|
||||
|
||||
def render_session_container(self, session: dict, section_store: dict, bpm: float, time_sig_num: int, total_samples: int) -> np.ndarray:
|
||||
def render_session_container(self, session: dict, section_store: dict, bpm: float, time_sig_num: int, total_samples: int, _cache: dict = None) -> np.ndarray:
|
||||
session_buffer = np.zeros((2, total_samples), dtype=np.float32)
|
||||
|
||||
# Solo semantics: when any track is soloed, only soloed tracks sound.
|
||||
tracks = session.get("tracks", [])
|
||||
solo_ids = {t.get("id") for t in tracks if t.get("solo")}
|
||||
|
||||
_channel_counter = 0
|
||||
|
||||
for track in session.get("tracks", []):
|
||||
for track in tracks:
|
||||
if solo_ids and track.get("id") not in solo_ids:
|
||||
continue
|
||||
track_type = track.get("type", "AUDIO")
|
||||
track_buffer = np.zeros((2, total_samples), dtype=np.float32)
|
||||
|
||||
@@ -123,8 +129,17 @@ class PythonRenderEngine:
|
||||
try:
|
||||
audio_data, sr = sf.read(resolved_path, dtype='float32')
|
||||
if sr != self.sample_rate:
|
||||
# Resampling fallback if simple, otherwise skip
|
||||
pass
|
||||
# Proper resampling: previously a silent no-op that
|
||||
# played 48kHz audio at the wrong speed/pitch.
|
||||
from scipy.signal import resample_poly
|
||||
g = math.gcd(sr, self.sample_rate)
|
||||
audio_data = resample_poly(
|
||||
audio_data,
|
||||
up=self.sample_rate // g,
|
||||
down=sr // g,
|
||||
axis=-1,
|
||||
)
|
||||
sr = self.sample_rate
|
||||
|
||||
# Handle channel mapping (Mono/Stereo)
|
||||
if len(audio_data.shape) == 1:
|
||||
@@ -148,7 +163,7 @@ class PythonRenderEngine:
|
||||
if actual_len > 0:
|
||||
track_buffer[:, start_sample:write_end] += sliced_audio[:, :actual_len]
|
||||
except Exception as e:
|
||||
print(f"[RenderEngine] Error reading audio file {resolved_path}: {e}")
|
||||
logger.warning("[RenderEngine] Error reading audio file %s: %s", resolved_path, e)
|
||||
|
||||
elif item_type == "MIDI_ITEM":
|
||||
source_data = item.get("source_data", {})
|
||||
@@ -284,21 +299,27 @@ class PythonRenderEngine:
|
||||
actual_len = min(synth_buffer.shape[1], total_samples)
|
||||
track_buffer[:, :actual_len] += synth_buffer[:, :actual_len]
|
||||
except Exception as e:
|
||||
print(f"[RenderEngine] Error rendering MIDI: {e}")
|
||||
logger.warning("[RenderEngine] Error rendering MIDI: %s", e)
|
||||
|
||||
elif item_type == "SECTION_ITEM":
|
||||
source_data = item.get("source_data", {})
|
||||
sec_id = source_data.get("referenced_section_id", "")
|
||||
if sec_id and sec_id in section_store:
|
||||
# Render nested section recursively
|
||||
sec_container = section_store[sec_id]
|
||||
sec_buffer = self.render_session_container(
|
||||
session=sec_container,
|
||||
section_store=section_store,
|
||||
bpm=bpm,
|
||||
time_sig_num=time_sig_num,
|
||||
total_samples=total_samples
|
||||
)
|
||||
# Render nested section recursively, cached per section id
|
||||
# so repeated section instances don't re-render every time.
|
||||
cache = _cache if _cache is not None else {}
|
||||
if sec_id in cache:
|
||||
sec_buffer = cache[sec_id]
|
||||
else:
|
||||
sec_buffer = self.render_session_container(
|
||||
session=section_store[sec_id],
|
||||
section_store=section_store,
|
||||
bpm=bpm,
|
||||
time_sig_num=time_sig_num,
|
||||
total_samples=total_samples,
|
||||
_cache=cache,
|
||||
)
|
||||
cache[sec_id] = sec_buffer
|
||||
|
||||
# Apply non-destructive crop/slicing on section buffer
|
||||
if offset_sample < total_samples:
|
||||
@@ -327,7 +348,7 @@ class PythonRenderEngine:
|
||||
board = Pedalboard([Chorus(rate_hz=1.5, depth=0.25)])
|
||||
track_buffer = board(track_buffer, sample_rate=self.sample_rate)
|
||||
except Exception as e:
|
||||
print(f"[RenderEngine] Pedalboard Chorus failed: {e}")
|
||||
logger.warning("[RenderEngine] Pedalboard Chorus failed: %s", e)
|
||||
else:
|
||||
# Fallback chorus using simple LFO delay modulation in scipy/numpy
|
||||
try:
|
||||
@@ -341,14 +362,14 @@ class PythonRenderEngine:
|
||||
wet[ch, :] = track_buffer[ch, indices]
|
||||
track_buffer = dry + wet * 0.5
|
||||
except Exception as e:
|
||||
print(f"[RenderEngine] Fallback Chorus failed: {e}")
|
||||
logger.warning("[RenderEngine] Fallback Chorus failed: %s", e)
|
||||
elif fx_type == "reverb":
|
||||
if HAS_PEDALBOARD:
|
||||
try:
|
||||
board = Pedalboard([Reverb(room_size=0.5, wet_level=0.4, dry_level=0.6)])
|
||||
track_buffer = board(track_buffer, sample_rate=self.sample_rate)
|
||||
except Exception as e:
|
||||
print(f"[RenderEngine] Pedalboard Reverb failed: {e}")
|
||||
logger.warning("[RenderEngine] Pedalboard Reverb failed: %s", e)
|
||||
else:
|
||||
# Fallback reverb using exponentially decaying noise room impulse response
|
||||
try:
|
||||
@@ -368,7 +389,7 @@ class PythonRenderEngine:
|
||||
wet[ch, :] = conv
|
||||
track_buffer = dry + wet * 0.4
|
||||
except Exception as e:
|
||||
print(f"[RenderEngine] Fallback Reverb failed: {e}")
|
||||
logger.warning("[RenderEngine] Fallback Reverb failed: %s", e)
|
||||
|
||||
# Process track volume
|
||||
if HAS_PEDALBOARD:
|
||||
@@ -410,7 +431,8 @@ class PythonRenderEngine:
|
||||
section_store=section_store,
|
||||
bpm=bpm,
|
||||
time_sig_num=time_sig_num,
|
||||
total_samples=total_samples
|
||||
total_samples=total_samples,
|
||||
_cache={},
|
||||
)
|
||||
|
||||
# Normalization to prevent clipping
|
||||
|
||||
@@ -280,31 +280,37 @@ class SoundFontConverter:
|
||||
@staticmethod
|
||||
def _sf3_plays_audio(path: str) -> bool:
|
||||
"""Verify a SoundFont actually loads and renders audible audio (guards
|
||||
against shipping malformed SF3 files that silently play nothing)."""
|
||||
against shipping malformed SF3 files that silently play nothing).
|
||||
|
||||
Uses the low-level CFFI binding (new_fluid_synth / write_float) — the
|
||||
high-level Synth() class does not exist in this binding, so it is never
|
||||
used here.
|
||||
"""
|
||||
if not os.path.exists(path):
|
||||
return False
|
||||
try:
|
||||
import fluidsynth
|
||||
import fluidsynth as _fs
|
||||
import numpy as np
|
||||
fl = fluidsynth.Synth()
|
||||
_settings = _fs.new_fluid_settings()
|
||||
_fl = _fs.new_fluid_synth(_settings)
|
||||
try:
|
||||
h = fl.sfload(path)
|
||||
h = _fs.fluid_synth_sfload(_fl, path.encode("utf-8"), 1)
|
||||
if h < 0:
|
||||
return False
|
||||
fl.program_select(0, h, 0, 0)
|
||||
fl.noteon(0, 60, 100)
|
||||
_fs.fluid_synth_program_select(_fl, 0, h, 0, 0)
|
||||
_fs.fluid_synth_noteon(_fl, 0, 60, 100)
|
||||
frames = 8820 # 0.2s
|
||||
buf = np.zeros(frames * 2, dtype=np.float32)
|
||||
fluidsynth._fl.fluid_synth_write_float(
|
||||
fl.synth, frames, buf.ctypes.data, 0, 1,
|
||||
_fs.fluid_synth_write_float(
|
||||
_fl, frames, buf.ctypes.data, 0, 1,
|
||||
buf.ctypes.data + frames * 4, 0, 1
|
||||
)
|
||||
fl.noteoff(0, 60)
|
||||
_fs.fluid_synth_noteoff(_fl, 0, 60)
|
||||
rms = float(np.sqrt(np.mean(buf ** 2)))
|
||||
return rms > 1e-4
|
||||
finally:
|
||||
try:
|
||||
fl.delete()
|
||||
_fs.delete_fluid_synth(_fl)
|
||||
except Exception:
|
||||
pass
|
||||
except Exception:
|
||||
|
||||
+59
-39
@@ -2,7 +2,7 @@
|
||||
import os
|
||||
import numpy as np
|
||||
import functools
|
||||
from ctypes import c_int, c_char_p, c_void_p
|
||||
from ctypes import c_char_p
|
||||
|
||||
def midi_note_to_freq(note_number: int) -> float:
|
||||
return 440.0 * (2.0 ** ((note_number - 69) / 12.0))
|
||||
@@ -110,7 +110,12 @@ def get_plugin_manager(vst_dir="/opt/daw_engine/vst3", sf_dir="/opt/daw_engine/s
|
||||
return _PLUGIN_MANAGER_INSTANCE
|
||||
|
||||
def load_soundfont_cached(path: str):
|
||||
"""Return a cached FluidSynth instance for path, incrementing refcount."""
|
||||
"""Return a cached low-level FluidSynth instance for path, incrementing refcount.
|
||||
|
||||
Uses the CFFI binding API (new_fluid_synth / fluid_synth_sfload) — the same
|
||||
API render_engine relies on. The high-level `FluidSynth()`/`Synth()` classes
|
||||
do not exist in this binding, so they are never used here.
|
||||
"""
|
||||
global _FLUID_CACHE
|
||||
if not HAS_PYFLUIDSYNTH:
|
||||
return None
|
||||
@@ -119,10 +124,15 @@ def load_soundfont_cached(path: str):
|
||||
_FLUID_CACHE[path] = (fl, ref + 1)
|
||||
return fl
|
||||
try:
|
||||
import fluidsynth
|
||||
fl = fluidsynth.FluidSynth(sample_rate=44100, gain=0.5)
|
||||
font_id = fl.sfload(path)
|
||||
fl.program_select(0, font_id, 0, 0)
|
||||
import fluidsynth as _fs
|
||||
_settings = _fs.new_fluid_settings()
|
||||
_fs.fluid_settings_setnum(_settings, b'synth.sample-rate', 44100.0)
|
||||
fl = _fs.new_fluid_synth(_settings)
|
||||
font_id = _fs.fluid_synth_sfload(fl, path.encode("utf-8"), 1)
|
||||
if font_id < 0:
|
||||
_fs.delete_fluid_synth(fl)
|
||||
return None
|
||||
_fs.fluid_synth_program_select(fl, 0, font_id, 0, 0)
|
||||
_FLUID_CACHE[path] = (fl, 1)
|
||||
return fl
|
||||
except Exception:
|
||||
@@ -136,7 +146,8 @@ def release_soundfont(path: str):
|
||||
fl, ref = _FLUID_CACHE[path]
|
||||
if ref <= 1:
|
||||
try:
|
||||
fl.delete()
|
||||
import fluidsynth as _fs
|
||||
_fs.delete_fluid_synth(fl)
|
||||
except Exception:
|
||||
pass
|
||||
del _FLUID_CACHE[path]
|
||||
@@ -245,38 +256,47 @@ class PluginManager:
|
||||
if base == sf_id or base == sf_id.replace("sf_", ""):
|
||||
path = os.path.join(d, f)
|
||||
try:
|
||||
import fluidsynth
|
||||
fl = fluidsynth.Synth()
|
||||
fid = fl.sfload(path)
|
||||
if fid < 0:
|
||||
fl.delete()
|
||||
continue
|
||||
presets = []
|
||||
_fl = fluidsynth._fl
|
||||
_fl.fluid_synth_get_sfont_by_id.restype = c_void_p
|
||||
_fl.fluid_preset_get_name.restype = c_char_p
|
||||
_fl.fluid_sfont_get_preset.restype = c_void_p
|
||||
sfont_ptr = _fl.fluid_synth_get_sfont_by_id(c_void_p(fl.synth), c_int(fid))
|
||||
if sfont_ptr:
|
||||
for bank in range(0, 2):
|
||||
for prog_num in range(0, 128):
|
||||
try:
|
||||
preset = fluidsynth.fluid_sfont_get_preset(sfont_ptr, c_int(bank), c_int(prog_num))
|
||||
except Exception:
|
||||
break
|
||||
if preset:
|
||||
name_ptr = fluidsynth.fluid_preset_get_name(preset)
|
||||
if name_ptr:
|
||||
name_val = c_char_p(name_ptr).value
|
||||
if name_val:
|
||||
presets.append({
|
||||
"bank": bank,
|
||||
"program": prog_num,
|
||||
"name": name_val.decode("utf-8", errors="replace")
|
||||
})
|
||||
fl.delete()
|
||||
_SF_INSTRUMENTS_CACHE[sf_id] = presets[:256]
|
||||
return presets[:256]
