Skip to content

v0.3.0

Latest

Choose a tag to compare

@rudyberends rudyberends released this 06 Sep 08:06

The S1 backend no longer depends on @svrooij/sonos. It speaks UPnP itself, on top of @sonn-audio/node-upnp.

Why

That package's npm latest is 2.5.0, published in June 2022, and it pins fast-xml-parser 3.19.0 — a line carrying two unpatched advisories (prototype pollution via a tag or attribute name; XMLBuilder CDATA injection) whose fixes exist only in 4.x and 5.x. No range bump could reach them.

What we actually used of it was small: device identity, ZoneGroupState, GetPositionInfo/GetMediaInfo, nine events and six transport commands. All of it is plain UPnP.

What's new

  • Radio now-playing works. Read out of Sonos's own r:streamContent, where dc:title stays fixed on the station name. streamInfo used to always be undefined.
  • Group reshuffles arrive as ZoneGroupTopology events instead of waiting up to 30 s for the poll, which is now only a safety net.
  • Commands are addressed with the coordinator's own host and port from the topology, rather than the port the client was constructed with.
  • npm audit is clean.

Testing

There is no S1 hardware in this loop, so scripts/s1-probe.mjs drives the client against a fake speaker reproducing the wire format — device description, SOAP control, and GENA NOTIFYs carrying the double-escaped DIDL that real firmware sends. It found two real bugs during development. Run it with npm run build && npm run probe:s1.

Breaking changes

  • S1SonosGroup and S1SonosPlayer take (client, seed); the SonosDevice argument is gone.
  • Track metadata on the group's apply* methods is UpnpTrack (lowercase fields), not @svrooij/sonos's Track.