Commit graph

107 commits

Author SHA1 Message Date
Troll (Hermes Agent)
d79c58691a Document config vars and rewrite README
- Clarified HERMES_API_KEY and PRICE_PER_VERSION comments in config.py.
- Completely rewrote README.md with:
  - version, overview, and table of contents
  - page-by-page customer and admin guide
  - status flow table
  - detailed /admin/settings section
  - Docker / Portainer install process
  - full environment variable table
  - local development and troubleshooting sections
2026-08-05 16:20:08 +00:00
Troll (Hermes Agent)
235507f499 Extend callback token expiry from 1 hour to 7 days
The signed callback token for /api/prompt/<rid> expired after 1 hour.
That was too short for a workflow where the operator may copy the URL and
paste it to Hermes, then wait for a response. Extend to 7 days.

Also fixes the misleading 401 on expired tokens (token check runs before
API key check). The new /api/key-test endpoint lets callers verify the
API key independently.

Bump version 0.4.4 -> 0.4.5.
2026-08-05 14:44:25 +00:00
Troll (Hermes Agent)
2637cdba61 Add /api/key-test diagnostic endpoint for API key verification
Provides a simple GET endpoint that validates the Authorization Bearer
token against HERMES_API_KEY and returns JSON:
  {"ok": true, "reason": "valid"} or
  {"ok": false, "reason": "key_mismatch" / "missing_bearer" / "not_configured"}

Rate limited to 4 per minute to prevent brute-force guessing.

Bump version 0.4.3 -> 0.4.4.
2026-08-05 14:41:39 +00:00
Troll (Hermes Agent)
4b48e0a44f Fix TypeError when revision_count is stored as TEXT
The previous schema migration added revision_count as TEXT. SQLite stores
the default as TEXT, but the app does integer arithmetic on it, causing:

  TypeError: unsupported operand type(s) for -: 'int' and 'str'

- init_db() now adds revision_count as INTEGER.
- app.py casts revision_count to int in play() and revise() and when
  incrementing in revise(), so existing TEXT values also work.

Bump version 0.4.2 -> 0.4.3.
2026-08-05 14:25:07 +00:00
Troll (Hermes Agent)
f5d3d487af Fix 500 on /play/<token>/revise for missing revision_count column
Deployed DBs persisted without the revision_count column / revision_history
table, causing customer revision requests to 500.

- init_db() now migrates existing tables by adding missing columns.
- log_revision() falls back to init_db() on missing table for full repair.
- Bump version 0.4.1 -> 0.4.2.
2026-08-05 13:51:53 +00:00
Troll (Hermes Agent)
3f9de1449c Fix 500 on customer revision when revision_history table is missing
Deployed databases can persist without the revision_history table,
causing /play/<token>/revise to crash with sqlite3.OperationalError.

- log_revision() now creates the table on the fly if it is missing.
- app.py runs init_db() at import time (safe CREATE TABLE IF NOT EXISTS)
  so new deployments auto-create missing tables on startup.

Bump patch version 0.4.0 -> 0.4.1.
2026-08-05 13:42:10 +00:00
Troll (Hermes Agent)
7ab8388741 Allow Hermes callback endpoint to accept revision prompts
/api/prompt/<rid> previously rejected any request not in 'pending'
status. This blocked the revision workflow from using the callback.

Now the endpoint accepts 'pending' (sets status to 'prompt_ready') and
'revisions_requested' (keeps status as 'revisions_requested' so the
operator still sees it needs new song uploads).
2026-08-05 03:30:51 +00:00
Troll (Hermes Agent)
51f7ffd5ab Add revision prompt copy button for Hermes on admin request page
When a request has revision_note set, the operator now sees a
'Copy revision prompt for Hermes' button in the revision note box.
It copies a prompt that includes:
- the original customer brief,
- the previously generated title/style/lyrics,
- the customer's revision request,
- the signed callback URL and expected JSON shape.