|
||||
import fluidsynth as _fs
|
||||
# Low-level CFFI API (same as render_engine); never use
|
||||
# the high-level Synth() class that this binding lacks.
|
||||
_settings = _fs.new_fluid_settings()
|
||||
_synth = _fs.new_fluid_synth(_settings)
|
||||
try:
|
||||
fid = _fs.fluid_synth_sfload(_synth, path.encode("utf-8"), 1)
|
||||
if fid < 0:
|
||||
continue
|
||||
sfont = _fs.fluid_synth_get_sfont_by_id(_synth, fid)
|
||||
presets = []
|
||||
if sfont:
|
||||
for bank in range(0, 2):
|
||||
for prog_num in range(0, 128):
|
||||
try:
|
||||
preset = _fs.fluid_sfont_get_preset(sfont, bank, prog_num)
|
||||
except Exception:
|
||||
break
|
||||
if preset:
|
||||
try:
|
||||
name_ptr = _fs.fluid_preset_get_name(preset)
|
||||
if name_ptr:
|
||||
if hasattr(_fs, "ffi"):
|
||||
raw = _fs.ffi.string(name_ptr)
|
||||
else:
|
||||
raw = c_char_p(name_ptr).value
|
||||
if raw:
|
||||
presets.append({
|
||||
"bank": bank,
|
||||
"program": prog_num,
|
||||
"name": raw.decode("utf-8", errors="replace")
|
||||
})
|
||||
except Exception:
|
||||
continue
|
||||
_SF_INSTRUMENTS_CACHE[sf_id] = presets[:256]
|
||||
return presets[:256]
|
||||
finally:
|
||||
try:
|
||||
_fs.delete_fluid_synth(_synth)
|
||||
except Exception:
|
||||
pass
|
||||
except Exception:
|
||||
import traceback; traceback.print_exc()
|
||||
_SF_INSTRUMENTS_CACHE[sf_id] = []
|
||||
|
||||
+24
-22
@@ -1,8 +1,11 @@
|
||||
import os
|
||||
from contextlib import asynccontextmanager
|
||||
|
||||
from fastapi import FastAPI
|
||||
from fastapi.responses import HTMLResponse
|
||||
from fastapi.responses import HTMLResponse, FileResponse
|
||||
from fastapi.staticfiles import StaticFiles
|
||||
from fastapi.middleware.cors import CORSMiddleware
|
||||
from fastapi.middleware.gzip import GZipMiddleware
|
||||
from app.config import settings
|
||||
from app.api.v1.audio import router as audio_router
|
||||
from app.api.v1.tasks import router as tasks_router
|
||||
@@ -22,16 +25,32 @@ from app.core.soundfont_scanner import SoundFontAutoScanner
|
||||
os.makedirs(settings.UPLOADS_DIR, exist_ok=True)
|
||||
os.makedirs(settings.PROCESSED_DIR, exist_ok=True)
|
||||
|
||||
app = FastAPI(title="SonicForge API Engine")
|
||||
_SF_SCANNER_STOP = None
|
||||
|
||||
from fastapi.middleware.gzip import GZipMiddleware
|
||||
|
||||
@asynccontextmanager
|
||||
async def lifespan(app: FastAPI):
|
||||
# Startup
|
||||
seed_admin()
|
||||
scanner = SoundFontAutoScanner()
|
||||
global _SF_SCANNER_STOP
|
||||
_SF_SCANNER_STOP = scanner.start_background(interval=30)
|
||||
yield
|
||||
# Shutdown
|
||||
if _SF_SCANNER_STOP is not None:
|
||||
_SF_SCANNER_STOP.set()
|
||||
|
||||
|
||||
app = FastAPI(title="SonicForge API Engine", lifespan=lifespan)
|
||||
|
||||
app.add_middleware(GZipMiddleware, minimum_size=500)
|
||||
|
||||
# Auth is token/cookie based (no cookies required for CORS), so credentials are
|
||||
# disabled — "*" + allow_credentials=True is rejected by browsers anyway.
|
||||
app.add_middleware(
|
||||
CORSMiddleware,
|
||||
allow_origins=["*"],
|
||||
allow_credentials=True,
|
||||
allow_credentials=False,
|
||||
allow_methods=["*"],
|
||||
allow_headers=["*"],
|
||||
)
|
||||
@@ -55,22 +74,6 @@ app.include_router(ai_presets_router, prefix="/api/v1/ai", tags=["ai"])
|
||||
app.include_router(plugins_router, prefix="/api/v1/plugins", tags=["plugins"])
|
||||
app.include_router(media_router, prefix="/api/v1/media", tags=["media"])
|
||||
|
||||
# Seed admin user on startup
|
||||
@app.on_event("startup")
|
||||
async def startup_seed_admin():
|
||||
seed_admin()
|
||||
|
||||
@app.on_event("startup")
|
||||
async def startup_convert_soundfonts():
|
||||
# SF2 -> SF3 conversion is disabled: the client FluidSynth WASM cannot decode
|
||||
# Ogg Vorbis (SF3) samples, so converted SF3s would play silence. The download
|
||||
# endpoint serves SF2 when available and converts SF3 -> SF2 on demand instead.
|
||||
pass
|
||||
|
||||
@app.on_event("startup")
|
||||
async def startup_sf_scanner():
|
||||
scanner = SoundFontAutoScanner()
|
||||
scanner.start_background(interval=30)
|
||||
|
||||
@app.get("/", response_class=HTMLResponse)
|
||||
async def get_index():
|
||||
@@ -80,12 +83,11 @@ async def get_index():
|
||||
with open(index_path, "r", encoding="utf-8") as file:
|
||||
return HTMLResponse(content=file.read(), status_code=200)
|
||||
|
||||
|
||||
@app.get("/favicon.svg")
|
||||
async def get_favicon():
|
||||
import os
|
||||
favicon_path = os.path.join(settings.TEMPLATES_DIR, "favicon.svg")
|
||||
if os.path.exists(favicon_path):
|
||||
from fastapi.responses import FileResponse
|
||||
return FileResponse(favicon_path, media_type="image/svg+xml")
|
||||
return HTMLResponse(content="", status_code=404)
|
||||
|
||||
|
||||
+17
-1
@@ -5,12 +5,18 @@ import time
|
||||
from typing import Optional, Dict, Any, List
|
||||
from app.config import settings
|
||||
|
||||
DB_PATH = os.path.join(settings.STORAGE_DIR, "sonicforge.db")
|
||||
# Default DB lives in storage/; tests override via SONICFORGE_DB_PATH so the
|
||||
# dev database is never touched by the test suite.
|
||||
DB_PATH = os.getenv("SONICFORGE_DB_PATH") or os.path.join(settings.STORAGE_DIR, "sonicforge.db")
|
||||
|
||||
def get_db_connection():
|
||||
os.makedirs(settings.STORAGE_DIR, exist_ok=True)
|
||||
conn = sqlite3.connect(DB_PATH)
|
||||
conn.row_factory = sqlite3.Row
|
||||
# WAL improves concurrent read/write; FK enforcement makes quota/backup
|
||||
# cleanup consistent when users are deleted.
|
||||
conn.execute("PRAGMA journal_mode=WAL")
|
||||
conn.execute("PRAGMA foreign_keys=ON")
|
||||
return conn
|
||||
|
||||
def init_db():
|
||||
@@ -89,6 +95,16 @@ def init_db():
|
||||
);
|
||||
""")
|
||||
|
||||
# Placeholder user for anonymous autosave: projects are saved with
|
||||
# user_id='anonymous' when no token is present, so the FK must resolve.
|
||||
cursor.execute("SELECT id FROM users WHERE id = 'anonymous'")
|
||||
if not cursor.fetchone():
|
||||
import secrets as _secrets
|
||||
cursor.execute("""
|
||||
INSERT OR IGNORE INTO users (id, username, email, hashed_password, role, must_change_password, created_at, is_active)
|
||||
VALUES ('anonymous', 'anonymous', 'anonymous@local', ?, 'standard', 0, ?, 0)
|
||||
""", (_secrets.token_hex(32), time.time()))
|
||||
|
||||
conn.commit()
|
||||
conn.close()
|
||||
|
||||
|
||||
+1269
-195
File diff suppressed because it is too large
Load Diff
File diff suppressed because one or more lines are too long
@@ -275,7 +275,10 @@ ${rules.join('\n')}` },
|
||||
} else {
|
||||
response = await fetch(`${origin}/api/v1/ai/proxy`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
...(localStorage.getItem('sonic_token') ? { 'X-Auth-Token': localStorage.getItem('sonic_token') } : {})
|
||||
},
|
||||
body: JSON.stringify({ url, headers, body })
|
||||
});
|
||||
}
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
8d26e2b55e73579d1bb3c37b4878f1845ef9cbf50a8e4ee6f7deaa2ab80db32d
|
||||
@@ -24,7 +24,7 @@
|
||||
<script src="/static/js/services/midiExtractor.js?v=202607281052"></script>
|
||||
<script src="/static/js/services/promptTemplateManager.js?v=202607281039"></script>
|
||||
<script src="/static/js/services/undoRedoEngine.js?v=202607290941"></script>
|
||||
<script src="/static/js/app.precompiled.js?v=202608031415" defer></script>
|
||||
<script src="/static/js/app.precompiled.js?v=202608033200" defer></script>
|
||||
<link rel="stylesheet" href="/static/css/styles.css?v=202607271016">
|
||||
<style>
|
||||
:root {
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
import os
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, "/app")
|
||||
|
||||
try:
|
||||
import fluidsynth
|
||||
print("fluidsynth import successful.")
|
||||
|
||||
fl = fluidsynth.Synth()
|
||||
# Try to load a pre-existing system SF3
|
||||
sf3_path = "/opt/daw_engine/soundfonts/Equinox_Grand_Pianos.sf3"
|
||||
print(f"Checking if {sf3_path} exists: {os.path.exists(sf3_path)}")
|
||||
if os.path.exists(sf3_path):
|
||||
h = fl.sfload(sf3_path)
|
||||
print(f"Loaded {sf3_path}, handle: {h}")
|
||||
else:
|
||||
print("Equinox_Grand_Pianos.sf3 not found.")
|
||||
except Exception as e:
|
||||
print(f"Failed: {e}")
|
||||
@@ -0,0 +1,66 @@
|
||||
import os
|
||||
import sys
|
||||
import logging
|
||||
|
||||
# Ensure app is in path
|
||||
sys.path.insert(0, "/app")
|
||||
|
||||
logging.basicConfig(level=logging.INFO)
|
||||
logger = logging.getLogger("test_sf_convert")
|
||||
|
||||
from app.core.soundfont_converter import SoundFontConverter
|
||||
|
||||
def test():
|
||||
sf2_dir = "/app/app/storage/soundfonts"
|
||||
sf2_files = [os.path.join(sf2_dir, f) for f in os.listdir(sf2_dir) if f.endswith(".sf2") and "_decomp" not in f]
|
||||
if not sf2_files:
|
||||
logger.error("No SF2 files found in /app/app/storage/soundfonts")
|
||||
return
|
||||
|
||||
sf2_path = sf2_files[0]
|
||||
logger.info(f"Testing with SF2 file: {sf2_path}")
|
||||
|
||||
converter = SoundFontConverter()
|
||||
|
||||
# Check ffmpeg encoder support
|
||||
has_ogg = converter._check_ffmpeg_ogg()
|
||||
logger.info(f"ffmpeg with libvorbis available: {has_ogg}")
|
||||
|
||||
# Convert SF2 -> SF3
|
||||
sf3_path = sf2_path.replace(".sf2", ".sf3")
|
||||
if os.path.exists(sf3_path):
|
||||
os.remove(sf3_path)
|
||||
|
||||
logger.info("Converting SF2 -> SF3...")
