fix(ypp): refresh 403'd on every real call — drop the auditDetails part (needs a partner scope)

Creator: 'when I attempt to refresh my YPP page, I get an error about not being
able to reach YouTube. Seriously?' Real log: channels.list failed (403) x3.

Root cause #1 (the 403): channels.list?mine=true&part=statistics,auditDetails,
contentDetails returns 403 insufficientPermissions when the token lacks the
youtubepartner-channel-audit scope — which the auditDetails part ALONE requires,
per the docs ('A request that retrieves the auditDetails part ... must provide an
authorization token that contains the youtubepartner-channel-audit scope'). That
scope is MCN partner tooling with a 2-week token-revocation rule; the app must not
hold it. TASK-39's 'current scopes suffice, no re-consent' slice-1 claim was wrong
for this part; mock-fake tests never touched the real API, so it shipped green and
403'd every refresh since 2026-09-22.
https://developers.google.com/youtube/v3/docs/channels/list

Fix: part=statistics,contentDetails only; standing flags removed from
ChannelStatsService -> YppStatSnapshot surface -> YppTrackerViewModel -> drawer,
replaced by an honest deep-link row ('Channel standing isn't exposed to YouTube
apps — check the Earn page'). YppSnapshot standing columns stay (schema-stable,
always false). channels.list failures now log the response BODY — the bare code
could not name insufficientPermissions, which is what made this undiagnosable.

Root cause #2 (found by the new Good Dog, masked by the 403): statistics come back
as JSON STRINGS ('350'); raw GetInt64() throws. Tolerant ReadInt64 (ValueKind-first;
JsonElement.TryGetInt64 THROWS on strings — type-in, not try-type).

Good Dog: ChannelStatsServiceTests.CaptureCurrent_RequestsNoAuditDetails_AndStillParsesTheSnapshot
(URL asserts no auditDetails + snapshot parses); YppPullOutTests fixture updated.
Recipes for both 403/scope and statistics-strings entered in MyMistakes.md.

Also shipped in the same commit (shared PreviewPane.xaml + ai.md): the audio-sync
status dot removal from the #77 feedback round (creator: 'what is the point of the
status light? Lose it') — IntToSyncBrushConverter deleted with it.