Minor version bump: 0.3.0 → 0.4.0.
2026-08-05 03:25:34 +00:00
Troll (Hermes Agent)
da6df64fbf Update README with current version v0.3.0 2026-08-05 03:19:00 +00:00
Troll (Hermes Agent)
db249e80bd Add VERSION file and live version display on settings page
- New VERSION file at project root, starting at 0.3.0.
- config.py reads VERSION and exposes it as Config.VERSION.
- Admin settings page now renders the live version from config.
- Semantic versioning convention: MAJOR for breaking/user-facing changes,
  MINOR for new features, PATCH for bug fixes and small polish.
2026-08-05 03:17:16 +00:00
Troll (Hermes Agent)
d9e198e397 Bump version tag to v0.3 on admin settings page 2026-08-05 03:13:21 +00:00
Troll (Hermes Agent)
2b46f7d3dc Guard customer_approved null/None in all templates
Some rows (schema drift, cancelled requests, manual status edits) have
customer_approved = NULL instead of the default 'none'. Templates called
.upper() on it blindly, causing a Jinja2 UndefinedError / 500 when the
customer player or admin pages loaded.

Replace all .upper() calls with (value or 'none').upper() and add truthy
checks before rendering the approved choice in status.html and
dashboard.html.
2026-08-05 03:11:21 +00:00
Troll (Hermes Agent)
9524a24715 Fix TypeError when loading max_revisions from settings JSON
The customer player page (/play/<token>) and revision endpoint were
reading max_revisions directly from booth_settings.json, where it is
stored as a string. Arithmetic/comparison with revision_count (an int)
raised TypeError and caused a 500 error when opening the customer player.