|
||||
result_path = converter.convert_sf2_to_sf3(sf2_path)
|
||||
logger.info(f"Result path from convert_sf2_to_sf3: {result_path}")
|
||||
|
||||
if result_path.endswith(".sf3"):
|
||||
logger.info(f"SF3 file exists: {os.path.exists(sf3_path)}")
|
||||
if os.path.exists(sf3_path):
|
||||
logger.info(f"SF3 size: {os.path.getsize(sf3_path)} bytes")
|
||||
# Verify if it plays audio
|
||||
plays = converter._sf3_plays_audio(sf3_path)
|
||||
logger.info(f"SF3 plays audio (pyfluidsynth verify): {plays}")
|
||||
|
||||
# Now test decompression back to SF2
|
||||
decomp_sf2 = sf3_path.replace(".sf3", "_decomp.sf2")
|
||||
if os.path.exists(decomp_sf2):
|
||||
os.remove(decomp_sf2)
|
||||
|
||||
logger.info("Decompressing SF3 -> SF2...")
|
||||
try:
|
||||
decomp_result = converter.sf3_to_sf2(sf3_path, decomp_sf2)
|
||||
logger.info(f"Decompress result path: {decomp_result}")
|
||||
if os.path.exists(decomp_sf2):
|
||||
logger.info(f"Decompressed SF2 size: {os.path.getsize(decomp_sf2)} bytes")
|
||||
# Check if it plays
|
||||
decomp_plays = converter._sf3_plays_audio(decomp_sf2)
|
||||
logger.info(f"Decompressed SF2 plays audio: {decomp_plays}")
|
||||
except Exception as e:
|
||||
logger.error(f"Decompression failed: {e}", exc_info=True)
|
||||
else:
|
||||
logger.warning("Conversion did not produce an SF3 path.")
|
||||
|
||||
if __name__ == "__main__":
|
||||
test()
|
||||
@@ -0,0 +1,14 @@
|
||||
// Rebuild app.precompiled.js from app.jsx using @babel/standalone (avoids the
|
||||
// Babel 8 ESM-only CLI conflict). Mirrors package.json's build script:
|
||||
// babel app/static/js/app.jsx --config-file ./babel.config.json -o app/static/js/app.precompiled.js
|
||||
import * as Babel from '@babel/standalone';
|
||||
import { readFileSync, writeFileSync } from 'fs';
|
||||
|
||||
const src = readFileSync('app/static/js/app.jsx', 'utf8');
|
||||
const out = Babel.transform(src, {
|
||||
presets: ['react'],
|
||||
filename: 'app.jsx',
|
||||
sourceType: 'script',
|
||||
}).code;
|
||||
writeFileSync('app/static/js/app.precompiled.js', out);
|
||||
console.log('BUILD OK', out.length, 'bytes');
|
||||
@@ -0,0 +1,14 @@
|
||||
"""Pytest bootstrap: isolate the test suite from the development database.
|
||||
|
||||
Must be imported before any app module (pytest imports conftest.py first), so
|
||||
app.models.user picks up the test DB path instead of the dev DB. Without this,
|
||||
tests that seed/rotate the admin password (test_auth_and_quota) permanently
|
||||
mutate the developer's sonicforge.db.
|
||||
"""
|
||||
import os
|
||||
import tempfile
|
||||
|
||||
os.environ.setdefault(
|
||||
"SONICFORGE_DB_PATH",
|
||||
os.path.join(tempfile.gettempdir(), "sonicforge_test.db"),
|
||||
)
|
||||
@@ -13,7 +13,17 @@ client = TestClient(app)
|
||||
def get_admin_token():
|
||||
resp = client.post("/api/v1/auth/login", json={"username": "admin", "password": "admin123"})
|
||||
if resp.status_code == 200:
|
||||
return resp.json()["access_token"]
|
||||
token = resp.json()["access_token"]
|
||||
# Admin is seeded with must_change_password=1; the app blocks music
|
||||
# processing until the first password change. Complete that flow here
|
||||
# (keeping the same password) so feature tests run unblocked.
|
||||
user = resp.json()["user"]
|
||||
if user.get("must_change_password"):
|
||||
r = client.post("/api/v1/auth/change-password", headers={"Authorization": f"Bearer {token}"},
|
||||
json={"old_password": "admin123", "new_password": "admin123"})
|
||||
if r.status_code == 200:
|
||||
token = r.json()["access_token"]
|
||||
return token
|
||||
return None
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,68 @@
|
||||
"""Regression tests for legacy project upgrade (items must stay on their tracks
|
||||
with correct bar positions)."""
|
||||
import json
|
||||
|
||||
from app.api.v1.projects import upgrade_project_json_if_needed
|
||||
|
||||
|
||||
def _legacy_project():
|
||||
return {
|
||||
"id": "legacy_1",
|
||||
"name": "Legacy",
|
||||
"bpm": 120.0, # 1 bar = 2.0s
|
||||
"tracks": [
|
||||
{
|
||||
"id": "1",
|
||||
"name": "Track 1",
|
||||
"volumeDb": 0.0,
|
||||
"pan": 0.0,
|
||||
"muted": False,
|
||||
"solo": False,
|
||||
"serverFileId": "abc.wav",
|
||||
"clips": [{"id": "c1", "name": "clip1", "startTime": 2.0}],
|
||||
"midiItems": [],
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"name": "Track 2",
|
||||
"volumeDb": 0.0,
|
||||
"pan": 0.0,
|
||||
"muted": False,
|
||||
"solo": False,
|
||||
"serverFileId": None,
|
||||
"clips": [],
|
||||
"midiItems": [
|
||||
{"id": "m1", "name": "midi1", "startTime": 4.0, "duration": 4.0,
|
||||
"notes": [{"id": "n1", "pitch": 60, "start_beat": 0.0, "duration_beats": 1.0, "velocity": 0.8}]}
|
||||
],
|
||||
},
|
||||
],
|
||||
}
|
||||
|
||||
|
||||
def test_upgrade_keeps_items_on_their_tracks():
|
||||
upgraded = upgrade_project_json_if_needed(_legacy_project())
|
||||
tracks = upgraded["main_session"]["tracks"]
|
||||
assert len(tracks) == 2
|
||||
t1_items = tracks[0]["items"]
|
||||
t2_items = tracks[1]["items"]
|
||||
# Items must NOT be merged into the first track
|
||||
assert [i["type"] for i in t1_items] == ["AUDIO_ITEM"]
|
||||
assert [i["type"] for i in t2_items] == ["MIDI_ITEM"]
|
||||
assert t1_items[0]["id"] == "c1"
|
||||
assert t2_items[0]["id"] == "m1"
|
||||
|
||||
|
||||
def test_upgrade_uses_bpm_based_seconds_per_bar():
|
||||
upgraded = upgrade_project_json_if_needed(_legacy_project())
|
||||
tracks = upgraded["main_session"]["tracks"]
|
||||
# 120bpm -> 1 bar = 2.0s; clip at 2.0s -> start_bar 1.0
|
||||
assert tracks[0]["items"][0]["start_bar"] == 1.0
|
||||
# midi at 4.0s -> start_bar 2.0; duration 4.0s -> 2.0 bars
|
||||
assert tracks[1]["items"][0]["start_bar"] == 2.0
|
||||
assert tracks[1]["items"][0]["duration_bars"] == 2.0
|
||||
|
||||
|
||||
def test_upgrade_skips_new_format():
|
||||
data = {"main_session": {"tracks": []}}
|
||||
assert upgrade_project_json_if_needed(data) is data
|
||||
@@ -0,0 +1,234 @@
|
||||
"""Regression tests for security hardening.
|
||||
|
||||
Covers the vulnerabilities found during the 2026-08 audit:
|
||||
- SSRF / open proxy on /api/v1/ai/proxy
|
||||
- path traversal on render output and audio file ids
|
||||
- unauthenticated filesystem access via /api/v1/media/*
|
||||
- hardcoded SECRET_KEY
|
||||
- quota bypass on project update
|
||||
- audio resampling correctness in the render engine
|
||||
"""
|
||||
import os
|
||||
import json
|
||||
|
||||
import numpy as np
|
||||
import pytest
|
||||
import soundfile as sf
|
||||
from fastapi.testclient import TestClient
|
||||
|
||||
from app.main import app
|
||||
from app.config import settings
|
||||
from app.core import auth as core_auth
|
||||
|
||||
client = TestClient(app)
|
||||
|
||||
|
||||
def get_admin_token():
|
||||
# test_auth_and_quota.py may have rotated the admin password; try both.
|
||||
for pwd in ("admin123", "admin_new_password_2026"):
|
||||
resp = client.post("/api/v1/auth/login", json={"username": "admin", "password": pwd})
|
||||
if resp.status_code != 200:
|
||||
continue
|
||||
token = resp.json()["access_token"]
|
||||
user = resp.json()["user"]
|
||||
if user.get("must_change_password"):
|
||||
r = client.post("/api/v1/auth/change-password", headers={"Authorization": f"Bearer {token}"},
|
||||
json={"old_password": pwd, "new_password": pwd})
|
||||
if r.status_code == 200:
|
||||
token = r.json()["access_token"]
|
||||
return token
|
||||
return None
|
||||
|
||||
|
||||
def auth_headers():
|
||||
return {"Authorization": f"Bearer {get_admin_token()}"}
|
||||
|
||||
|
||||
# ── 1. SSRF / open proxy ──
|
||||
|
||||
class TestAIProxySSRF:
|
||||
def test_proxy_requires_auth(self):
|
||||
resp = client.post("/api/v1/ai/proxy", json={"url": "https://api.openai.com/v1", "body": {}})
|
||||
assert resp.status_code == 401
|
||||
|
||||
def test_proxy_blocks_cloud_metadata(self):
|
||||
resp = client.post("/api/v1/ai/proxy", headers=auth_headers(),
|
||||
json={"url": "http://169.254.169.254/latest/meta-data/", "body": {}})
|
||||
assert resp.status_code == 403
|
||||
|
||||
def test_proxy_blocks_private_ip_not_configured(self):
|
||||
resp = client.post("/api/v1/ai/proxy", headers=auth_headers(),
|
||||
json={"url": "http://10.0.0.5/", "body": {}})
|
||||
assert resp.status_code == 403
|
||||
|
||||
def test_proxy_rejects_non_http_scheme(self):
|
||||
resp = client.post("/api/v1/ai/proxy", headers=auth_headers(),
|
||||
json={"url": "file:///etc/passwd", "body": {}})
|
||||
assert resp.status_code == 400
|
||||
|
||||
def test_proxy_allows_configured_localhost_provider(self):
|
||||
# localhost:11434 is in the default AI provider list; it must pass the
|
||||
# SSRF check (and then fail to connect in this environment -> 502).
|
||||
resp = client.post("/api/v1/ai/proxy", headers=auth_headers(),
|
||||
json={"url": "http://localhost:11434/v1/chat/completions", "body": {}})
|
||||
assert resp.status_code == 502
|
||||
|
||||
|
||||
# ── 2. Path traversal ──
|
||||
|
||||
class TestPathTraversal:
|
||||
def test_render_output_filename_sanitized(self):
|
||||
token = get_admin_token()
|
||||
if not token:
|
||||
pytest.skip("Cannot get admin token")
|
||||
project = {
|
||||
"metadata": {"bpm": 120, "time_signature_numerator": 4},
|
||||
"main_session": {"length_bars": 1, "tracks": []},
|
||||
"section_store": {},
|
||||
}
|
||||
resp = client.post("/api/v1/plugins/render", headers=auth_headers(),
|
||||
json={"project_json": project, "output_filename": "/tmp/evil_traversal.wav"})
|
||||
# Absolute paths must be reduced to a basename inside PROCESSED_DIR.
|
||||
assert resp.status_code == 200, resp.text
|
||||
out_path = resp.json()["path"]
|
||||
assert os.path.dirname(out_path) == settings.PROCESSED_DIR
|
||||
assert os.path.basename(out_path) == "evil_traversal.wav"
|
||||
assert os.path.isfile(out_path)
|
||||
|
||||
def test_audio_download_rejects_traversal(self):
|
||||
resp = client.get("/api/v1/audio/download/..%2F..%2Fapp%2Fconfig.py")
|
||||
assert resp.status_code == 404
|
||||
|
||||
def test_ai_scan_rejects_traversal_file_id(self):
|
||||
resp = client.post("/api/v1/audio/ai-scan",
|
||||
json={"track_id": "1", "file_id": "../../app/config.py"})
