Implement MediaShelf v1

The application the design describes: Flask + SQLite, Plex for library data,
Tautulli for watch history, report-only.

Structure follows the design's seams. providers/ splits MediaProvider from
HistoryProvider, because on this network library data and watch data live on
different machines and Jellyfin later will have no Tautulli equivalent.
scoring.py implements the reclaim score twice - as a SQL expression for the
live grid (weights change on every slider drag, so storing it would mean
rewriting thousands of rows per drag) and in Python for CSV export and tests,
with a property test over 500 generated rows asserting the two agree.
rules.py compiles saved views to parameterized SQL through a field/operator
whitelist; nothing user-supplied is ever interpolated.

Three properties are enforced by test rather than asserted in prose:

- Ingest is idempotent. Three consecutive full scans leave every count and
  every byte total unchanged. A scanner that double-counts produces a report
  that looks plausible and is wrong.
- Keep marks survive Plex reassigning every rating key in the library. They
  are keyed on content GUID, scoped per library so the Movies and 4K Movies
  copies of the same film mark independently.
- Every config variable the app reads is declared in docker-compose.yml, so
  a variable set in Portainer can never silently do nothing.

Also found and fixed while verifying against a fake Plex+Tautulli pair:
executescript() commits the pending transaction, so migrations needed their
BEGIN/COMMIT inside the script; replaceChildren() renders null as the literal
text "null"; a hash-only URL change does not reload the document, so deep
links needed a hashchange listener; and SQLite ROUND rounds half away from
zero where Python rounds half to even.

73 tests, no live server required.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GVbG48GAXfCZatcmX123Ra
This commit is contained in:
Jess Hallsworth 2026-09-07 14:59:03 +00:00
parent 58c2883492
commit 6a557bcdd9
No known key found for this signature in database
37 changed files with 6486 additions and 85 deletions

41
Dockerfile Normal file
View file

@ -0,0 +1,41 @@
# Multi-stage so build deps don't ship in the runtime image.
FROM python:3.12-slim AS build
WORKDIR /build
COPY requirements.txt .
RUN pip install --no-cache-dir --prefix=/install -r requirements.txt
FROM python:3.12-slim
LABEL org.opencontainers.image.title="MediaShelf" \
org.opencontainers.image.description="Plex library analytics and reclaim reporting" \
org.opencontainers.image.source="https://gitlab.hallsworth.ca/yrtria/MediaShelf"
COPY --from=build /install /usr/local
# Non-root. /data is the only writable path the app needs.
RUN useradd --create-home --uid 10001 mediashelf \
&& mkdir -p /data && chown mediashelf:mediashelf /data
WORKDIR /app
COPY --chown=mediashelf:mediashelf mediashelf/ ./mediashelf/
COPY --chown=mediashelf:mediashelf wsgi.py ./
USER mediashelf
VOLUME ["/data"]
EXPOSE 8080
ENV PYTHONUNBUFFERED=1 \
PYTHONDONTWRITEBYTECODE=1 \
DATABASE_PATH=/data/mediashelf.db
HEALTHCHECK --interval=60s --timeout=10s --start-period=20s --retries=3 \
CMD python -c "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://localhost:8080/healthz', timeout=8).status==200 else 1)"
# Two workers: enough for one person browsing while a scan runs. The scheduler
# starts in exactly one of them, guarded by an flock on /data (see §11.4).
# --preload is deliberately NOT used: it would run the app factory before the
# fork, so both workers would inherit one already-open SQLite connection.
CMD ["gunicorn", "--workers", "2", "--threads", "4", "--bind", "0.0.0.0:8080", \
"--timeout", "120", "--access-logfile", "-", "wsgi:app"]