Repository navigation
The S1 backend no longer depends on @svrooij/sonos. It speaks UPnP itself, on top of @sonn-audio/node-upnp.
Why
That package's npm latest is 2.5.0, published in June 2022, and it pins fast-xml-parser 3.19.0 — a line carrying two unpatched advisories (prototype pollution via a tag or attribute name; XMLBuilder CDATA injection) whose fixes exist only in 4.x and 5.x. No range bump could reach them.
What we actually used of it was small: device identity, ZoneGroupState, GetPositionInfo/GetMediaInfo, nine events and six transport commands. All of it is plain UPnP.
What's new
- Radio now-playing works. Read out of Sonos's own
r:streamContent, wheredc:titlestays fixed on the station name.streamInfoused to always beundefined. - Group reshuffles arrive as ZoneGroupTopology events instead of waiting up to 30 s for the poll, which is now only a safety net.
- Commands are addressed with the coordinator's own host and port from the topology, rather than the port the client was constructed with.
npm auditis clean.
Testing
There is no S1 hardware in this loop, so scripts/s1-probe.mjs drives the client against a fake speaker reproducing the wire format — device description, SOAP control, and GENA NOTIFYs carrying the double-escaped DIDL that real firmware sends. It found two real bugs during development. Run it with npm run build && npm run probe:s1.
Breaking changes
S1SonosGroupandS1SonosPlayertake(client, seed); theSonosDeviceargument is gone.- Track metadata on the group's
apply*methods isUpnpTrack(lowercase fields), not@svrooij/sonos'sTrack.