|
||||
# Traversal must NOT read the file: falls through to the demo branch.
|
||||
assert resp.status_code == 200
|
||||
assert resp.json()["success"] is True
|
||||
|
||||
|
||||
# ── 3. Filesystem exposure via media endpoints ──
|
||||
|
||||
class TestMediaAuth:
|
||||
# Use a fresh client (no cookies from earlier logins) to prove 401.
|
||||
@pytest.fixture(autouse=True)
|
||||
def _fresh_client(self):
|
||||
self.fresh = TestClient(app)
|
||||
yield
|
||||
self.fresh.close()
|
||||
|
||||
def test_media_computer_requires_auth(self):
|
||||
resp = self.fresh.get("/api/v1/media/computer")
|
||||
assert resp.status_code == 401
|
||||
|
||||
def test_media_browse_requires_auth(self):
|
||||
resp = self.fresh.get("/api/v1/media/browse", params={"path": "/etc"})
|
||||
assert resp.status_code == 401
|
||||
|
||||
def test_media_file_requires_auth(self):
|
||||
resp = self.fresh.get("/api/v1/media/file", params={"path": "/etc/passwd"})
|
||||
assert resp.status_code == 401
|
||||
|
||||
|
||||
# ── 4. Secret key ──
|
||||
|
||||
class TestSecretKey:
|
||||
def test_secret_key_not_hardcoded_default(self):
|
||||
assert core_auth.SECRET_KEY != "sonicforge_secret_key_super_secure_2026"
|
||||
assert len(core_auth.SECRET_KEY) >= 32
|
||||
|
||||
|
||||
# ── 5. Quota enforcement on update ──
|
||||
|
||||
class TestQuotaUpdate:
|
||||
def test_update_cloud_project_enforces_quota(self):
|
||||
token = get_admin_token()
|
||||
if not token:
|
||||
pytest.skip("Cannot get admin token")
|
||||
# Register a fresh user with a small quota (unique name per run so the
|
||||
# test is re-runnable against a persistent DB).
|
||||
import uuid as _uuid
|
||||
uname = f"quota_user_{_uuid.uuid4().hex[:8]}"
|
||||
resp = client.post("/api/v1/auth/register", json={
|
||||
"username": uname, "email": f"{uname}@studio.com", "password": "quota_pass_123"})
|
||||
assert resp.status_code == 200, resp.text
|
||||
user_token = resp.json()["access_token"]
|
||||
user_headers = {"Authorization": f"Bearer {user_token}"}
|
||||
|
||||
# Shrink quota to 1 MB via admin API.
|
||||
uid = resp.json()["user"]["id"]
|
||||
r = client.put(f"/api/v1/admin/quotas/{uid}", headers=auth_headers(),
|
||||
json={"storage_limit_mb": 1, "max_tracks": 16})
|
||||
assert r.status_code == 200, r.text
|
||||
|
||||
# Save a small project.
|
||||
small = json.dumps({
|
||||
"project_id": "p1",
|
||||
"metadata": {"title": "small", "bpm": 120, "time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4, "sample_rate": 44100},
|
||||
"main_session": {"id": "main", "name": "MAIN SESSION", "is_root": True,
|
||||
"length_bars": 16.0, "auto_compute_length": True, "tracks": []},
|
||||
"section_store": {}})
|
||||
r = client.post("/api/v1/projects/cloud", headers=user_headers,
|
||||
json={"name": "small", "data_json": small})
|
||||
assert r.status_code == 200, r.text
|
||||
pid = r.json()["project_id"]
|
||||
|
||||
# Updating with a payload over the quota must be rejected (was a bypass).
|
||||
items = [{
|
||||
"type": "AUDIO_ITEM", "id": f"it_{i}", "name": "n",
|
||||
"start_bar": 0.0, "duration_bars": 1.0, "clip_start_offset_bars": 0.0,
|
||||
"source_data": {"audio_file_url": "", "gain": 1.0},
|
||||
} for i in range(20000)]
|
||||
huge = json.dumps({
|
||||
"project_id": "p1",
|
||||
"metadata": {"title": "huge", "bpm": 120, "time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4, "sample_rate": 44100},
|
||||
"main_session": {"id": "main", "name": "MAIN SESSION", "is_root": True,
|
||||
"length_bars": 16.0, "auto_compute_length": True,
|
||||
"tracks": [{"id": "t", "name": "x", "type": "AUDIO", "items": items}]},
|
||||
"section_store": {}})
|
||||
r = client.put(f"/api/v1/projects/cloud/{pid}", headers=user_headers,
|
||||
json={"name": "huge", "data_json": huge})
|
||||
assert r.status_code == 400, r.text
|
||||
assert "Quota" in r.json()["detail"]
|
||||
|
||||
|
||||
# ── 6. Render engine: resampling correctness ──
|
||||
|
||||
class TestRenderResample:
|
||||
def test_audio_item_resampled_to_engine_rate(self, tmp_path):
|
||||
from app.core.render_engine import PythonRenderEngine
|
||||
# 44.1kHz source, engine at 22.05kHz -> exactly 2x downsampling.
|
||||
sr_src = 44100
|
||||
t = np.arange(sr_src) / sr_src
|
||||
tone = (0.5 * np.sin(2 * np.pi * 440 * t)).astype(np.float32)
|
||||
src_path = os.path.join(settings.UPLOADS_DIR, "resample_test_tone.wav")
|
||||
sf.write(src_path, tone, sr_src)
|
||||
|
||||
engine = PythonRenderEngine(sample_rate=22050)
|
||||
session = {
|
||||
"tracks": [{
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0.0, "pan": 0.0, "mute": False,
|
||||
"items": [{
|
||||
"type": "AUDIO_ITEM",
|
||||
"start_bar": 0.0, "duration_bars": 4.0,
|
||||
"clip_start_offset_bars": 0.0,
|
||||
"source_data": {"audio_file_url": "/static/audio/uploads/resample_test_tone.wav", "gain": 1.0},
|
||||
}],
|
||||
}]
|
||||
}
|
||||
buf = engine.render_session_container(session, {}, bpm=120.0, time_sig_num=4,
|
||||
total_samples=engine.sample_rate * 2)
|
||||
# A 1s 440Hz tone must actually render energy (previously the SR
|
||||
# mismatch silently skipped the audio).
|
||||
assert np.max(np.abs(buf)) > 0.01
|
||||
# Duration should be ~1 second at the engine rate, not 2.
|
||||
nonzero = np.where(np.abs(buf[0]) > 1e-4)[0]
|
||||
assert len(nonzero) > 0
|
||||
assert (nonzero[-1] - nonzero[0]) < int(engine.sample_rate * 1.3)
|
||||
try:
|
||||
os.remove(src_path)
|
||||
except OSError:
|
||||
pass
|
||||
@@ -0,0 +1,993 @@
|
||||
[
|
||||
{
|
||||
"id": "bca1bb5f-b656-48a8-b113-8fff900188ab",
|
||||
"name": "Test",
|
||||
"data_json": {
|
||||
"project_id": "project_1784710097790",
|
||||
"metadata": {
|
||||
"title": "Test",
|
||||
"bpm": 120.0,
|
||||
"time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4,
|
||||
"sample_rate": 44100
|
||||
},
|
||||
"main_session": {
|
||||
"id": "main",
|
||||
"name": "MAIN SESSION",
|
||||
"is_root": true,
|
||||
"length_bars": 16.0,
|
||||
"auto_compute_length": true,
|
||||
"tracks": [
|
||||
{
|
||||
"id": "1",
|
||||
"name": "Track 01",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"name": "Track 02",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"section_store": {}
|
||||
},
|
||||
"updated_at": 1784710143.4476569
|
||||
},
|
||||
{
|
||||
"id": "d627f532-b632-4ef0-a21f-80dcc2ac8396",
|
||||
"name": "Test",
|
||||
"data_json": {
|
||||
"project_id": "project_1784719724178",
|
||||
"metadata": {
|
||||
"title": "Test",
|
||||
"bpm": 120.0,
|
||||
"time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4,
|
||||
"sample_rate": 44100
|
||||
},
|
||||
"main_session": {
|
||||
"id": "main",
|
||||
"name": "MAIN SESSION",
|
||||
"is_root": true,
|
||||
"length_bars": 16.0,
|
||||
"auto_compute_length": true,
|
||||
"tracks": [
|
||||
{
|
||||
"id": "1",
|
||||
"name": "Track 01",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"name": "Track 02",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"section_store": {}
|
||||
},
|
||||
"updated_at": 1784719770.23144
|
||||
},
|
||||
{
|
||||
"id": "a17fe50b-c51d-408d-b45c-c09645777e68",
|
||||
"name": "Test",
|
||||
"data_json": {
|
||||
"project_id": "project_1784719775936",
|
||||
"metadata": {
|
||||
"title": "Test",
|
||||
"bpm": 120.0,
|
||||
"time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4,
|
||||
"sample_rate": 44100
|
||||
},
|
||||
"main_session": {
|
||||
"id": "main",
|
||||
"name": "MAIN SESSION",
|
||||
"is_root": true,
|
||||
"length_bars": 16.0,
|
||||
"auto_compute_length": true,
|
||||
"tracks": [
|
||||
{
|
||||
"id": "1",
|
||||
"name": "Track 01",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"name": "Track 02",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"section_store": {}
|
||||
},
|
||||
"updated_at": 1784719821.9856758
|
||||
},
|
||||
{
|
||||
"id": "38a0f344-05dc-47e3-a769-07426c57f5fe",
|
||||
"name": "Test",
|
||||
"data_json": {
|
||||
"project_id": "project_1784720540893",
|
||||
"metadata": {
|
||||
"title": "Test",
|
||||
"bpm": 120.0,
|
||||
"time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4,
|
||||
"sample_rate": 44100
|
||||
},
|
||||
"main_session": {
|
||||
"id": "main",
|
||||
"name": "MAIN SESSION",
|
||||
"is_root": true,
|
||||
"length_bars": 16.0,
|
||||
"auto_compute_length": true,
|
||||
"tracks": [
|
||||
{
|
||||
"id": "1",
|
||||
"name": "Cartoon Capers Loop.mp3",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"name": "Track 02",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"section_store": {}
|
||||
},
|
||||
"updated_at": 1784720586.9746954
|
||||
},
|
||||
{
|
||||
"id": "8037d8f5-1410-4639-8167-5b89dcb1c3e9",
|
||||
"name": "Rose",
|
||||
"data_json": {
|
||||
"project_id": "project_1784720555735",
|
||||
"metadata": {
|
||||
"title": "Rose",
|
||||
"bpm": 120.0,
|
||||
"time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4,
|
||||
"sample_rate": 44100
|
||||
},
|
||||
"main_session": {
|
||||
"id": "main",
|
||||
"name": "MAIN SESSION",
|
||||
"is_root": true,
|
||||
"length_bars": 16.0,
|
||||
"auto_compute_length": true,
|
||||
"tracks": [
|
||||
{
|
||||
"id": "1",
|
||||
"name": "Track 01",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"name": "Track 02",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"fx_chain": [],
|
||||
"synth_engine": {
|
||||
"plugin_id": "synth",
|
||||
"preset_id": "default",
|
||||
"parameters": {}
|
||||
},
|
||||
"items": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"section_store": {}
|
||||
},
|
||||
"updated_at": 1784720601.8155787
|
||||
},
|
||||
{
|
||||
"id": "525bdab5-e594-4a0c-a3e6-102a0abef816",
|
||||
"name": "Rose (autosave 03/08)",
|
||||
"data_json": {
|
||||
"project_id": "8037d8f5-1410-4639-8167-5b89dcb1c3e9",
|
||||
"metadata": {
|
||||
"title": "Rose (autosave 03/08)",
|
||||
"bpm": 128,
|
||||
"time_signature_numerator": 4,
|
||||
"time_signature_denominator": 4,
|
||||
"sample_rate": 44100
|
||||
},
|
||||
"main_session": {
|
||||
"id": "main",
|
||||
"name": "MAIN SESSION",
|
||||
"is_root": true,
|
||||
"length_bars": 16,
|
||||
"auto_compute_length": true,
|
||||
"tracks": [
|
||||
{
|
||||
"id": "1",
|
||||
"name": "Track 01",
|
||||
"type": "MIDI",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"instrument_id": "sf_DSK_Asian_DreamZ",
|
||||
"instrument_program": 5,
|
||||
"instrument_name": "BAN-DI",
|
||||
"items": [
|
||||
{
|
||||
"id": "midi_1785057918746",
|
||||
"name": "MIDI Item",
|
||||
"type": "MIDI_ITEM",
|
||||
"start_bar": 0,
|
||||
"duration_bars": 4,
|
||||
"clip_start_offset_bars": 0,
|
||||
"source_data": {
|
||||
"total_buffer_bars": 4,
|
||||
"notes": [
|
||||
{
|
||||
"id": "note_1785057946413j2a54",
|
||||
"pitch": 55,
|
||||
"start_beat": 1.5,
|
||||
"duration_beats": 0.125,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946488uv1f6r6q_2",
|
||||
"pitch": 56,
|
||||
"start_beat": 1.5166666666666666,
|
||||
"duration_beats": 0.2333333333333334,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946505gxl5rre2_3",
|
||||
"pitch": 57,
|
||||
"start_beat": 1.75,
|
||||
"duration_beats": 0.3833333333333333,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946522v0dmipvj_4",
|
||||
"pitch": 60,
|
||||
"start_beat": 2.1333333333333333,
|
||||
"duration_beats": 0.2666666666666666,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579465381vqpeamx_5",
|
||||
"pitch": 62,
|
||||
"start_beat": 2.4,
|
||||
"duration_beats": 0.21666666666666679,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946555rmpgksfp_6",
|
||||
"pitch": 63,
|
||||
"start_beat": 2.6166666666666667,
|
||||
"duration_beats": 0.20000000000000018,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946572cvrxri09_7",
|
||||
"pitch": 64,
|
||||
"start_beat": 2.816666666666667,
|
||||
"duration_beats": 0.25,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946588nvmp7zld_8",
|
||||
"pitch": 66,
|
||||
"start_beat": 3.066666666666667,
|
||||
"duration_beats": 0.1499999999999999,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946605jkbnh8mf_9",
|
||||
"pitch": 67,
|
||||
"start_beat": 3.216666666666667,
|
||||
"duration_beats": 0.2666666666666666,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946638i28svktt_10",
|
||||
"pitch": 68,
|
||||
"start_beat": 3.4833333333333334,
|
||||
"duration_beats": 0.1499999999999999,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579466559iy45ml8_11",
|
||||
"pitch": 69,
|
||||
"start_beat": 3.6333333333333333,
|
||||
"duration_beats": 0.1333333333333333,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946672s712j5m6_12",
