Lyrics Card Generator v5.9.3 Local Release-Candidate Notes
Release-candidate date: 2026-08-07
v5.9.3 combines #98–#103 with final-review fixes, focusing on packaged Windows startup, local-audio imports, music-platform metadata, and the Next.js security patch.
Windows startup and single-instance ownership
- Packaged startup now authenticates the intended local Next service with a unique HMAC challenge and proof on every launch instead of trusting an arbitrary HTTP response on the selected port.
- Spawn failures, early server exits, port competition, and
ENOENTfail closed. An unexpected server exit revokes the local renderer origin and closes the desktop shell. - A second launch exits the secondary process and restores, shows, and focuses the existing window. Only the primary can start the local server, register privileged IPC, and write History.
Local-audio boundaries and metadata
- MP3 / FLAC requests use a 100 MiB file limit and a bounded multipart stream. Known oversized requests are rejected before body reads, while missing or deceptive lengths remain subject to streaming byte counts.
- Embedded covers have an aggregate 8 MiB budget and lyrics have a 256 Ki-character budget. Oversized metadata is rejected before cover Base64 encoding, lyric expansion, and JSON response serialization.
- Parsing uses a close-safe random-access tokenizer so trailing APEv2 tags remain available. Recognized MIME types override conflicting extensions, and
file.arrayBuffer()no longer creates a second whole-file copy.
Music platforms and dependency security
- Spotify artist extraction now combines structured page metadata, descriptions, and explicit title formats while preserving genuine remaster, mix, and live suffixes in track titles.
- NetEase search ranks a larger candidate pool by title and artist semantics. Strong canonical matches are promoted; otherwise, upstream ordering remains intact.
- Next.js and its ESLint package are aligned on 15.5.21. The unused Next image optimizer entry point is disabled, and the desktop standalone closure explicitly includes the local-audio tokenizer plus startup and single-instance helpers.
Candidate boundary
These notes describe a locally packaged and reviewed v5.9.3 release candidate. They do not state that a push, tag, or GitHub Release has occurred. Public availability is determined by the project's live GitHub Releases page.