Files
mesh-catalog/modules/ombi/client.ts
T
jschoubben d289e5a928 modules: wire tool-runtime app credentials as own-secrets
The six modules that run a mesh-<mod> tool-runtime sidecar read an app
credential from an env var the manifest never provided, so the sidecar
crash-looped in the whole-mesh dry-run (e.g. "no Plex token — set
MESH_PLEX_TOKEN"). These are operator-set app secrets, so deliver them the
same way cloudflare-dns delivers its API token: an own-secret file mounted
read-only, with a MESH_<APP>_*_FILE env pointing at the mount, and the
runtime code preferring that file (falling back to the existing env so
nothing regresses).

- plex: own-secret token -> /run/secrets/token, MESH_PLEX_TOKEN_FILE
- bazarr: own-secret api-key -> /run/secrets/api-key, MESH_BAZARR_API_KEY_FILE
- ombi: own-secret api-key -> /run/secrets/api-key, MESH_OMBI_API_KEY_FILE
- home-assistant: own-secret token -> /run/secrets/token, MESH_HOMEASSISTANT_TOKEN_FILE
- nzbget: own-secret password -> /run/secrets/password, MESH_NZBGET_PASSWORD_FILE (URL stays plain env)
- qbittorrent: own-secret password -> /run/secrets/password, MESH_QBITTORRENT_PASSWORD_FILE (URL stays plain env)

The operator now completes each with `secret accept <node> <module> <name> --from <file>`.
tsc passes for all six.
2026-09-08 18:40:23 +02:00

123 lines
4.7 KiB
TypeScript

// The Ombi API client — ombi's own code, living in the module (novox/hq ADR 0039). Ombi is the
// request front-end: viewers ask for movies and shows, and an operator approves them. This client
// talks its /api/v1 REST API (keyed by an ApiKey header); ombi's tools and events import it.
import { readFileSync } from "node:fs";
export interface OmbiRequest {
kind: "movie" | "tv";
id: number;
title: string;
requestedBy?: string;
requestedDate?: string;
approved: boolean;
available: boolean;
denied: boolean;
tmdbId?: number;
}
export interface RequestCounts {
pending: number;
approved: number;
available: number;
}
/** The settings-merged config the mesh delivers (novox/hq ADR 0046): { url, apiKey, token, password, user, ... }. */
function meshConfig(file?: string): Record<string, string> {
if (!file) return {};
try { return JSON.parse(readFileSync(file, "utf8")) as Record<string, string>; }
catch { return {}; }
}
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
* absent or unreadable yields undefined so callers fall back rather than crash. */
function readSecret(file?: string): string | undefined {
if (!file) return undefined;
try { return readFileSync(file, "utf8").trim(); }
catch { return undefined; }
}
export class OmbiClient {
readonly baseUrl: string;
constructor(
url: string,
private readonly apiKey: string,
) {
this.baseUrl = url.replace(/\/$/, "");
}
/** Build from the module's resolved environment. Ombi's API is keyed; without URL and key there
* is nothing to talk to, so this throws rather than run half-configured. */
static fromEnv(env: NodeJS.ProcessEnv = process.env): OmbiClient {
const cfg = meshConfig(env.MESH_OMBI_CONFIG_FILE);
const url = cfg.url ?? env.MESH_OMBI_URL;
const apiKey = cfg.apiKey ?? readSecret(env.MESH_OMBI_API_KEY_FILE) ?? env.MESH_OMBI_API_KEY;
if (!url) throw new Error("no Ombi URL — set MESH_OMBI_URL");
if (!apiKey) throw new Error("no Ombi API key — set MESH_OMBI_API_KEY");
return new OmbiClient(url, apiKey);
}
private async request(method: string, path: string, body?: unknown): Promise<any> {
const res = await fetch(`${this.baseUrl}/api/v1${path}`, {
method,
headers: {
ApiKey: this.apiKey,
Accept: "application/json",
...(body !== undefined ? { "Content-Type": "application/json" } : {}),
},
body: body !== undefined ? JSON.stringify(body) : undefined,
});
if (!res.ok) throw new Error(`Ombi API ${method} ${path}: ${res.status} ${await res.text()}`);
const text = await res.text();
return text ? JSON.parse(text) : {};
}
/** All requests, movies and TV together — who asked for what, and where each stands. */
async getRequests(): Promise<OmbiRequest[]> {
const [movies, tv] = await Promise.all([
this.request("GET", "/Request/movie"),
this.request("GET", "/Request/tv"),
]);
const films: OmbiRequest[] = (Array.isArray(movies) ? movies : []).map((r: any) => ({
kind: "movie" as const,
id: r.id,
title: r.title ?? "Unknown",
requestedBy: r.requestedUser?.userName ?? r.requestedUser?.userAlias,
requestedDate: r.requestedDate,
approved: Boolean(r.approved),
available: Boolean(r.available),
denied: Boolean(r.denied),
tmdbId: r.theMovieDbId,
}));
// TV requests carry per-season child requests; the top-level record is approved when all its
// children are, which is the grain an operator acts on.
const shows: OmbiRequest[] = (Array.isArray(tv) ? tv : []).map((r: any) => {
const children: any[] = r.childRequests ?? [];
return {
kind: "tv" as const,
id: r.id,
title: r.title ?? "Unknown",
requestedBy: children[0]?.requestedUser?.userName,
requestedDate: children[0]?.requestedDate,
approved: children.length > 0 && children.every((c) => c.approved),
available: children.length > 0 && children.every((c) => c.available),
denied: children.some((c) => c.denied),
tmdbId: r.theMovieDbId,
};
});
return [...films, ...shows];
}
/** Live pending/approved/available counts — a one-line health read without listing everything. */
async getCounts(): Promise<RequestCounts> {
const c = await this.request("GET", "/Request/count");
return { pending: c.pending ?? 0, approved: c.approved ?? 0, available: c.available ?? 0 };
}
/** Approve a request. TV approval fans out to the request's child (per-season) requests. */
async approve(kind: "movie" | "tv", id: number): Promise<void> {
await this.request("POST", `/Request/${kind}/approve`, { id });
}
}