|
||||
"pitch": 70,
|
||||
"start_beat": 3.7666666666666666,
|
||||
"duration_beats": 0.1333333333333333,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946688pq858zcx_13",
|
||||
"pitch": 71,
|
||||
"start_beat": 3.9,
|
||||
"duration_beats": 0.18333333333333313,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579467054usc79tx_14",
|
||||
"pitch": 72,
|
||||
"start_beat": 4.083333333333333,
|
||||
"duration_beats": 0.15000000000000036,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946722dspmlfaa_15",
|
||||
"pitch": 73,
|
||||
"start_beat": 4.233333333333333,
|
||||
"duration_beats": 0.2999999999999998,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946755h5mvip3h_16",
|
||||
"pitch": 74,
|
||||
"start_beat": 4.533333333333333,
|
||||
"duration_beats": 0.15000000000000036,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946772a5e5iona_17",
|
||||
"pitch": 75,
|
||||
"start_beat": 4.683333333333334,
|
||||
"duration_beats": 0.16666666666666607,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946788cfqxk2c8_18",
|
||||
"pitch": 76,
|
||||
"start_beat": 4.85,
|
||||
"duration_beats": 0.2666666666666666,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_178505794682247xy477z_19",
|
||||
"pitch": 77,
|
||||
"start_beat": 5.116666666666666,
|
||||
"duration_beats": 0.25,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946855nygukqis_20",
|
||||
"pitch": 78,
|
||||
"start_beat": 5.366666666666666,
|
||||
"duration_beats": 0.20000000000000018,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946888oyfvmvq2_21",
|
||||
"pitch": 79,
|
||||
"start_beat": 5.566666666666666,
|
||||
"duration_beats": 0.35000000000000053,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947455xrq7rfmm_22",
|
||||
"pitch": 78,
|
||||
"start_beat": 5.916666666666667,
|
||||
"duration_beats": 0.2833333333333332,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579474722sn8bsed_23",
|
||||
"pitch": 77,
|
||||
"start_beat": 6.2,
|
||||
"duration_beats": 0.31666666666666643,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947489mbv5z7q6_24",
|
||||
"pitch": 76,
|
||||
"start_beat": 6.516666666666667,
|
||||
"duration_beats": 0.2833333333333332,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947505qmasllso_25",
|
||||
"pitch": 75,
|
||||
"start_beat": 6.8,
|
||||
"duration_beats": 0.41666666666666696,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947539wkqyr6fw_26",
|
||||
"pitch": 74,
|
||||
"start_beat": 7.216666666666667,
|
||||
"duration_beats": 0.18333333333333357,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947572a2ydjwzu_27",
|
||||
"pitch": 73,
|
||||
"start_beat": 7.4,
|
||||
"duration_beats": 0.1999999999999993,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947589b18pcser_28",
|
||||
"pitch": 72,
|
||||
"start_beat": 7.6,
|
||||
"duration_beats": 0.16666666666666696,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947605bsiv751r_29",
|
||||
"pitch": 71,
|
||||
"start_beat": 7.766666666666667,
|
||||
"duration_beats": 0.13333333333333375,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947622ii453i6x_30",
|
||||
"pitch": 70,
|
||||
"start_beat": 7.9,
|
||||
"duration_beats": 0.18333333333333357,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947639zdv6seea_31",
|
||||
"pitch": 69,
|
||||
"start_beat": 8.083333333333334,
|
||||
"duration_beats": 0.36666666666666536,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947672devle9p7_32",
|
||||
"pitch": 68,
|
||||
"start_beat": 8.45,
|
||||
"duration_beats": 0.25,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947689x8rgn7ih_33",
|
||||
"pitch": 67,
|
||||
"start_beat": 8.7,
|
||||
"duration_beats": 0.3333333333333339,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947722u5b36hrl_34",
|
||||
"pitch": 66,
|
||||
"start_beat": 9.033333333333333,
|
||||
"duration_beats": 0.2833333333333332,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947772f9qp4st0_35",
|
||||
"pitch": 65,
|
||||
"start_beat": 9.316666666666666,
|
||||
"duration_beats": 0.38333333333333286,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947805cf5bjiv1_36",
|
||||
"pitch": 64,
|
||||
"start_beat": 9.7,
|
||||
"duration_beats": 0.6666666666666679,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947855ojfcoccj_37",
|
||||
"pitch": 63,
|
||||
"start_beat": 10.366666666666667,
|
||||
"duration_beats": 0.36666666666666536,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579478721jvhzolj_38",
|
||||
"pitch": 62,
|
||||
"start_beat": 10.733333333333333,
|
||||
"duration_beats": 0.3000000000000007,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947889nqk9ckue_39",
|
||||
"pitch": 61,
|
||||
"start_beat": 11.033333333333333,
|
||||
"duration_beats": 0.3333333333333339,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "2",
|
||||
"name": "Track 02",
|
||||
"type": "AUDIO",
|
||||
"volume_db": 0,
|
||||
"pan": 0,
|
||||
"mute": false,
|
||||
"solo": false,
|
||||
"instrument_id": null,
|
||||
"instrument_program": null,
|
||||
"instrument_name": null,
|
||||
"items": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"sub_tabs": [
|
||||
{
|
||||
"id": "midi_1785057919362",
|
||||
"label": "Piano Roll: MIDI Item",
|
||||
"type": "PIANO_ROLL",
|
||||
"track_id": "1",
|
||||
"target_id": "midi_1785057918746",
|
||||
"parent_tab_id": null,
|
||||
"notes": [
|
||||
{
|
||||
"id": "note_1785057946413j2a54",
|
||||
"pitch": 55,
|
||||
"start_beat": 1.5,
|
||||
"duration_beats": 0.125,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946488uv1f6r6q_2",
|
||||
"pitch": 56,
|
||||
"start_beat": 1.5166666666666666,
|
||||
"duration_beats": 0.2333333333333334,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946505gxl5rre2_3",
|
||||
"pitch": 57,
|
||||
"start_beat": 1.75,
|
||||
"duration_beats": 0.3833333333333333,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946522v0dmipvj_4",
|
||||
"pitch": 60,
|
||||
"start_beat": 2.1333333333333333,
|
||||
"duration_beats": 0.2666666666666666,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579465381vqpeamx_5",
|
||||
"pitch": 62,
|
||||
"start_beat": 2.4,
|
||||
"duration_beats": 0.21666666666666679,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946555rmpgksfp_6",
|
||||
"pitch": 63,
|
||||
"start_beat": 2.6166666666666667,
|
||||
"duration_beats": 0.20000000000000018,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946572cvrxri09_7",
|
||||
"pitch": 64,
|
||||
"start_beat": 2.816666666666667,
|
||||
"duration_beats": 0.25,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946588nvmp7zld_8",
|
||||
"pitch": 66,
|
||||
"start_beat": 3.066666666666667,
|
||||
"duration_beats": 0.1499999999999999,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946605jkbnh8mf_9",
|
||||
"pitch": 67,
|
||||
"start_beat": 3.216666666666667,
|
||||
"duration_beats": 0.2666666666666666,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946638i28svktt_10",
|
||||
"pitch": 68,
|
||||
"start_beat": 3.4833333333333334,
|
||||
"duration_beats": 0.1499999999999999,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579466559iy45ml8_11",
|
||||
"pitch": 69,
|
||||
"start_beat": 3.6333333333333333,
|
||||
"duration_beats": 0.1333333333333333,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946672s712j5m6_12",
|
||||
"pitch": 70,
|
||||
"start_beat": 3.7666666666666666,
|
||||
"duration_beats": 0.1333333333333333,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946688pq858zcx_13",
|
||||
"pitch": 71,
|
||||
"start_beat": 3.9,
|
||||
"duration_beats": 0.18333333333333313,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579467054usc79tx_14",
|
||||
"pitch": 72,
|
||||
"start_beat": 4.083333333333333,
|
||||
"duration_beats": 0.15000000000000036,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946722dspmlfaa_15",
|
||||
"pitch": 73,
|
||||
"start_beat": 4.233333333333333,
|
||||
"duration_beats": 0.2999999999999998,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946755h5mvip3h_16",
|
||||
"pitch": 74,
|
||||
"start_beat": 4.533333333333333,
|
||||
"duration_beats": 0.15000000000000036,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946772a5e5iona_17",
|
||||
"pitch": 75,
|
||||
"start_beat": 4.683333333333334,
|
||||
"duration_beats": 0.16666666666666607,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946788cfqxk2c8_18",
|
||||
"pitch": 76,
|
||||
"start_beat": 4.85,
|
||||
"duration_beats": 0.2666666666666666,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_178505794682247xy477z_19",
|
||||
"pitch": 77,
|
||||
"start_beat": 5.116666666666666,
|
||||
"duration_beats": 0.25,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946855nygukqis_20",
|
||||
"pitch": 78,
|
||||
"start_beat": 5.366666666666666,
|
||||
"duration_beats": 0.20000000000000018,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057946888oyfvmvq2_21",
|
||||
"pitch": 79,
|
||||
"start_beat": 5.566666666666666,
|
||||
"duration_beats": 0.35000000000000053,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947455xrq7rfmm_22",
|
||||
"pitch": 78,
|
||||
"start_beat": 5.916666666666667,
|
||||
"duration_beats": 0.2833333333333332,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579474722sn8bsed_23",
|
||||
"pitch": 77,
|
||||
"start_beat": 6.2,
|
||||
"duration_beats": 0.31666666666666643,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947489mbv5z7q6_24",
|
||||
"pitch": 76,
|
||||
"start_beat": 6.516666666666667,
|
||||
"duration_beats": 0.2833333333333332,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947505qmasllso_25",
|
||||
"pitch": 75,
|
||||
"start_beat": 6.8,
|
||||
"duration_beats": 0.41666666666666696,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947539wkqyr6fw_26",
|
||||
"pitch": 74,
|
||||
"start_beat": 7.216666666666667,
|
||||
"duration_beats": 0.18333333333333357,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947572a2ydjwzu_27",
|
||||
"pitch": 73,
|
||||
"start_beat": 7.4,
|
||||
"duration_beats": 0.1999999999999993,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947589b18pcser_28",
|
||||
"pitch": 72,
|
||||
"start_beat": 7.6,
|
||||
"duration_beats": 0.16666666666666696,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947605bsiv751r_29",
|
||||
"pitch": 71,
|
||||
"start_beat": 7.766666666666667,
|
||||
"duration_beats": 0.13333333333333375,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947622ii453i6x_30",
|
||||
"pitch": 70,
|
||||
"start_beat": 7.9,
|
||||
"duration_beats": 0.18333333333333357,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947639zdv6seea_31",
|
||||
"pitch": 69,
|
||||
"start_beat": 8.083333333333334,
|
||||
"duration_beats": 0.36666666666666536,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947672devle9p7_32",
|
||||
"pitch": 68,
|
||||
"start_beat": 8.45,
|
||||
"duration_beats": 0.25,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947689x8rgn7ih_33",
|
||||
"pitch": 67,
|
||||
"start_beat": 8.7,
|
||||
"duration_beats": 0.3333333333333339,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947722u5b36hrl_34",
|
||||
"pitch": 66,
|
||||
"start_beat": 9.033333333333333,
|
||||
"duration_beats": 0.2833333333333332,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947772f9qp4st0_35",
|
||||
"pitch": 65,
|
||||
"start_beat": 9.316666666666666,
|
||||
"duration_beats": 0.38333333333333286,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947805cf5bjiv1_36",
|
||||
"pitch": 64,
|
||||
"start_beat": 9.7,
|
||||
"duration_beats": 0.6666666666666679,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947855ojfcoccj_37",
|
||||
"pitch": 63,
|
||||
"start_beat": 10.366666666666667,
|
||||
"duration_beats": 0.36666666666666536,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_17850579478721jvhzolj_38",
|
||||
"pitch": 62,
|
||||
"start_beat": 10.733333333333333,
|
||||
"duration_beats": 0.3000000000000007,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
},
|
||||
{
|
||||
"id": "note_1785057947889nqk9ckue_39",
|
||||
"pitch": 61,
|
||||
"start_beat": 11.033333333333333,
|
||||
"duration_beats": 0.3333333333333339,
|
||||
"velocity": 0.8,
|
||||
"pan": 0
|
||||
}
|
||||
],
|
||||
"duration": 7.5,
|
||||
"instrument_program": 5,
|
||||
"instrument_name": "BAN-DI",
|
||||
"current_time": 0,
|
||||
"color": null
|
||||
}
|
||||
],
|
||||
"section_store": {}
|
||||
},
|
||||
"updated_at": 1785058087.45
|
||||
}
|
||||
]
|
||||
@@ -0,0 +1,62 @@
|
||||
"""Khôi phục các dự án cloud cũ (từ git history) vào bất kỳ sonicforge.db nào.
