fix(ypp): refresh 403'd on every real call — drop the auditDetails part (needs a partner scope)

Creator: 'when I attempt to refresh my YPP page, I get an error about not being
able to reach YouTube. Seriously?' Real log: channels.list failed (403) x3.

Root cause #1 (the 403): channels.list?mine=true&part=statistics,auditDetails,
contentDetails returns 403 insufficientPermissions when the token lacks the
youtubepartner-channel-audit scope — which the auditDetails part ALONE requires,
per the docs ('A request that retrieves the auditDetails part ... must provide an
authorization token that contains the youtubepartner-channel-audit scope'). That
scope is MCN partner tooling with a 2-week token-revocation rule; the app must not
hold it. TASK-39's 'current scopes suffice, no re-consent' slice-1 claim was wrong
for this part; mock-fake tests never touched the real API, so it shipped green and
403'd every refresh since 2026-09-22.
https://developers.google.com/youtube/v3/docs/channels/list

Fix: part=statistics,contentDetails only; standing flags removed from
ChannelStatsService -> YppStatSnapshot surface -> YppTrackerViewModel -> drawer,
replaced by an honest deep-link row ('Channel standing isn't exposed to YouTube
apps — check the Earn page'). YppSnapshot standing columns stay (schema-stable,
always false). channels.list failures now log the response BODY — the bare code
could not name insufficientPermissions, which is what made this undiagnosable.

Root cause #2 (found by the new Good Dog, masked by the 403): statistics come back
as JSON STRINGS ('350'); raw GetInt64() throws. Tolerant ReadInt64 (ValueKind-first;
JsonElement.TryGetInt64 THROWS on strings — type-in, not try-type).

Good Dog: ChannelStatsServiceTests.CaptureCurrent_RequestsNoAuditDetails_AndStillParsesTheSnapshot
(URL asserts no auditDetails + snapshot parses); YppPullOutTests fixture updated.
Recipes for both 403/scope and statistics-strings entered in MyMistakes.md.

Also shipped in the same commit (shared PreviewPane.xaml + ai.md): the audio-sync
status dot removal from the #77 feedback round (creator: 'what is the point of the
status light? Lose it') — IntToSyncBrushConverter deleted with it.

