Skip to content

Lyrics Card Generator v5.9.3 Local Release-Candidate Notes ​

Release-candidate date: 2026-08-07

v5.9.3 combines #98–#103 with final-review fixes, focusing on packaged Windows startup, local-audio imports, music-platform metadata, and the Next.js security patch.

Windows startup and single-instance ownership ​

  • Packaged startup now authenticates the intended local Next service with a unique HMAC challenge and proof on every launch instead of trusting an arbitrary HTTP response on the selected port.
  • Spawn failures, early server exits, port competition, and ENOENT fail closed. An unexpected server exit revokes the local renderer origin and closes the desktop shell.
  • A second launch exits the secondary process and restores, shows, and focuses the existing window. Only the primary can start the local server, register privileged IPC, and write History.

Local-audio boundaries and metadata ​

  • MP3 / FLAC requests use a 100 MiB file limit and a bounded multipart stream. Known oversized requests are rejected before body reads, while missing or deceptive lengths remain subject to streaming byte counts.
  • Embedded covers have an aggregate 8 MiB budget and lyrics have a 256 Ki-character budget. Oversized metadata is rejected before cover Base64 encoding, lyric expansion, and JSON response serialization.
  • Parsing uses a close-safe random-access tokenizer so trailing APEv2 tags remain available. Recognized MIME types override conflicting extensions, and file.arrayBuffer() no longer creates a second whole-file copy.

Music platforms and dependency security ​

  • Spotify artist extraction now combines structured page metadata, descriptions, and explicit title formats while preserving genuine remaster, mix, and live suffixes in track titles.
  • NetEase search ranks a larger candidate pool by title and artist semantics. Strong canonical matches are promoted; otherwise, upstream ordering remains intact.
  • Next.js and its ESLint package are aligned on 15.5.21. The unused Next image optimizer entry point is disabled, and the desktop standalone closure explicitly includes the local-audio tokenizer plus startup and single-instance helpers.

Candidate boundary ​

These notes describe a locally packaged and reviewed v5.9.3 release candidate. They do not state that a push, tag, or GitHub Release has occurred. Public availability is determined by the project's live GitHub Releases page.

Cherry Chu · Projects, notes, and working documentation.