|
||||
|
||||
Cách dùng trên máy deployment thật (host game):
|
||||
python3 tools/restore_cloud_projects.py /path/to/sonicforge.db
|
||||
|
||||
Script đọc backup projects (JSON) đã xuất từ git history và chèn vào DB chỉ định,
|
||||
gán tất cả cho user_id được yêu cầu (mặc định: admin đầu tiên tìm thấy).
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import sqlite3
|
||||
import sys
|
||||
|
||||
PROJECTS_BACKUP = os.path.join(os.path.dirname(__file__), "cloud_projects_backup.json")
|
||||
|
||||
|
||||
def main(db_path: str, user_id: str = None):
|
||||
if not os.path.exists(PROJECTS_BACKUP):
|
||||
print(f"Không tìm thấy {PROJECTS_BACKUP}")
|
||||
return 1
|
||||
if not os.path.exists(db_path):
|
||||
print(f"Không tìm thấy DB: {db_path}")
|
||||
return 1
|
||||
|
||||
with open(PROJECTS_BACKUP) as f:
|
||||
projects = json.load(f)
|
||||
|
||||
conn = sqlite3.connect(db_path)
|
||||
conn.row_factory = sqlite3.Row
|
||||
|
||||
if user_id is None:
|
||||
row = conn.execute("SELECT id FROM users WHERE role='admin' ORDER BY created_at LIMIT 1").fetchone()
|
||||
if not row:
|
||||
print("Không có user admin nào trong DB")
|
||||
conn.close()
|
||||
return 1
|
||||
user_id = row["id"]
|
||||
print(f"Gán tất cả cho admin: {user_id}")
|
||||
|
||||
restored = 0
|
||||
for p in projects:
|
||||
if conn.execute("SELECT id FROM projects WHERE id=?", (p["id"],)).fetchone():
|
||||
print(f" bỏ qua (đã tồn tại): {p['name']}")
|
||||
continue
|
||||
conn.execute(
|
||||
"INSERT INTO projects (id, user_id, name, data_json, is_temp, size_bytes, updated_at) VALUES (?,?,?,?,0,?,?)",
|
||||
(p["id"], user_id, p["name"], json.dumps(p["data_json"], ensure_ascii=False),
|
||||
len(json.dumps(p["data_json"]).encode("utf-8")), p["updated_at"]))
|
||||
restored += 1
|
||||
print(f" đã khôi phục: {p['name']}")
|
||||
|
||||
conn.commit()
|
||||
conn.close()
|
||||
print(f"\nHoàn tất: {restored} dự án đã khôi phục cho user {user_id}")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
if len(sys.argv) < 2:
|
||||
print("Usage: python3 restore_cloud_projects.py <path/to/sonicforge.db> [user_id]")
|
||||
sys.exit(1)
|
||||
sys.exit(main(sys.argv[1], sys.argv[2] if len(sys.argv) > 2 else None))
|
||||
@@ -1,3 +1,126 @@
|
||||
### [2026-08-03] Task: Loop vẫn giãn selection tới bar 18 — mở rộng hasSel + verify bundle serve
|
||||
- **Tóm tắt thay đổi:** User báo vẫn lỗi sau fix trước. Kiểm tra toàn diện: (1) Không có path nào khác giãn selection khi loop bật (SubTabToolbar/onLoop là code chết; toggleLoop là Media Explorer preview; useEffect BPM chỉ chạy khi đổi tempo). (2) Mở rộng điều kiện `hasSel` trong handler nút loop: ngoài `selectionMode==='local'`, còn nhận selection qua `selectionStart/selectionEnd` hợp lệ (phòng trường hợp sweep không set 'local'). (3) **Verify bằng server thật** (uvicorn 9131): file `app.precompiled.js?v=202608033200` được serve có chứa `hasSel=selectionMode===` + comment fix — chứng minh bundle workspace đã đúng. Nếu user vẫn thấy lỗi → trình duyệt cache hoặc đang chạy deployment khác (không phải workspace).
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608033200; sửa double `</script>` phát sinh khi bump)
|
||||
- **Ghi chú/Test (nếu có):** `pytest` 86 passed (chưa chạy lại lần này — chỉ đổi frontend).
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Fix loop button ghi đè vùng chọn thành 0→18 bar (MAIN SESSION/SECTION-TAB)
|
||||
- **Tóm tắt thay đổi:** Khi quét chọn vùng duration rồi bấm nút loop, vùng chọn bị tự đổi thành 0→18 bar. Nguyên nhân: handler nút loop (nhánh main timeline, không có sub-tab active) LUÔN tự derive loop end từ content tracks (`maxEnd + 2 bar` — content 16 bar → 18) rồi `setSelectionStart(0); setSelectionEnd(loopEnd)` — ghi đè vùng chọn của user. Fix: **tôn trọng selection có sẵn** (`hasSel = selectionMode==='local' && selLeft/selRight hợp lệ`) — chỉ auto-derive khi CHƯA có vùng chọn nào. Áp dụng cho cả MAIN SESSION lẫn SECTION-TAB (cả 2 đều đi qua nhánh main timeline khi không có sub-tab; section-tab dùng chung selection handler nên sweep cũng set `selectionMode='local'`). Kèm theo: `handleTrackLaneMouseDown` giờ `setSelectionCleared(false)` khi bắt đầu chọn vùng mới — nếu user từng Ctrl+click xoá chọn thì vùng mới vẫn loop được.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608033100)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, syntax OK, `pytest` 86 passed.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Fix React error #310 khi mở Mixer modal (hooks sau early return)
|
||||
- **Tóm tắt thay đổi:** Sau fix `isFxActive`, mở Mixer modal vẫn lỗi `Minified React error #310` ("Rendered more hooks than during the previous render"). Nguyên nhân: khi thêm dynamic module chain, 2 hooks `dragChainIndexRef` (useRef) + `addModuleOpen` (useState) được khai báo SAU dòng `if (!isOpen) return null;` trong MasteringModal → số hooks giữa các render thay đổi khi modal đóng/mở (return null sớm bỏ qua 2 hooks) → React #310. Fix: di chuyển 2 hooks lên TRƯỚC early return (cạnh useEffect [isOpen]).
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032900)
|
||||
- **Ghi chú/Test (nếu có):** verify: hooks tại 9252-9253 trước `if (!isOpen) return null;` (9255), không còn hook nào sau early return trong MasteringModal; syntax OK; bracket balance 0.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Fix "ReferenceError: isFxActive is not defined" khi mở Mixer modal
|
||||
- **Tóm tắt thay đổi:** Khi mở Mixer modal bị lỗi `Uncaught ReferenceError: isFxActive is not defined`. Nguyên nhân: lúc thêm FX chain editor cho TrackStripConsole, tôi vô tình xóa luôn khai báo `const [isFxActive, setIsFxActive]` riêng của TrackStripConsole (git HEAD có 2 khai báo: master strip + track strip; sau khi dọn duplicate thì chỉ còn 1 của master strip) → nút FX Power trong TrackStripConsole tham chiếu biến không tồn tại. Fix: khôi phục khai báo `isFxActive` trong TrackStripConsole (cạnh `fxChainOpen`).
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032800)
|
||||
- **Ghi chú/Test (nếu có):** verify: 2 khai báo `isFxActive` (master strip 1154 + track strip 1460), bundle có `isFxActive` ×5, syntax OK, bracket balance 0.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Nâng cấp Mastering panel theo mastering_expand.md (EQ presets + module factory + reorder + track FX reuse)
|
||||
- **Tóm tắt thay đổi:** Làm 4 yêu cầu spec mastering_expand.md:
|
||||
1. **EQ Presets** (§II.1): `EQ_PRESET_LIBRARY` (flat/vocal_clarity/bass_punch/warm_tape) + dropdown trong EQ view — `applyEQPreset` ramp freq/gain/Q trên 4 biquad filter + sync knobs/canvas.
|
||||
2. **Module factory + 5 module mới** (§II.2): thêm DSP cho **Bus Compressor** (DynamicsCompressor + makeup), **Brickwall Limiter** (ratio 20:1, knee 0), **Harmonic Exciter** (WaveShaper + HP 2kHz + dry/wet), **Master Rebalance** (M/S gains qua L/R crossfeed) trong initMasterBus; mỗi module có input/output gain riêng.
|
||||
3. **Module reordering + dynamic re-route** (§II.3): `rebuildMasteringGraph(active, chain)` — disconnect mọi boundary node rồi nối chuỗi active modules giữa inputAnalyser→outputAnalyser. Chain strip giờ render ĐỘNG từ `ozState.chain` (drag-drop reorder, power toggle, delete, nút [+] mở modal thêm module 7 loại). `toggleMasteringOnMaster` dùng chain signature cho idempotency. Migration: project cũ không có `chain` → default [eq, imager, maximizer] + params mới.
|
||||
4. **Reuse cho track FX** (§II.4): `createTrackFxModule(type, ctx)` — factory tạo instance DSP giống mastering cho từng track; `getOrCreateTrackNode` wire `track.fxChain` (chuỗi module) trước chorus/reverb; serialize/deserialize `fx_chain`; nút **FX** trên TrackStripConsole mở modal editor (thêm/xóa/toggle từng module Comp/Limiter/Exciter/M-S/EQ).
