GitShow/kentcdodds/mediarss
kentcdodds

mediarss

An RSS feed generator for media (audio/video).

by kentcdodds
Star on GitHubForknpm

TypeScript

45 stars8 forks6 contributorsActive · 5d agoSince 2025v4.1.1

Meet the team

See all 6 on GitHub →
kentcdodds
kentcdodds224 contributions
kody-bot
kody-bot36 contributions
devin-ai-integration[bot]Bot
devin-ai-integration[bot]3 contributions
cursoragent
cursoragent2 contributions
github-actions[bot]Bot
github-actions[bot]2 contributions
imgbot[bot]Bot
imgbot[bot]1 contribution

Languages

View on GitHub →
TypeScript99.2%
Shell0.5%
CSS0.2%
Dockerfile0.1%

Commit activity

Last 12 weeks · 29 commits

Full graph →

Community health

2 of 6 standards met

Community profile →
42
✓README○License○Contributing○Code of Conduct○Issue Template✓PR Template

Recent fixes

View closed PRs →
kentcdodds
fix(oauth): keep refresh tokens alive when Kody refreshes concurrentlyMergedPR

MediRSS was forcing a weekly MediRSS re-auth in Kody because overlapping refresh-token rotations were treated as theft and the whole token family was revoked. Root cause Access tokens last 1 hour. Refresh tokens rotate on every use, and any reuse revoked the family. That is correct for a stolen token replayed later. It is not correct for the client Kody actually is. Kody's MCP OAuth client is 1.30.0 ( depends on 0.22.0, which uses that SDK). has no single-flight lock around refresh. When the access token expires, two in-flight calls both POST the same refresh token. The loser receives . The SDK then calls , which deletes the stored refresh token. If the family was already revoked, the winner's replacement is dead too, so the next refresh fails the same way. The account card is written after that wipe, so storage no longer has a refresh token: That is Kody's recovery attempt id, not the saved server id. appends ( stamps a new attempt id when it parks the connection). The saved server is . shows for that server. Checked against the live request and ruled out as the cause of the missing refresh token: Client id includes . Redirect is . Live authorization-server metadata advertises . The live authorize URL sends and . The token endpoint ignores unknown form fields, including . A code exchange and a refresh that both send that resource still return a (new test). A grant that never included a refresh token would die about an hour after authorize (JWT is 3600s, and every MCP request re-checks it), not after a week of use. () stays ready with . The same Kody client survives there. That server also advertises , but it is a different authorization server. The failure is specific to this server's rotate-and-revoke-on-any-reuse policy. A sibling agent is checking Kody's client; this PR fixes the server behavior that turns that client's overlap into a logged-out connection. Fix Reuse of a refresh token within 60 seconds returns the family's current live refresh token (HTTP 200, same the first caller received) and does not revoke the family. Requests for that token are serialized per family in-process, with atomic / updates if two processes share the database file. Reuse after 60 seconds still revokes the family, including when the presented token's own has already passed. Revoked tokens are stamped outside the grace window so presenting one cannot mint a replacement. is added in . Public clients are still required to rotate refresh tokens (MCP authorization spec); the grace window is only for the overlap. Test Plan [x] (format, lint, typecheck, 271 tests) [x] Authorize and refresh with and still return a refresh token [x] Immediate replay of a just-rotated refresh token returns 200 and the same successor; a later refresh of that successor still works [x] Two overlapping refreshes of the same token both return 200 with one shared successor, and that successor still refreshes [x] Replay after the grace window, and replay of an expired used token, still return and revoke the descendant After deploy, Kent should: 1. Open the authorization link once from for the saved server (). 2. Confirm shows with and connected. 3. Use the server across an access-token expiry (1 hour) or several refreshes. should stay true without another browser login. 4. Optional: in the logs means an overlap was absorbed. still means a real replay outside the window. Checklist [x] Tests updated [ ] Docs updated (no user-facing docs; this is token-endpoint behavior) Screenshots    Summary by CodeRabbit Bug Fixes** Refresh-token requests now retain the refresh token when using a resource indicator. Briefly reusing a recently rotated refresh token returns the current token instead of failing. Concurrent refresh requests also receive a consistent result. Reuse after the grace period continues to invalidate the token family. Requested scopes that exceed the original grant are rejected.

kentcdodds · 5d ago
kentcdodds
fix(media): sort General Conference feeds newest-conference-firstMergedPR

Directory feeds like General Conference (, ) were emitting April before October of the same year. ID3 only stores a year, so every 2026 talk got , the path tie-break sorted before , and the live folder order was . Wanted: with … still in session order inside a conference. Each well-tagged talk already has in the description. This change reads that (or the folder in the path) and uses the conference month as when metadata is year-only. Saturday and Sunday talks therefore share a date, only applies to the first field (), and stays ascending so session order is preserved. Using the raw session timestamp as would put Sunday talks before Saturday under desc. Do not switch the whole sort to desc — that would reverse / inside a conference. Media cache version is bumped to 5 so a redeploy re-parses existing files. No ingest rewrite of ~1500 GC files is required. Some GC items still have Jan 1900 s and raw filename titles (duplicate sustaining mp3s). Those are missing tags, not this year-only collapse, and are left alone. Test Plan [x] prefers estimated-publish month over year-only [x] Saturday and Sunday estimated publishes in April 2026 share [x] Full TDRL still wins over estimated publish [x] folder is used when estimated publish is missing [x] emits 2026-04 intro, 2026-04 closing, 2025-10, 2025-04 [x] Full (format, lint, typecheck, 264 tests) After deploy: production GC feed should list then then , with before inside 2026-04. Cache v5 invalidation happens on first scan after deploy. Checklist [x] Tests updated [ ] Docs updated Screenshots N/A — RSS item order / metadata extraction. Test output:   

kentcdodds · 4w ago
kentcdodds
fix(mcp): lock RSS subscribe URLs to /feed/{token}MergedPR

Production MediaRSS MCP tools (, ) still describe and (on the currently deployed image) return subscribe links as . That path 404s. The live route is (HTTP 200, ). Verified live 2026-08-31: → 404 → 200 Main already builds as (and accepts an optional token ). This PR locks that contract so tool descriptions cannot regress, and documents the live path in . Production is still running (before the URL fix). Merging this will publish a new Docker image so the NAS can pick up the correct MCP descriptions and values. Test Plan [x] [x] Full (lint, format, typecheck, tests) [x] Assert MCP descriptions contain and never [x] Assert input schema includes optional [ ] After deploy: production commit is this merge; MCP tool descriptions no longer mention the query-token path Checklist [x] Tests updated [x] Docs updated Screenshots N/A — MCP/tool-description change. Test output:    Summary by CodeRabbit Documentation Documented the correct token-only RSS feed URL format: . Clarified that the legacy query-parameter format is invalid and may return an error. Documented optional labels for created feed tokens. Tests Added coverage confirming MCP tool descriptions expose the correct token URL format. Verified token-related tools expose the expected feed ID, label, and URL information.

kentcdodds · 4w ago
Structured data for AI agents

Repository: kentcdodds/mediarss. Description: An RSS feed generator for media (audio/video). Stars: 45, Forks: 8. Primary language: TypeScript. Languages: TypeScript (99.2%), Shell (0.5%), CSS (0.2%), Dockerfile (0.1%). Latest release: v4.1.1 (3mo ago). Open PRs: 0, open issues: 0. Last activity: 5d ago. Community health: 42%. Top contributors: kentcdodds, kody-bot, devin-ai-integration[bot], cursoragent, github-actions[bot], imgbot[bot].

·@ofershap

Replace github.com with gitshow.dev