A pass over the whole app against the Ethos laws, then a focused pass on
Vibe with the operator reviewing each change.
Across the app:
- The player bar restores the last track it played, paused at zero, so a
fresh tab opens on where the listener was instead of "nothing playing".
- Track titles link to their album, matching the artist links beside them.
Playback stays on the artwork tile; a title that played was the surprise.
- The search field is bg-bg2. Tailwind cannot alpha-modify these var()
colors, so bg-surface0/70 emitted no rule at all and the input fell back
to the UA's white.
- Row hover is light falling off to the right, not a flat slab.
- The artwork placeholder can drop its note glyph, so TrackRow no longer
layers a play icon on top of one.
Vibe:
- A seeded Vibe plays its seed first. The seed sits in front of the durable
plan without being part of it, so the first advance consumes it locally
and reports no plan feedback.
- The queue drops a second recording of a song it already holds — same
title, different track id, which id-based dedup let through.
- Up next is read from the queue rather than the plan preview, since the
seed is not a plan item.
- The header carries the live profile (energy, discovery, goal) and both
verbs. Keep is gone: letting a track finish already reports `completed`,
which the director weighs the same.
- The aura is one warm diffuse blob in the page background, warm-hued only
and quieter on mobile.
- Compact artwork is 32px. It was h-8 w-8, which this remapped spacing
scale renders as 64px inside a 44px row, and that overflow was the
"stacked" look.
Verified by render at 1440x900 and 390x844, no horizontal overflow at
either. 26 frontend and 122 backend tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The isPlaying subscriber is unselected. Every store write during Vibe's
feedback/replan handshake called play() on the element that had just ended.
That replayed its final buffered milliseconds until the next source loaded.
Gate that subscriber and the seek subscriber on an actual value change, and
never resume a finished element.
Then close the gap the handshake leaves behind. The engine now drives two
<audio> elements. The next track buffers into the idle one 20s early. The
handover starts before `ended`, so the round-trip happens under the outgoing
tail. With a crossfade, that tail fades out under the new track. With crossfade
off, the new track waits in silence and starts the moment the tail ends.
Both are configurable under Settings -> Transitions and persist to
localStorage. Preload is on and crossfade is 400ms by default.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
next() did `queue.slice(idx + 1)`, so the current track was always
queue[0]. prev()'s `idx > 0` guard could therefore never pass after an
auto-advance — Previous did nothing, ever — and repeat: 'all' jumped to
queue[0], which is the track that just finished, looping the last track of
an album instead of restarting it.
Replaced with a currentIndex cursor; the queue is no longer trimmed behind
the playhead. The old slice did serve a purpose — bounding Vibe-prefetch
growth — so that is preserved as a MAX_HISTORY = 50 cap that drops the
oldest entries and re-bases the index, rather than dropped outright.
setQueue/playTrack/setCurrentTrack recompute the cursor, next()/prev() fall
back to findIndex if it drifts, and shuffle now picks by index so the
cursor stays valid.
Consumer audit: NowPlayingPanel and Vibe.tsx already derived position via
findIndex and needed no change. TrackRow.handlePlay did
`setQueue(queue.slice(index))`, which re-broke prev at the point of click
even with the store fixed; it now passes the intact queue.
This commit also includes a pre-existing uncommitted fix from the working
tree (not authored by Claude): the end-of-queue auto-resume loop, which
stops playback at the end of the queue instead of restarting. It is correct
and independent of the cursor bug, and is preserved verbatim here.
REVIEW-2026-07-30.md finding 7.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The entire admin surface of the SPA had been dead since auth landed
(5ed8d9e / 3bc9f2d). nginx.conf.template injected only
`Authorization: Bearer ${MUZICK_API_KEY}` for all of /api, docker-compose
passed only MUZICK_API_KEY to the frontend container, and app.ts requires
token === adminKey for /api/admin/*. The two keys differ, and
services/api.ts sets no headers of its own.
All 10 admin call sites were affected: the Jobs page polled 403s every
3s/5s forever and rendered a blank Overview with no error state, and every
Settings library action (Scan, Reindex, Reprocess artists, Re-enrich,
Duplicates merge) silently failed.
Three changes, each necessary:
- a `location /api/admin/` block injecting the admin key
- the Dockerfile envsubst list widened to include MUZICK_ADMIN_KEY,
without which the new variable substitutes to empty and the header
becomes a bare "Bearer"
- MUZICK_ADMIN_KEY passed to the frontend service in docker-compose
nginx selects the longest matching prefix regardless of block order;
verified empirically in a throwaway nginx:stable-alpine running the real
envsubst output against a stub that echoes $http_authorization:
/api/admin/queue-stats -> Bearer ADMINKEY456
/api/admin/duplicates/merge -> Bearer ADMINKEY456
/api/tracks -> Bearer APIKEY123
/api/health -> Bearer APIKEY123
All 10 call sites use /admin/... under the axios /api baseURL and none
request bare /api/admin without a trailing slash.
Also gives the Jobs page an error state: a banner that names a 401/403 as a
missing or wrong admin key, a Retry button, "Loading queue stats..." in
place of a blank Overview, and refetchInterval returning false once the
query has errored so it stops hammering a failing endpoint.
Deletes frontend/nginx.conf — unreferenced by the Dockerfile (confirmed by
grep) and the insecure variant of the template.
Worth noting and not addressed here: the outer LAN-only proxy already
forges credentials for everything reaching /api, so this key split buys no
real security while having cost the whole admin surface. Collapsing to one
key would be simpler.
REVIEW-2026-07-30.md finding 2.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>