Skip to content

Reject a wrong Client ID or Secret before the Spotify redirect - #74

Merged
Mincka merged 1 commit into
mainfrom
fix/73-reject-bad-credentials
Sep 19, 2026
Merged

Mincka merged 1 commit into
mainfrom
fix/73-reject-bad-credentials

Conversation

@Mincka

@Mincka Mincka commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Problem

Home Assistant stores application credentials outside the config entry and never validates them. A typo in the Client ID or Secret sends the user to Spotify's own INVALID_CLIENT page, the browser is never redirected back, and the flow sits on the external step until it times out. No config entry exists at that point, so there is nothing for a repair or a reauth to attach to, and reinstalling Spotcast does not bring the credentials form back because the bad pair stays in HA's store (#73).

Fix

  • async_step_auth now validates the stored pair with a client-credentials token request before generating the authorize URL. A 400 invalid_client answer aborts the flow with a new invalid_credentials message linking to the Application credentials panel (My Home Assistant redirect) and to the docs. Anything else (network error, 429, 5xx, odd payload) falls through so a Spotify hiccup never blocks setup. Reauth uses the same step, so a rotated secret is covered too.
  • The first setup screen links to the reset instructions.
  • New "Changing or resetting the application credentials" section in the configuration guide, with a README pointer and a changelog entry.
  • Translations updated in en/fr/de (placeholder parity test green).

Verification

  • Full unit suite: 822 tests green, pylint 10.00 on the handler.
  • The helper was probed against the real Spotify token endpoint: a bogus ID and a bogus secret both come back 400 invalid_client; an offline session is reported as not rejected.
  • Not exercised through a real HA config flow (no local HA container available).

Fixes #73

🤖 Generated with Claude Code

Home Assistant stores application credentials outside the config entry and
never validates them. A typo in the Client ID or Secret sent the user to
Spotify's own INVALID_CLIENT page, the browser was never redirected back,
and the flow sat on the external step until it timed out. Since no config
entry exists at that point there is nothing for a repair or a reauth to
attach to, and reinstalling Spotcast does not bring the credentials form
back because the bad pair stays in HA's store.

async_step_auth now asks Spotify to validate the stored pair with a
client-credentials token request before generating the authorize URL. A
400 invalid_client answer aborts the flow with a message that links to the
Application credentials panel (My Home Assistant redirect) and to a new
docs section on resetting them. Anything else (network error, 429, 5xx,
odd payload) falls through to the normal flow so a Spotify hiccup never
blocks setup. Reauth passes through the same step, so a rotated secret
is covered too.

The first setup screen gains a link to the reset instructions, the guide
gets a dedicated "Changing or resetting the application credentials"
section, and the README points at it.

Fixes #73

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Mincka
Mincka merged commit bf422c3 into main Sep 19, 2026
7 checks passed
@Mincka
Mincka deleted the fix/73-reject-bad-credentials branch September 19, 2026 06:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Entered the client ID wrong and cannot change it anymore

1 participant