mirror of
https://github.com/gesellix/Bose-SoundTouch.git
synced 2026-08-19 00:56:16 +00:00
Seven BMX adapter handlers required a non-empty `Authorization` header and returned 401 from writeBMXUnauthorized when missing: TuneIn: Playback, PodcastInfo, PlaybackPodcast, Report, Navigate, Search Orion: Playback Speakers calling these endpoints directly carry their margeAuthToken in the header, so the gate works for them. But the Stockholm browser proxy (pkg/service/stockholm/proxy.go injectBackendHeaders) only injects Authorization for hosts ending in .bose.com or .apigee.net with a marge path — when Stockholm calls back into our own service for TuneIn browsing/playback/search/etc., no header is added and every request 401s. Disable the gate at all seven sites; log the missing-header case so the absence remains visible. Keep writeBMXUnauthorized as the future-restore point (//nolint:unused) — when the gate comes back (e.g. behind a BMX_STRICT_AUTH env-var or once the Stockholm proxy learns to inject Authorization for our own host), callers will use this helper again. Tests that assert 401 for missing Authorization (TestBMXUnauthorized, TestHandleTuneInReport/Unauthorized, TestHandleTuneInNavigate/Unauthorized, TestHandleTuneInSearch/Unauthorized) are `t.Skip`'d with a pointer back to handlers_bmx_tunein.go — they stay in the file to come back to life the day the gate does. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>