fix(ypp): refresh 403'd on every real call — drop the auditDetails part (needs a partner scope)
Creator: 'when I attempt to refresh my YPP page, I get an error about not being able to reach YouTube. Seriously?' Real log: channels.list failed (403) x3. Root cause #1 (the 403): channels.list?mine=true&part=statistics,auditDetails, contentDetails returns 403 insufficientPermissions when the token lacks the youtubepartner-channel-audit scope — which the auditDetails part ALONE requires, per the docs ('A request that retrieves the auditDetails part ... must provide an authorization token that contains the youtubepartner-channel-audit scope'). That scope is MCN partner tooling with a 2-week token-revocation rule; the app must not hold it. TASK-39's 'current scopes suffice, no re-consent' slice-1 claim was wrong for this part; mock-fake tests never touched the real API, so it shipped green and 403'd every refresh since 2026-09-22. https://developers.google.com/youtube/v3/docs/channels/list Fix: part=statistics,contentDetails only; standing flags removed from ChannelStatsService -> YppStatSnapshot surface -> YppTrackerViewModel -> drawer, replaced by an honest deep-link row ('Channel standing isn't exposed to YouTube apps — check the Earn page'). YppSnapshot standing columns stay (schema-stable, always false). channels.list failures now log the response BODY — the bare code could not name insufficientPermissions, which is what made this undiagnosable. Root cause #2 (found by the new Good Dog, masked by the 403): statistics come back as JSON STRINGS ('350'); raw GetInt64() throws. Tolerant ReadInt64 (ValueKind-first; JsonElement.TryGetInt64 THROWS on strings — type-in, not try-type). Good Dog: ChannelStatsServiceTests.CaptureCurrent_RequestsNoAuditDetails_AndStillParsesTheSnapshot (URL asserts no auditDetails + snapshot parses); YppPullOutTests fixture updated. Recipes for both 403/scope and statistics-strings entered in MyMistakes.md. Also shipped in the same commit (shared PreviewPane.xaml + ai.md): the audio-sync status dot removal from the #77 feedback round (creator: 'what is the point of the status light? Lose it') — IntToSyncBrushConverter deleted with it. verify.sh gate: 0 warnings, 316/316 pass, scope-check clean.
This commit is contained in:
@@ -15,6 +15,35 @@
|
||||
|
||||
## 🔬 Recipes registry
|
||||
|
||||
### YOUTUBE STATISTICS ARE JSON STRINGS; TryGetInt64 THROWS ON STRINGS (RECIPE)
|
||||
|
||||
YouTube Data API v3 returns `statistics.subscriberCount / viewCount / videoCount` as
|
||||
JSON **strings** (`"350"`), not numbers. (2026-09-23: the YPP parse bug surfaced the
|
||||
moment the auditDetails 403 stopped masking it.) Fix = a tolerant read that checks
|
||||
`ValueKind` FIRST, then `TryGetInt64` for `Number`, then `long.TryParse(GetString())`
|
||||
for `String`. Trap within the fix: **`JsonElement.TryGetInt64` THROWS
|
||||
`InvalidOperationException` on any non-Number token** ("requires an element of type
|
||||
'Number'") — it is try-type-in, not try-catch. Guard on `value.ValueKind` before
|
||||
calling it; a leaked 403→parse chain means your "whole request failed" symptom can
|
||||
paper over a second crash that only appears once the 403 is fixed (test the full
|
||||
happy path, not just the error path).
|
||||
|
||||
### CHANNELS.LIST auditDetails PART 403s THE WHOLE REQUEST WITHOUT A PARTNER SCOPE (RECIPE)
|
||||
|
||||
YouTube Data API v3 `channels.list` rejects the ENTIRE request with
|
||||
`403 insufficientPermissions` if your `part=` list includes `auditDetails` but the
|
||||
token lacks `https://www.googleapis.com/auth/youtubepartner-channel-audit` — the
|
||||
docs' exact words: "A request that retrieves the auditDetails part for a channel
|
||||
resource must provide an authorization token that contains the
|
||||
youtubepartner-channel-audit scope". That scope is MCN content-partner tooling
|
||||
(with a two-week token-revocation rule); normal-creator apps should NEVER ask for
|
||||
it. 2026-09-23 real-log evidence: YPP refresh 403'd three times in a row while the
|
||||
mock-fake tests stayed green ("current scopes suffice, no re-consent" was wrong).
|
||||
Fixes: (1) drop `auditDetails` from `part=`; (2) log the response BODY — the bare
|
||||
status code could not name `insufficientPermissions`, which is what made this
|
||||
failure undiagnosable for days; (3) when a feature needs data no ordinary scope
|
||||
grants, deep-link to the site instead of requesting the partner privilege.
|
||||
|
||||
### TRANSITION(COMPLETE) RACES AUTOSTOP: PRE-FLIGHT lifeCycleStatus (RECIPE)
|
||||
|
||||
A blind `liveBroadcasts.transition?broadcastStatus=complete` POST can 403
|
||||
|
||||
Reference in New Issue
Block a user