Add get_max_revisions() helper that always returns a non-negative int,
and use it in play(), revise(), and admin_settings().
2026-08-05 03:04:48 +00:00
Troll (Hermes Agent)
b8ddff9afe Update README and REVIEW with all new features (kiosk, pricing, cancelled status, revision history, stems, sales, backups) 2026-08-04 20:46:47 +00:00
Troll (Hermes Agent)
8de32d91b7 Move revision history above operator notes, move cancel button next to status with confirmation 2026-08-04 18:58:49 +00:00
Troll (Hermes Agent)
968a6fb43c Add Cancelled status and cancel request button 2026-08-04 17:56:02 +00:00
Troll (Hermes Agent)
fd58cf47da Reorder Suno copy buttons to Lyrics, Style, Title 2026-08-04 17:49:44 +00:00
Troll (Hermes Agent)
985092d629 Remove footer URL from kiosk page 2026-08-04 17:46:49 +00:00
Troll (Hermes Agent)
9cc1bd94a6 Trim Hermes API key section on settings page 2026-08-04 17:45:16 +00:00
Troll (Hermes Agent)
c726525c8e Add public kiosk page with QR/pricing cycle and configurable slide timing 2026-08-04 17:41:33 +00:00
Troll (Hermes Agent)
a25bf3a9c9 Add admin Pricing page with fixed and custom items 2026-08-04 17:17:57 +00:00
Troll (Hermes Agent)
a3fd5938a5 Detect missing tables in DB health check and always show schema fix button 2026-08-04 16:59:54 +00:00
Troll (Hermes Agent)
cda4d57859 Add revision history log and music files ZIP backup 2026-08-04 16:54:51 +00:00
Troll (Hermes Agent)
8246f641a2 Move request status badge to top of admin request page 2026-08-04 16:45:24 +00:00
Troll (Hermes Agent)
0c90b5a298 Make all customer info fields editable from admin request page 2026-08-04 16:32:17 +00:00
Troll (Hermes Agent)
da917692f0 Add admin Sales report page 2026-08-04 01:20:56 +00:00
Troll (Hermes Agent)
d02d0b3d25 Add stems_link support for Pingvin-Share-X delivery 2026-08-04 01:10:15 +00:00
Troll (Hermes Agent)
02f1d05301 chore: remove stray test settings file 2026-08-03 22:55:59 +00:00
Troll (Hermes Agent)
a72da4c5da ui: remove Hermes API key regenerate button from admin settings
Key is now managed via HERMES_API_KEY env var only.
2026-08-03 22:55:55 +00:00
Troll (Hermes Agent)
107e558aea revert: HERMES_API_KEY env var takes precedence over runtime settings
Simpler ops model: set the key in Portainer environment variables.
2026-08-03 22:54:45 +00:00
Troll (Hermes Agent)
fc700f2d82 fix: tolerate plaintext Hermes API key in booth_settings.json
The regenerate button stores encrypted keys, but legacy/manual writes may
save plaintext. get_hermes_api_key now falls back to returning the raw
value if Fernet decryption fails.
2026-08-03 22:47:57 +00:00
Troll (Hermes Agent)
06d87eb600 fix: persist runtime settings next to database so they survive redeploys 2026-08-03 22:37:57 +00:00
Troll (Hermes Agent)
b6a0987236 fix: isolate metadata keys passed to admin settings template
Previously passed the entire runtime_settings dict as metadata, which could
clobber/overlap email form fields. Now only artist/album/year/comment are passed.
2026-08-03 19:11:23 +00:00
Troll (Hermes Agent)
d5d4882d07 feat: require customer approval before mark paid/deliver
- Disable checkboxes, payment ref input, and submit button in admin UI when customer has not approved.
- Add server-side guard in mark_paid_deliver action.
2026-08-03 19:07:22 +00:00
Troll (Hermes Agent)
3057eb8eda feat: stream MP3s through backend proxy endpoint
- Replace /audio/<token>/<v>.mp3 with /api/stream/<token>/<v>.mp3.
- Stream bytes from private storage with Accept-Ranges and Content-Range support.
- Keep old /audio route returning 404.
- Update player page JS to use new stream endpoint.
2026-08-03 18:59:00 +00:00
Troll (Hermes Agent)
5863c32e35 ui: assign audio src via JS so direct MP3 URLs are not in page source 2026-08-03 18:52:01 +00:00
Troll (Hermes Agent)
56493f5ea7 feat: disable direct MP3 download from customer player page
- Add controlsList=nodownload to audio elements.
- Serve audio with Content-Disposition: inline to discourage browser save dialogs.
2026-08-03 18:49:26 +00:00
Troll (Hermes Agent)
1694b50160 ui: display v0.2 version tag on admin settings page 2026-08-03 18:44:25 +00:00
Troll (Hermes Agent)
06db9f3e55 ui: preserve blank lines between verses in customer lyrics view 2026-08-03 18:42:31 +00:00
Troll (Hermes Agent)
d44882c237 ui: hide Suno metatag brackets from customer lyrics view 2026-08-03 18:41:06 +00:00
Troll (Hermes Agent)
e5b8186b4f fix: remove pre-wrap from lyrics container to eliminate phantom spacing 2026-08-03 18:36:24 +00:00
Troll (Hermes Agent)
d7e30ba317 ui: compress lyrics line spacing further on player page 2026-08-03 18:28:31 +00:00
Troll (Hermes Agent)
5757a768d5 ui: tighten lyrics spacing on player page 2026-08-03 18:16:00 +00:00
Troll (Hermes Agent)
7a9c8b8240 ui: show formatted lyrics on customer player page above audio players 2026-08-03 18:13:44 +00:00
Troll (Hermes Agent)
6a60aa686c feat: Hermes prompt callback endpoint + API key management
- Add /api/prompt/<rid> callback endpoint with dual auth:
  per-request signed URL token + Bearer API key.
- Add HERMES_API_KEY config and runtime key helpers in app.py.
- Update admin request page to copy request details + callback URL.
- Add API key management to admin settings: regenerate, mask, show-once.
- Update .env.example, docker-compose.yml, README, REVIEW docs.
2026-08-03 17:16:56 +00:00
Troll (Hermes Agent)
e46893e0b4 docs: update comments, docstrings, README, REVIEW, and env docs to match current features 2026-08-03 00:11:41 +00:00
Troll (Hermes Agent)
0aa3eab084 fix: record payment ref immediately; show it on admin request page 2026-08-02 23:23:45 +00:00
Troll (Hermes Agent)
109ac6c0b2 fix: make settings metadata fields always default to empty string 2026-08-02 22:41:21 +00:00
Troll (Hermes Agent)
4ab1c1e589 fix: correct DB health fix button action from fix_schema to fix_db 2026-08-02 22:35:22 +00:00
Troll (Hermes Agent)
3cb63a6480 ui: convert admin request page to two-column layout 2026-08-02 22:24:54 +00:00