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032700)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, syntax OK, bracket balance 0, `pytest` 86 passed. Lưu ý: module mới có param riêng (compThreshold/compRatio/compMakeup, limThreshold, excDrive, rebalMid/rebalSide) được lưu trong mastering_settings.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Cài đặt Imager module theo imager_spec.md (M/S width + vectorscope + correlation meter)
|
||||
- **Tóm tắt thay đổi:** Làm đúng spec imager_spec.md trong MASTERING PANEL (Mixer F7):
|
||||
1. **DSP width semantics chuẩn spec**: 0% = MONO (S×0), 100% = Original (S×1), 200% = 2× Width (S×2). Giữ cấu trúc 4-band crossover (20-100Hz / 100Hz-1kHz / 1k-6kHz / 6k-20kHz) với matrix L/R crossfeed tương đương M/S (M = (L+R)/2 giữ nguyên, S = (L−R)/2 × w/100 — chứng minh: g1=(w+100)/200, g2=(100−w)/200 → mid=(g1+g2)=1, side=(g1−g2)=w/100).
|
||||
2. **Migration**: project cũ lưu scale −100..+100 (0 = original) → tự +100 mỗi band khi load (0→100, 15→115, 35→135, 50→150), dùng marker `imagerScale:'v2'` cho project mới. Default mới theo khuyến nghị spec: Band1=0% (MONO maker), Band2=115%, Band3=135%, Band4=150%.
|
||||
3. **Vectorscope thật (Polar M/S)**: thay chấm ngẫu nhiên giả bằng trace thật X=(L+R), Y=(L−R) từ leftAnalyser/rightAnalyser (post-mastering) — mono → nằm ngang, width tăng → trải dọc.
|
||||
4. **Phase Correlation meter thật**: ρ = Σ(L·R)/√(ΣL²·ΣR²) (−1..+1), gauge vẽ zone màu theo spec (+0.5..+1 xanh an toàn, 0..+0.5 vàng cẩn trọng, <0 đỏ nguy hiểm) + hiển thị số "Corr:".
|
||||
5. UI: slider range 0-200%, nhãn band theo spec, hint "0% = Mono · 100% = Original · 200% = 2× Width".
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032600)
|
||||
- **Ghi chú/Test (nếu có):** verify DSP (w=0→side 0, w=100→side 1, w=200→side 2, mid luôn 1), migration (0,15,35,50 → 100,115,135,150; v2 giữ nguyên), slider trong bundle. `pytest` 86 passed.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Mute/Solo realtime cho MIDI items — dùng CC7 (channel volume) của FluidSynth
|
||||
- **Tóm tắt thay đổi:** Mute/unmute/solo chưa realtime với **MIDI items** vì FluidSynth WASM render toàn bộ channel vào **1 worklet → 1 `_gainNode` chung** (`_workletNode.connect(_gainNode)`), nên gain node của track không câm được MIDI (chỉ audio clips + section sub-tracks qua track gain mới bị ảnh hưởng). Fix: mỗi track MIDI sở hữu **channel riêng** (`ensureTrackMidiChannel`, 0-15 trừ 9) → dùng **CC7 (channel volume)** của FluidSynth (`window.SonicSF.controllerChange(ch, 7, 100|0)`) — áp realtime kể cả với notes đang vang. Thêm vào `applyAllTrackMuteSolo` (nút M/S) + effect sync `[tracks, sessionTabs]` (load/undo). Khi mute → CC7=0 (notes đang phát câm ngay); unmute → CC7=100 (notes đang phát vang lại + cơ chế becameAudible→restart vẫn giữ). Audio clips/section vẫn qua track gain như cũ.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032500)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, syntax OK, verify `controllerChange(ch,7,...)` ×2 trong bundle; `pytest` 86 passed.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Fix items rớt/dồn sai track khi load-save project (3 bug)
|
||||
- **Tóm tắt thay đổi:** (1) **`serializeTracksList` (app.jsx)**: chuỗi `if/else-if` theo `trackType` chỉ serialize MỘT loại items → track có cả clips + midiItems/sections bị **rớt items khi save** (mất dữ liệu âm thầm, có thể gây cảm giác "items biến mất/dồn chỗ"). Sửa: serialize ĐỘC LẬP từng loại items có trên track. (2) **`upgrade_project_json_if_needed` (projects.py)**: hardcode `start_bar = startTime/4.0` + `duration_bars = 4.0` → vị trí items sai (lệch 2× ở 120bpm, càng lệch khi tempo khác). Sửa: dùng `seconds_per_bar = (60/bpm)*4` từ bpm của project. (3) **`loadAudioBuffersForTracks` (app.jsx)**: merge buffer theo **array index** → nếu state đổi giữa lúc fetch (race: mở project khác khi buffer-load cũ chưa xong) thì tracks bị xáo trộn, items rơi vào track sai. Sửa: merge theo **track ID** + clip ID.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/api/v1/projects.py`, `app/templates/index.html` (bump v=202608032400), `tests/test_project_upgrade.py` (mới)
|
||||
- **Ghi chú/Test (nếu có):** verify: round-trip serialize→deserialize giữ đúng track + vị trí (đã test bằng code bundle thật); track hỗn hợp giờ ra `AUDIO_ITEM,MIDI_ITEM`; `pytest` **86 passed** (3 test mới cho upgrade). Lưu ý: deserialize/upgrade vốn đã map đúng từng track — nếu user vẫn thấy items dồn track 1 sau khi hard-refresh, cần kiểm tra dữ liệu project cụ thể (và bản bundle trình duyệt đang chạy).
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Fix unmute không phát lại khi đang play (sources bị loop-restart bỏ qua)
|
||||
- **Tóm tắt thay đổi:** Khi đang play, mute → câm (OK, gain 0) nhưng unmute → không nghe lại được. Nguyên nhân: nếu có loop restart (`stopAllPlayback` + `startTrackPlayback` trong updatePlayhead), vòng lặp mới **bỏ qua track đang mute/solo** (isPlayable check) → sources của track không được tạo lại → chỉ set gain khi unmute không "hồi sinh" được nguồn đã không tồn tại. Fix trong `applyAllTrackMuteSolo`: theo dõi `trackAudibleRef` (audibility từng track), khi phát hiện chuyển tiếp **inaudible → audible** (unmute / tắt solo) và `isPlaying` + không đang RECORDING → `stopAllPlayback()` + `startTrackPlayback(currentTime)` re-schedule lại từ playhead hiện tại (đúng cơ chế toggleTrackSoloEvaluate đã dùng cho solo). Mute thuần (audible→inaudible) vẫn chỉ set gain (tức thì, không gián đoạn track khác). Effect sync `[tracks, sessionTabs]` giờ cũng cập nhật `trackAudibleRef` để nhất quán khi load/undo.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032300)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, syntax OK, `pytest` 83 passed.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Mute/Solo realtime — tác dụng ngay lên items đang phát của track
|
||||
- **Tóm tắt thay đổi:** Nút M/S ở cả MixerStrip (mixer F7) và TrackStripConsole (track strip) giờ tác dụng **realtime**: toggle mute/solo lập tức set gain của track node đang phát (crossfade 20ms, không click). Cơ chế: `computeTrackAudibleGain(list, track)` (mute luôn tắt; nếu có bất kỳ solo → chỉ track solo nghe được; ngược lại theo volumeDb), `setTrackNodeGain(node, gain)` áp vào `gainNode` của track node. `window.__applyTrackMuteSolo(trackId, patch)` được gọi từ: (1) nút M/S của cả 2 strip (patch state + áp ngay), (2) `getOrCreateTrackNode` khi tạo node (items của track muted/soloed bắt đầu đúng trạng thái), (3) `startSubTabPlayback` cho chain mới, (4) effect sync `[tracks, sessionTabs]` với signature `muted|solo|volumeDb` (chỉ re-apply khi thay đổi — phủ load project/undo/section tab). Vì audio clip `source.connect(gainNode)` và MIDI note (đường oscillator fallback) đều qua track gainNode → mute/solo có tác dụng lên toàn bộ items của track.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032200)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, syntax OK, `pytest` 83 passed. Giới hạn: MIDI qua FluidSynth WASM render chung 1 worklet → không tách theo track (cùng giới hạn với bypass); đường oscillator fallback thì có tác dụng.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Đồng bộ hành vi click+drag item (clip = move như section/MIDI; Alt+click+drag = quét chọn)
|
||||
- **Tóm tắt thay đổi:** (1) **Thống nhất**: click + drag trên MỌI item (section/MIDI/audio clip) = **di chuyển**; trước đây audio clip click+drag = quét chọn vùng (gây cảm giác "không đáp ứng"). (2) Hành động cũ của audio clip chuyển sang **Alt+click+drag = quét chọn duration** (gọi `onTrackLaneMouseDown` → local sweep select); Alt+right-edge vẫn = time-stretch. (3) **Fix "thỉnh thoảng không đáp ứng"**: mọi item giờ dùng cơ chế **pending drag có threshold 5px** — click thuần chỉ chọn item (không tạo undo/toast, không vô tình di chuyển do rung chuột), di chuột >5px mới bắt đầu drag. Cơ chế: `handleSetPendingDragMove` (mới) lưu `pendingDragRef` với `duplicate:false`; effect pending-drag route: clip đơn → `handleClipDragStartRef` (clip machinery), còn lại → `handleSectionItemDragStartRef` (multiIds đã hỗ trợ clip). `handleSetPendingDrag` (Ctrl+click copy) giờ lưu `duplicate:true`. Sửa lookup clip trong nhánh non-duplicate của `handleSectionItemDragStart`.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032100)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, syntax OK, verify `duplicate:true`/`!pdSnap.duplicate` trong bundle. `pytest` 83 passed. Grab tool (kéo nhanh) giữ nguyên.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Bypass trên nút Routing Matrix (track strip TCP) + bypass bỏ cả track FX
|
||||
- **Tóm tắt thay đổi:** (1) Nút **Routing Matrix** trong `TrackStripConsole` (TCP strip, cạnh M/S) giờ là nút **Bypass** — tooltip "Bypass: track KHÔNG qua FX + mastering ở Main out", active style xanh khi bật. (2) Thay đổi điểm lấy tín hiệu dry: trong `getOrCreateTrackNode`, `dryGain` giờ tap từ **`gainNode` (PRE-FX)** thay vì `analyserNode` (post-FX) → khi bypass, channel bỏ qua **cả track FX (chorus/reverb) lẫn mastering chain** ở Main out; đường routeGain giữ nguyên (post-FX → mastering) khi không bypass. (3) Xác nhận Mixer Panel đã ở phím **F7** (code sẵn: F7 → `__toggleMixerRef`).
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608032000)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, syntax OK, không còn "Routing Matrix", `pytest` 83 passed.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Fix TDZ "Cannot access 'sessionTabs' before initialization" sau khi thêm nút Bypass
|
||||
- **Tóm tắt thay đổi:** `useEffect` sync `trackMasteringBypassMap` đặt ở ~11786 nhưng dependency array `[tracks, sessionTabs]` được đánh giá ngay tại chỗ gọi — trước khi `sessionTabs` khai báo (12239) → `ReferenceError: Cannot access 'sessionTabs' before initialization` khi chạy app. Fix: di chuyển useEffect xuống sau khối khai báo `subTabs`/`sessionTabs`/`sessionTabsRef` (TDZ-safe). `window.__setTrackMasteringBypass` an toàn vì chỉ truy cập `activeTrackNodesRef` bên trong body hàm (lúc click).
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608031900)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` OK, verify trong bundle: effect @453168 sau sessionTabs decl @451814. `pytest` 83 passed. Người dùng chạy `npm run build` trên workspace là được.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Nút Bypass Mastering cho từng track strip trong Mixer Panel
|
||||
- **Tóm tắt thay đổi:** Thêm nút **B** (Bypass) trong mỗi track strip của Mixer Panel (cạnh M/S). Khi bật ON: âm thanh track đi qua **dry bus mới** (`masterBus.dryInput → dryOutput → output`) — **bỏ qua toàn bộ chuỗi mastering** (EQ / Imager / Maximizer) nhưng vẫn qua master volume + metering ở Main out. Cơ chế: `createMasteringRoute()` tạo 2 đường gain bù nhau (routeGain → `masterBus.input` qua mastering, dryGain → `dryInput`); `setMasteringRoute()` crossfade 20ms khi toggle (không click). Áp dụng tại: `getOrCreateTrackNode` (node track chính, toggle live qua `node.route`), `startSubTabPlayback` (clip playback). Map trạng thái `trackMasteringBypassMap` sync từ tracks state qua useEffect; `window.__setTrackMasteringBypass` toggle ngay cho track đang phát. Lưu/đọc project: `mastering_bypass` trong serialize/deserialize (schema không chặn additionalProperties nên không cần sửa).
