fix(ypp): refresh 403'd on every real call — drop the auditDetails part (needs a partner scope)
Creator: 'when I attempt to refresh my YPP page, I get an error about not being able to reach YouTube. Seriously?' Real log: channels.list failed (403) x3. Root cause #1 (the 403): channels.list?mine=true&part=statistics,auditDetails, contentDetails returns 403 insufficientPermissions when the token lacks the youtubepartner-channel-audit scope — which the auditDetails part ALONE requires, per the docs ('A request that retrieves the auditDetails part ... must provide an authorization token that contains the youtubepartner-channel-audit scope'). That scope is MCN partner tooling with a 2-week token-revocation rule; the app must not hold it. TASK-39's 'current scopes suffice, no re-consent' slice-1 claim was wrong for this part; mock-fake tests never touched the real API, so it shipped green and 403'd every refresh since 2026-09-22. https://developers.google.com/youtube/v3/docs/channels/list Fix: part=statistics,contentDetails only; standing flags removed from ChannelStatsService -> YppStatSnapshot surface -> YppTrackerViewModel -> drawer, replaced by an honest deep-link row ('Channel standing isn't exposed to YouTube apps — check the Earn page'). YppSnapshot standing columns stay (schema-stable, always false). channels.list failures now log the response BODY — the bare code could not name insufficientPermissions, which is what made this undiagnosable. Root cause #2 (found by the new Good Dog, masked by the 403): statistics come back as JSON STRINGS ('350'); raw GetInt64() throws. Tolerant ReadInt64 (ValueKind-first; JsonElement.TryGetInt64 THROWS on strings — type-in, not try-type). Good Dog: ChannelStatsServiceTests.CaptureCurrent_RequestsNoAuditDetails_AndStillParsesTheSnapshot (URL asserts no auditDetails + snapshot parses); YppPullOutTests fixture updated. Recipes for both 403/scope and statistics-strings entered in MyMistakes.md. Also shipped in the same commit (shared PreviewPane.xaml + ai.md): the audio-sync status dot removal from the #77 feedback round (creator: 'what is the point of the status light? Lose it') — IntToSyncBrushConverter deleted with it. verify.sh gate: 0 warnings, 316/316 pass, scope-check clean.
This commit is contained in:
@@ -0,0 +1,84 @@
|
||||
using System;
|
||||
using System.Net;
|
||||
using System.Text;
|
||||
using System.Threading.Tasks;
|
||||
using Xunit;
|
||||
using ytLive.Services;
|
||||
|
||||
namespace ytLive.Tests;
|
||||
|
||||
/// <summary>
|
||||
/// TASK 39 root-cause guard (2026-09-23): the YPP refresh's channels.list call
|
||||
/// must NOT request the `auditDetails` part — that part alone requires the
|
||||
/// `youtubepartner-channel-audit` scope the app doesn't (and mustn't) hold, and
|
||||
/// the whole request 403s `insufficientPermissions` over it (this exact failure
|
||||
/// sat in the real logs for weeks). One integration test: the snapshot still
|
||||
/// parses subscribers/views/videos/uploads from `statistics,contentDetails`, and
|
||||
/// the URL never mentions auditDetails.