verify.sh gate: 0 warnings, 316/316 pass, scope-check clean.
This commit is contained in:
2026-09-23 16:45:56 -07:00
parent d72949e2f9
commit cb750660c3
13 changed files with 284 additions and 176 deletions
+30 -17
View File
@@ -7,11 +7,16 @@ namespace ytLive.Services;
/// <summary>
/// Pulls a connected channel's YPP-relevant numbers from the YouTube Data API
/// (TASK 39, slice 1 — the current OAuth scopes suffice, no re-consent):
/// subscriptions/views/videos + audit standing via channels.list, and the count
/// of public uploads in the trailing 90 days via playlistItems.list on the
/// (TASK 39, slice 1): subscriptions/views/videos via channels.list, and the
/// count of public uploads in the trailing 90 days via playlistItems.list on the
/// uploads playlist. Long-form watch hours and Shorts-feed views need the
/// Analytics API (a later slice behind the IChannelStatsProvider seam).
///
/// NOTE (root cause, 2026-09-23): channels.list must NOT request the
/// `auditDetails` part — that part alone requires the
/// `youtubepartner-channel-audit` scope the app doesn't (and mustn't) hold, and
/// the whole request 403s `insufficientPermissions` over it. Standing flags are
/// not exposed to ordinary apps; the drawer deep-links to YouTube Studio instead.
/// </summary>
public class ChannelStatsService
{
@@ -42,10 +47,14 @@ public class ChannelStatsService
_http.DefaultRequestHeaders.Authorization = new("Bearer", _auth.CurrentChannel!.AccessToken);
var response = await _http.GetAsync(
$"{ApiBase}/channels?mine=true&part=statistics,auditDetails,contentDetails");
$"{ApiBase}/channels?mine=true&part=statistics,contentDetails");
if (!response.IsSuccessStatusCode)
{
AppLog.Write($"YPP stats: channels.list failed ({(int)response.StatusCode})");
// Log the response body: YouTube's error.reason names the failure
// (insufficientPermissions / quotaExceeded / …) — the bare code was
// undiagnosable for the 2026-09-23 auditDetails 403.
var errorBody = await response.Content.ReadAsStringAsync();
AppLog.Write($"YPP stats: channels.list failed ({(int)response.StatusCode}): {errorBody}");
return null;
}
@@ -69,17 +78,26 @@ public class ChannelStatsService
return new YppStatSnapshot
{
CapturedAtUtc = DateTime.UtcNow,
SubscriberCount = statistics.TryGetProperty("subscriberCount", out var subs) ? subs.GetInt64() : 0,
VideoCount = statistics.TryGetProperty("videoCount", out var videos) ? videos.GetInt64() : 0,
TotalViews = statistics.TryGetProperty("viewCount", out var views) ? views.GetInt64() : 0,
SubscriberCount = ReadInt64(statistics, "subscriberCount"),
VideoCount = ReadInt64(statistics, "videoCount"),
TotalViews = ReadInt64(statistics, "viewCount"),
UploadsLast90Days = uploadsLast90Days,
CommunityGuidelinesGoodStanding = ReadStandingFlag(channel, "communityGuidelinesGoodStanding"),
CopyrightStrikesGoodStanding = ReadStandingFlag(channel, "copyrightStrikesGoodStanding"),
ContentIdClaimsGoodStanding = ReadStandingFlag(channel, "contentIdClaimsGoodStanding"),
OverallGoodStanding = ReadStandingFlag(channel, "overallGoodStanding"),
};
}
/// <summary>YouTube serializes statistics as JSON STRINGS ("350"); a tolerant
/// read that also accepts a number (the real 403 hid this parse bug until the
/// auditDetails removal surfaced the string shape in 2026-09-23's Good Dog).
/// NOTE: JsonElement.TryGetInt64 THROWS on a non-Number token — ValueKind must
/// be checked first (try-type-in, not try-catch).</summary>
private static long ReadInt64(JsonElement parent, string name)
{
if (!parent.TryGetProperty(name, out var value)) return 0;
if (value.ValueKind == JsonValueKind.Number && value.TryGetInt64(out var n)) return n;
if (value.ValueKind == JsonValueKind.String && long.TryParse(value.GetString(), out n)) return n;
return 0;
}
/// <summary>Counts uploads published within the trailing 90 days, scanning the
/// most recent 50 from the uploads playlist (generous beyond the 3/90-day YPP
/// requirement; the YPP tab labels it as the recent-50 window).</summary>
@@ -111,9 +129,4 @@ public class ChannelStatsService
}
return count;
}
private static bool ReadStandingFlag(JsonElement channel, string property)
=> channel.TryGetProperty("auditDetails", out var audit)
&& audit.TryGetProperty(property, out var flag)
&& flag.GetBoolean();
}
+7 -28
View File
@@ -9,10 +9,11 @@ namespace ytLive.Services;
/// Backing VM for the YPP pull-out (the "YPP" tab below Stream Settings on the
/// Live screen's right edge). Shows the connected channel's current position
/// toward the YPP tier thresholds (subscribers + 90-day uploads via the Data
/// API), a compliance checklist (live standing from auditDetails + self-reported
/// 2FA/AdSense), and the "what counts" education the creator would otherwise
/// have to leave the app to find. Snapshots are appended to SQLite on every
/// refresh so a later analytics slice can compute velocity/ETA from history.
/// API), a compliance checklist (2FA/AdSense self-reported — channel standing is
/// NOT exposed to ordinary apps, so the drawer deep-links to the Earn page for it)
/// and the "what counts" education the creator would otherwise have to leave the
/// app to find. Snapshots are appended to SQLite on every refresh so a later
/// analytics slice can compute velocity/ETA from history.
/// Drawer open/close lives here (mirrors LiveBroadcastFormViewModel).
/// </summary>
public sealed class YppTrackerViewModel : ViewModelBase
@@ -33,10 +34,6 @@ public sealed class YppTrackerViewModel : ViewModelBase
private long _videoCount;
private long _totalViews;
private int _uploadsLast90Days;
private bool _communityGuidelinesGoodStanding;
private bool _copyrightStrikesGoodStanding;
private bool _contentIdClaimsGoodStanding;
private bool _overallGoodStanding;
private bool _hasSnapshot;
private bool _twoFactorEnabled;
private bool _adsenseLinked;
@@ -109,10 +106,6 @@ public sealed class YppTrackerViewModel : ViewModelBase
public long VideoCount => _videoCount;
public long TotalViews => _totalViews;
public int UploadsLast90Days => _uploadsLast90Days;
public bool CommunityGuidelinesGoodStanding => _communityGuidelinesGoodStanding;
public bool CopyrightStrikesGoodStanding => _copyrightStrikesGoodStanding;
public bool ContentIdClaimsGoodStanding => _contentIdClaimsGoodStanding;
public bool OverallGoodStanding => _overallGoodStanding;
/// <summary>True once a snapshot has successfully captured at least once this
/// session (drives the standing detail text's "sign in to load" state).</summary>
@@ -158,14 +151,8 @@ public sealed class YppTrackerViewModel : ViewModelBase
{
get
{
if (!HasSnapshot) return "Sign in to load your channel's standing from YouTube.";
var flags = new System.Collections.Generic.List<string>();
if (!CommunityGuidelinesGoodStanding) flags.Add("a community-guidelines flag");
if (!CopyrightStrikesGoodStanding) flags.Add("a copyright strike");
if (!ContentIdClaimsGoodStanding) flags.Add("a content-ID claim");
return flags.Count == 0
? "Good standing — no live flags."
: $"FLAGGED ({string.Join(", ", flags)}). Check YouTube Studio for details.";
if (!HasSnapshot) return "Sign in to load your channel's progress from YouTube.";
return "Channel standing isn't exposed to YouTube apps — check the Earn page for your live status.";
}
}
@@ -263,10 +250,6 @@ public sealed class YppTrackerViewModel : ViewModelBase
_videoCount = snapshot.VideoCount;
_totalViews = snapshot.TotalViews;
_uploadsLast90Days = snapshot.UploadsLast90Days;
_communityGuidelinesGoodStanding = snapshot.CommunityGuidelinesGoodStanding;
_copyrightStrikesGoodStanding = snapshot.CopyrightStrikesGoodStanding;
_contentIdClaimsGoodStanding = snapshot.ContentIdClaimsGoodStanding;
_overallGoodStanding = snapshot.OverallGoodStanding;
_hasSnapshot = true;
OnPropertyChanged(nameof(DisplayName));
@@ -274,10 +257,6 @@ public sealed class YppTrackerViewModel : ViewModelBase
OnPropertyChanged(nameof(VideoCount));
OnPropertyChanged(nameof(TotalViews));
OnPropertyChanged(nameof(UploadsLast90Days));
OnPropertyChanged(nameof(CommunityGuidelinesGoodStanding));
OnPropertyChanged(nameof(CopyrightStrikesGoodStanding));
OnPropertyChanged(nameof(ContentIdClaimsGoodStanding));
OnPropertyChanged(nameof(OverallGoodStanding));
OnPropertyChanged(nameof(HasSnapshot));
OnPropertyChanged(nameof(Tier1SubsProgress));
OnPropertyChanged(nameof(Tier2SubsProgress));