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (rebuild), `app/templates/index.html` (bump v=202608031800)
|
||||
- **Ghi chú/Test (nếu có):** `node build.mjs` rebuild OK, syntax OK, `pytest` 83 passed. **Giới hạn:** track MIDI/SoundFont dùng chung 1 bộ render FluidSynth (1 worklet → 1 gain) nên bypass hiện áp dụng cho track AUDIO (clip) + oscillator fallback; track MIDI dùng FluidSynth WASM chưa tách được theo track (cần refactor renderer) — sẽ làm tiếp nếu cần.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Rebuild app.precompiled.js từ app.jsx (fix "handleOpenProject is not defined")
|
||||
- **Tóm tắt thay đổi:** Lỗi `Uncaught ReferenceError: handleOpenProject is not defined` khi click Open → bundle `app.precompiled.js` mà trình duyệt tải bị lệch với `app.jsx` (bundle cũ không chứa định nghĩa hàm ở scope đúng). `npm run build` không chạy được vì Babel 8 ESM-only (`ERR_REQUIRE_ESM`). Giải pháp: build lại bundle bằng **@babel/standalone@7** qua `build.mjs` (script mới, mirror đúng lệnh build trong package.json), tạo `app.precompiled.js` mới (858KB, syntax OK, đủ `const handleOpenProject` + 3 references, kèm fix restoreLastSessionProject). Đã smoke-test: trích deserializer từ bundle mới chạy với 6 project khôi phục → 6/6 OK, "Rose (autosave 03/08)" đủ 39 MIDI notes. Bump cache-buster lên `v=202608031700`.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.precompiled.js` (rebuild), `build.mjs` (NEW — rebuild thủ công khi Babel 8 lỗi), `app/templates/index.html`
|
||||
- **Ghi chú/Test (nếu có):** `pytest tests/` → 83 passed. Node portable dùng: `/tmp/node-v20.18.0-linux-x64/bin/node` (máy không có node hệ thống). Trên máy deployment: copy 3 file (app.jsx, app.precompiled.js, index.html) hoặc chạy `node build.mjs` rồi hard refresh.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Fix auto-restore dự án lỗi "Không tìm thấy dự án" sau khi khôi phục DB
|
||||
- **Tóm tắt thay đổi:** Sau khi DB bị xóa/tạo lại, `localStorage.sonic_project_id` của trình duyệt vẫn trỏ tới project cũ đã mất → mỗi lần tải trang `restoreLastSessionProject` gọi API, nhận 404 "Không tìm thấy dự án" và chỉ `console.warn` vĩnh viễn. Fix: khi restore thất bại, tự xóa `sonic_project_id` + `sonic_project_name` khỏi localStorage để lỗi không lặp lại. Bump cache-buster precompiled lên `v=202608031600`.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js`, `app/templates/index.html`
|
||||
- **Ghi chú/Test (nếu có):** Verified qua API: cả 6 project khôi phục mở được (GET /cloud/{id} → 200 + main_session đầy đủ). Người dùng cần hard refresh (Ctrl+Shift+R) để nạp bundle mới, mở "Rose (autosave 03/08)" 1 lần để ghim project hiện tại.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Khôi phục các dự án cloud cũ bị mất (git recovery)
|
||||
- **Tóm tắt thay đổi:** Các dự án cloud cũ ('Test' x4, 'Rose' từ 22/07) và project đang làm dở "Rose" (autosave 03/08, 2 track MIDI+AUDIO, 39 notes, bpm 128) đã được khôi phục vào `app/storage/sonicforge.db` dưới user_id admin hiện tại từ **git history** (`app/storage/sonicforge.db` từng được commit trước khi vào `.gitignore`). Nguyên nhân mất: DB bị xóa/tạo lại nhiều lần trong quá trình dev (test suite `test_auth_and_quota` xóa DB → admin được re-seed với UUID mới → project cũ gắn với user_id cũ không hiển thị). Đã dọn các project/user test rác, backup DB trước khi khôi phục tại `/tmp/sonicforge_db_before_restore.db`.
|
||||
- **Các file ảnh hưởng:** `app/storage/sonicforge.db` (dữ liệu), `tools/restore_cloud_projects.py` (NEW — script khôi phục cho deployment khác), `tools/cloud_projects_backup.json` (NEW — 6 project dạng portable)
|
||||
- **Ghi chú/Test (nếu có):** Verified qua API: login admin → `GET /api/v1/projects/cloud` trả đủ 6 project; mở "Rose (autosave 03/08)" đủ 39 MIDI notes. Trên máy deployment thật (nếu DB khác): `python3 tools/restore_cloud_projects.py <duong-dan>/sonicforge.db`. Từ giờ test suite không đụng DB dev (xem entry conftest).
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Cô lập test suite khỏi DB dev + khôi phục mật khẩu admin
|
||||
- **Tóm tắt thay đổi:** (1) `DB_PATH` trong `app/models/user.py` giờ có thể override bằng env `SONICFORGE_DB_PATH`. (2) Thêm `tests/conftest.py` set env này sang `/tmp/sonicforge_test.db` trước khi mọi app module được import → pytest không bao giờ sửa DB dev nữa (trước đây `test_auth_and_quota` seed + đổi mật khẩu admin ngay trong `app/storage/sonicforge.db`, khiến login `admin123` fail). (3) Reset mật khẩu admin DB dev về `admin123` (`must_change_password=0`).
|
||||
- **Các file ảnh hưởng:** `app/models/user.py`, `tests/conftest.py` (NEW)
|
||||
- **Ghi chú/Test (nếu có):** `pytest tests/` → 83 passed, 5 skipped. Đã verify live: login admin/admin123 → 200, sai mật khẩu → 400. Nếu deployment khác cũng bị dính (chạy test trên cùng DB), reset thủ công: `UPDATE users SET hashed_password='<hash_of_admin123>', must_change_password=0 WHERE username='admin'` hoặc xóa DB để `seed_admin` tạo lại.
|
||||
---
|
||||
|
||||
### [2026-08-03] Task: Security audit + bug fixes (bảo mật, bug chức năng, cải thiện)
|
||||
- **Tóm tắt thay đổi:** (1) **SSRF** `/api/v1/ai/proxy`: thêm auth bắt buộc + chặn cloud metadata/link-local (169.254.0.0/16), chặn IP private trừ khi host nằm trong danh sách AI provider user đã cấu hình (cho phép Ollama localhost:11434), chặn scheme không phải http/https, không forward header X-Auth-Token lên upstream. (2) **Path traversal** `/plugins/render`: `output_filename` chỉ lấy basename + ép đuôi .wav. (3) **Path traversal** toàn bộ `/audio/*`: helper `_safe_file_id`/`_resolve_storage_path` (basename + chỉ đọc trong uploads/processed). (4) **SECRET_KEY**: bỏ hardcode, tự sinh random bền vững lưu `app/storage/.secret_key` (ưu tiên env SECRET_KEY). (5) **media.py** (`computer`/`browse`/`file`): yêu cầu auth — login giờ set HttpOnly cookie `sf_token`, `get_current_user` nhận token từ Bearer / X-Auth-Token / cookie nên frontend raw fetch vẫn hoạt động. (6) Upload audio + soundfont: streaming theo chunk + giới hạn size (1GB/2GB) thay vì đọc cả file vào RAM. (7) **Quota bypass**: `update_cloud_project` giờ kiểm tra quota như `save_cloud_project`. (8) `enforce_password_changed` (bắt buộc đổi mật khẩu lần đầu) được wire vào upload/edit/render/ai-scan/ai-cut/python-tool/upload-soundfont. (9) **render_engine**: fix resample bị bỏ qua (`sr != sample_rate` trước là no-op → giờ resample_poly), render tôn trọng **solo** track, cache buffer section theo `section_id`, thay print → logger. (10) **vst_engine**: thống nhất FluidSynth API low-level CFFI (high-level `Synth()`/`FluidSynth()` không tồn tại trong binding này). (11) Rate-limit login theo IP (10 lần/15 phút), validate độ mạnh password khi register. (12) main.py: `on_event` → `lifespan`, CORS `allow_credentials=False`, xóa stub rỗng. (13) SQLite: WAL + foreign_keys=ON + seed user `anonymous` placeholder (FK hợp lệ cho project ẩn danh). (14) Pydantic v2 `model_dump()` thay `dict()`.
|
||||
- **Các file ảnh hưởng:** `app/core/auth.py`, `app/api/v1/auth.py`, `app/api/v1/ai_proxy.py`, `app/api/v1/plugins.py`, `app/api/v1/audio.py`, `app/api/v1/media.py`, `app/api/v1/projects.py`, `app/api/v1/multitrack.py`, `app/api/v1/user_config.py`, `app/core/render_engine.py`, `app/core/vst_engine.py`, `app/models/user.py`, `app/main.py`, `app/static/js/services/aiGateway.js` (gửi X-Auth-Token khi gọi proxy), `tests/test_security_hardening.py` (NEW, 14 test), `tests/test_plugin_api.py`
|
||||
- **Ghi chú/Test (nếu có):** `pytest tests/` → 83 passed, 5 skipped. Đã verify live: proxy không token → 401, metadata → 403; media không token → 401 / có cookie → 200; render `output_filename=/tmp/x.wav` → path nằm trong PROCESSED_DIR. Lưu ý: nếu triển khai cũ đang chạy, restart server để tạo `.secret_key` (token cũ sẽ hết hạn vì secret đổi). Login mật khẩu admin mặc định vẫn `admin123` (đã khôi phục trong DB dev).
|
||||
---
|
||||
|
||||
### [2026-07-31 07:03] Task: Fix Lucide icons not rendering on new tracks (TCP + SECTION-TAB)
|
||||
- **Tóm tắt thay đổi:** `useEffect` gọi `lucide.createIcons()` thiếu `activeTracks` trong dependency array → khi track được tạo (user/AI/MIDI import/clone section), DOM nodes mới có `data-lucide` nhưng không được chuyển thành SVG → icon ẩn hoặc hiển thị sai. Fix: thêm `activeTracks` vào deps để auto-refresh icons sau mỗi lần track list thay đổi.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`
|
||||
@@ -1274,3 +1397,8 @@
|
||||
- **Tóm tắt thay đổi:** User chẩn đoán: mở Mastering modal, IN peak có tín hiệu nhưng OUT peak trống → tín hiệu chết TRONG master chain. Khắc phục triệt để 3 nguyên nhân có thể làm chain câm: (1) **WaveShaper `curve = null`**: một số engine xuất CÂM khi curve null (identity) — đổi luôn sang identity table `Float32Array([-1,1])` (passthrough chủ động, không bao giờ null) ở cả init và khi maximizer tắt. (2) **Tần số filter vượt Nyquist**: `eqHighFilter` 10000Hz / imager crossover 6000Hz trên thiết bị sample rate thấp (8/11/16kHz) → hệ số biquad NaN → `BiquadFilterNode: state is bad` → chain câm. Thêm `clampF(v) = min(v, sampleRate*0.45)` cho mọi biquad. (3) **Watchdog an toàn**: trong Mastering modal, nếu `masteringActive` mà IN peak > 0.01 còn OUT peak < 0.001 (chain hỏng) → tự `toggleMasteringOnMaster(false)` về routing trực tiếp để âm thanh KHÔNG BAO GIỜ bị câm toàn cục.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (build lại), `app/templates/index.html`
|
||||
- **Ghi chú/Test (nếu có):** `npm run build` OK, bundle chứa `maxFilterFreq`, `Chain broken`, `Float32Array([-1,1])`. 9 harness vẫn PASS. Hard refresh (Ctrl+F5) → thử play (main + piano roll) + bật mastering. Nếu OUT peak vẫn trống, watchdog sẽ tự bypass và log `[Mastering] Chain broken...` — báo tôi message đó.
|
||||
|
||||
### [2026-08-03 14:30] Task: Media Explorer - auto tempo theo MIDI file, gõ tempo tay, focus folder cha, điều hướng tree bằng phím mũi tên
|
||||
- **Tóm tắt thay đổi:** (1) **Auto set tempo**: click MIDI file → `handleSelect` set tempo từ metadata `f.bpm`; `playMidiPreview` sau khi parse set tempo theo `midiResult[0].bpm` (clamp 40-300) trước khi schedule → preview phát đúng tempo file. (2) **Gõ tempo tay**: input tempo dùng `tempoText` (string) cho phép gõ tự do (trước đây clamp 40-300 ngay khi gõ chặn việc nhập số < 40), commit khi hợp lệ hoặc blur/Enter; `commitTempo` còn re-schedule MIDI preview đang phát theo tempo mới. (3) **Focus folder cha**: click file → expand các node cha + `centerTreeNodeInPane` cuộn tree pane (ref `treePaneRef`) để folder cha hiện GIỮA ô tree. (4) **Phím mũi tên**: khi panel active (`window.mediaExplorerActive`) và ở computer mode, ArrowUp/Down di chuyển cursor qua node hiển thị (dùng `computerPathRef`/`computerTreeRef`/`computerRootsRef` để tránh stale closure trong keydown `[]`), ArrowRight expand/load, ArrowLeft collapse hoặc về thư mục cha; `browseComputerDirRef` tránh stale `browseComputerDir`.
|
||||
- **Các file ảnh hưởng:** `app/static/js/app.jsx`, `app/static/js/app.precompiled.js` (build lại), `app/templates/index.html`
|
||||
- **Ghi chú/Test (nếu có):** `npm run build` OK, bundle chứa commitTempo/navigateTreeTo/centerTreeNodeInPane/getVisibleTreePaths/treePaneRef/tempoText. Harness `node /tmp/kilo/test_tree.js` mô phỏng flatten tree + Up/Down/Left logic — ALL PASSED. 9 harness còn lại PASS. Hard refresh.
|
||||
|
||||
Reference in New Issue
Block a user