Expand description
The web UI: sign in, browse the library and play it in the browser.
Server-rendered HTML, with Datastar for the parts that change in place
(search as you type, loading more, the share button) and a small script of
its own that swaps only the page content on navigation, so the player keeps
playing. Playback happens in the browser, streaming from /ui/stream: a
headless server has no speakers.
Sign-in is koan’s own session: the same HttpOnly access and refresh
cookies the JSON login sets, so tokens never reach page script. The gate
accepts a valid access cookie; a page load without one goes through
/auth/resume, which spends the refresh cookie (scoped to /auth, so only
that route sees it) for fresh cookies, or on to the sign-in form.