|
||||
/// </summary>
|
||||
public class ChannelStatsServiceTests
|
||||
{
|
||||
private sealed class RecordingHandler : HttpMessageHandler
|
||||
{
|
||||
public string? LastBody;
|
||||
public Func<HttpRequestMessage, string?>? ResponseSelector;
|
||||
public readonly System.Collections.Generic.List<string> Requests = new();
|
||||
|
||||
protected override Task<HttpResponseMessage> SendAsync(
|
||||
HttpRequestMessage request, CancellationToken cancellationToken)
|
||||
{
|
||||
Requests.Add($"{request.Method.Method} {request.RequestUri}");
|
||||
LastBody = request.Content?.ReadAsStringAsync().GetAwaiter().GetResult();
|
||||
return Task.FromResult(new HttpResponseMessage(HttpStatusCode.OK)
|
||||
{
|
||||
Content = new StringContent(
|
||||
ResponseSelector?.Invoke(request) ?? "{}", Encoding.UTF8, "application/json"),
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task CaptureCurrent_RequestsNoAuditDetails_AndStillParsesTheSnapshot()
|
||||
{
|
||||
var auth = new YouTubeAuthService("test-client", "test-secret");
|
||||
auth.SetSession(new Models.YouTubeChannel
|
||||
{
|
||||
AccessToken = "acc-123",
|
||||
TokenExpiry = DateTime.UtcNow.AddHours(1),
|
||||
});
|
||||
|
||||
var handler = new RecordingHandler
|
||||
{
|
||||
ResponseSelector = request =>
|
||||
request.RequestUri!.ToString().Contains("channels")
|
||||
? """
|
||||
{"items":[{"id":"UC-1","statistics":{"subscriberCount":"350","viewCount":"12345","videoCount":"42"},
|
||||
"contentDetails":{"relatedPlaylists":{"uploads":"UPL"}}}]}
|
||||
"""
|
||||
: """
|
||||
{"items":[
|
||||
{"snippet":{"publishedAt":"2026-08-01T00:00:00Z"}},
|
||||
{"snippet":{"publishedAt":"2026-09-01T00:00:00Z"}},
|
||||
{"snippet":{"publishedAt":"2025-01-01T00:00:00Z"}}
|
||||
]}
|
||||
""",
|
||||
};
|
||||
|
||||
var service = new ChannelStatsService(auth, new System.Net.Http.HttpClient(handler));
|
||||
var snapshot = await service.CaptureCurrentAsync();
|
||||
|
||||
Assert.NotNull(snapshot);
|
||||
Assert.Equal(2, handler.Requests.Count);
|
||||
Assert.StartsWith("GET ", handler.Requests[0]);
|
||||
Assert.Contains("channels?mine=true", handler.Requests[0]);
|
||||
Assert.Contains("part=statistics,contentDetails", handler.Requests[0]);
|
||||
Assert.DoesNotContain("auditDetails", handler.Requests[0]);
|
||||
Assert.Contains("playlistItems", handler.Requests[1]);
|
||||
|
||||
Assert.Equal(350, snapshot!.SubscriberCount);
|
||||
Assert.Equal(42, snapshot.VideoCount);
|
||||
Assert.Equal(12_345, snapshot.TotalViews);
|
||||
Assert.Equal(2, snapshot.UploadsLast90Days);
|
||||
Assert.False(DateTime.UtcNow - snapshot.CapturedAtUtc > TimeSpan.FromMinutes(1));
|
||||
}
|
||||
}
|
||||
@@ -61,10 +61,6 @@ public sealed class YppPullOutTests
|
||||
VideoCount = 42,
|
||||
TotalViews = 12_345,
|
||||
UploadsLast90Days = 2,
|
||||
CommunityGuidelinesGoodStanding = true,
|
||||
CopyrightStrikesGoodStanding = true,
|
||||
ContentIdClaimsGoodStanding = true,
|
||||
OverallGoodStanding = true,
|
||||
};
|
||||
|
||||
var vm = new YppTrackerViewModel(
|
||||
@@ -81,7 +77,6 @@ public sealed class YppPullOutTests
|
||||
Assert.True(vm.HasSnapshot);
|
||||
Assert.Equal(350, vm.SubscriberCount);
|
||||
Assert.Equal(2, vm.UploadsLast90Days);
|
||||
Assert.True(vm.OverallGoodStanding);
|
||||
Assert.Equal("Test Channel", vm.DisplayName);
|
||||
Assert.Equal("350 / 500", vm.Tier1SubsText);
|
||||
Assert.Equal("350 / 1,000", vm.Tier2SubsText);
|
||||
|
||||
Reference in New Issue
Block a user