verify.sh gate: 0 warnings, 316/316 pass, scope-check clean.
This commit is contained in:
2026-09-23 16:45:56 -07:00
parent d72949e2f9
commit cb750660c3
13 changed files with 284 additions and 176 deletions
+2 -2
View File
@@ -9,7 +9,7 @@
1. ☑ `AudioSyncOffsetMs` on `MainViewModel` (global, default 0, range 0..500 ms) — positive-only: OBS's documented fix delays the audio so it lands on video when it runs ahead; advancing audio would need a video-side delay (out of the audio layer's scope, v1.1+).
2. ☑ Applied in `AudioMixer` — post-mix interleaved-stereo delay via the pure `AudioSyncDelay` line (`Services/Audio/AudioSyncDelay.cs`), fed through a `Func<int> syncOffsetMs` seam each mix tick.
3. ☑ UI: compact "SYNC" slider (0..500) on the mic bar with a status dot (green = no-op, amber = offset set) via `IntToSyncBrushConverter`. **Provenance (recorded 2026-09-01 after a creator "I never ordered this" scare): the creator explicitly asked for OBS's delay-filter lip-sync fix BUILT NATIVELY — the feature is his, not AI drift. Its placement (preview-rail vs mic-settings/gear) remains an open design question; do not remove the capability.**
3. ☑ UI: compact "SYNC" slider (0..500) on the mic bar. **The status dot (green = no-op, amber = offset set) was REMOVED 2026-09-23 (creator, live-launch feedback: "what is the point of the status light? Lose it") — the slider's position + the numeric tooltip carry the state, and `IntToSyncBrushConverter` was deleted with it.** **Provenance (recorded 2026-09-01 after a creator "I never ordered this" scare): the creator explicitly asked for OBS's delay-filter lip-sync fix BUILT NATIVELY — the feature is his, not AI drift. Its placement (preview-rail vs mic-settings/gear) remains an open design question; do not remove the capability.**
4. ☑ Persisted in `LayoutStore.Settings` (`Audio.SyncOffsetMs`) via `LoadAudioSyncOffsetMs`/`SaveAudioSyncOffsetMs`; saved from `SaveLayoutNow`.
5. ☑ Tests: `AudioSyncDelayTests` — zero-delay identity, negative→0 clamp, >500 ms clamp to 500 ms, and 10 ms → 960 interleaved-sample shift.
6. ⚠ **Post-ship regression (found 2026-09-01, first real launch):** this task's sync-delay line `_delayedMix` was declared nullable and never initialized — the first `delayed.Length` deref NRE'd EVERY live-mix tick, silently killing all live/record audio, hanging `AudioPipelineTests`, and being mislabeled a "known failure". Fixed in the recording-verification pass (init + null-check + throttled loop errors logged with stack); `AudioPipelineTests` 25/25 green afterward. Lesson recorded in MyMistakes.
@@ -33,7 +33,7 @@
> webcams). Regression test: `StartLive_NegativeOffset_AdvancesAudio_ByDroppingTheStreamHead`.
- **Positive-only (delay audio)** — the physically-correct direction (audio runs ahead of the video). True "advance" needs a video-side delay and is PERMANENTLY OUT with per-source sync (TASKS.md → "Out of product" — v1.x phrasing retired 2026-09-01).
- **Simple slider** — 0 to +500 ms, default 0. No numeric input needed.
- **Visual feedback** — "sync OK" status dot shows when an offset is dialled in.
- ~~**Visual feedback** — "sync OK" status dot when an offset is dialled in.~~ **RETIRED 2026-09-23 by creator** — the status light added nothing (see item 3); the numeric tooltip already states the offset.
### ❗ REQUIRED before 1.0 (creator directive 2026-09-14)
+33 -8
View File
@@ -24,10 +24,34 @@ from day one.
- No public API exposes the Earn-tab counters or the "valid public" filtering. Numbers are
**API-derived and labeled close-to-but-not-identical to Studio**.
- **2FA and AdSense linkage are not readable from ANY YouTube API** → in-app self-reported
checkboxes with deep links (Google's 2-Step page / the Earn page). Standing IS readable from
`channels.list auditDetails` (overall + the three sub-flags) — live, no re-consent.
checkboxes with deep links (Google's 2-Step page / the Earn page).
- **Channel standing is NOT readable by ordinary apps either** — see the scope correction below;
the slice-1 claim that `channels.list auditDetails` gave it "no re-consent" was WRONG and
silently 403'd every real refresh until 2026-09-23.
- `subscriberCount` is rounded to 3 significant figures by Google.
## ⚠️ Scope correction (2026-09-23, creator: "YPP refresh — can't reach YouTube. Seriously?")
The refresh 403'd on EVERY real call since slice 1 shipped: `channels.list?mine=true
&part=statistics,auditDetails,contentDetails` returns `403 insufficientPermissions` because the
**`auditDetails` part alone requires the `youtubepartner-channel-audit` scope** — which no
ordinary-creator app should hold (it's the MCN content-partner audit privilege, and the token has
a two-week-revocation rule attached). The mock-based test passed; the real API never did.
Reference: https://developers.google.com/youtube/v3/docs/channels/list ("A request that retrieves
the auditDetails part … must provide … youtubepartner-channel-audit").
**Fix:** dropped `auditDetails` from the part list (now `statistics,contentDetails`); standing
flags removed from the snapshot → VM → drawer, replaced by an honest deep-link row ("Channel
standing isn't exposed to YouTube apps — check the Earn page"). The standing columns in the
`YppSnapshot` SQLite table stay (schema-stable; always false for the new API path). `channels.list`
failures now log the response body, so the DIAGNOSIS that cost this hunt (bare status code, no
reason) can't hide again. New Good Dog: `ChannelStatsServiceTests.CaptureCurrent_RequestsNoAuditDetails_
AndStillParsesTheSnapshot` — guards the URL never carries auditDetails and the snapshot still parses.
The same Good Dog then caught a SECOND latent bug the 403 had masked: **`statistics.*` comes back as
JSON strings** (subscriberCount `"350"`), and the raw `GetInt64()` read throws — now via the
tolerant `ReadInt64` (ValueKind-first; `JsonElement.TryGetInt64` throws on strings). Recipe in
MyMistakes.
## What shipped
- `Models/YppThresholds.cs` — thresholds as **versioned date-aware data** (never constants, per
@@ -37,13 +61,14 @@ from day one.
(`YppSnapshot` table): append-only snapshot history; manual checklist (`Ypp.TwoFactorEnabled` /
`Ypp.AdSenseLinked`); last-refresh-UTC gate (the once-daily gate a quota-thin analytics slice
will need is baked in now).
- `Services/ChannelStatsService.cs` — `channels.list?mine=true&part=statistics,auditDetails,
contentDetails` (subs/views/videos + uploads-playlist id + standing flags) then
`playlistItems.list` (recent 50) counts uploads in the trailing 90 days. Virtual
`CaptureCurrentAsync` = the test seam. No new scope.
- `Services/ChannelStatsService.cs` — `channels.list?mine=true&part=statistics,contentDetails`
(subs/views/videos + uploads-playlist id; **`auditDetails` REMOVED 2026-09-23**, see the scope
correction) then `playlistItems.list` (recent 50) counts uploads in the trailing 90 days.
Virtual `CaptureCurrentAsync` = the test seam. No new scope.
- `Services/YppTrackerViewModel.cs` — drawer state + `Toggle/CloseDrawerCommand` + `RefreshCommand`
(mirrors `LiveBroadcastFormViewModel`), plus: signed-out/loading/error states, tier progress
bars (subs Tier-1 & Tier-2, uploads), live standing checkbox + detail, manual 2FA/AdSense
bars (subs Tier-1 & Tier-2, uploads), standing info line (deep-link advice, honest about the
API gap since 2026-09-23) + manual 2FA/AdSense
checkboxes, `WhatCountsText` education, deep links, `EnsureLoadedAsync` (once/day gate) +
explicit refresh, `OnAccountChanged()` hook.
- `ViewModels/MainViewModel.Ypp.cs` + ctor — `Ypp` property, `ChannelStatsFactoryOverride` test
@@ -79,6 +104,6 @@ doc; the once-daily refresh gate and history table are already in place.
- [x] Clicking it slides out the YPP drawer; opening one drawer closes the other; outside-click
collapses whichever is open.
- [x] Signed out → "Sign in to YouTube…" hint. Signed in → subs (Tier 1 & Tier 2), uploads/90d,
live standing, manual 2FA/AdSense, education text, refresh + last-updated.
standing-guidance row, manual 2FA/AdSense, education text, refresh + last-updated.
- [x] Every refresh appends a snapshot to SQLite (history ready for slice 2).
- [x] 0 warnings / 0 errors; **313/313 tests pass** (one new Good Dog integration test).