SKYHOUSE.dev Journal

Maintaining the Cloud Fortress

inspiredby: new site, validation, Spotify and suggestions

Why: Damien wanted the redesigned inspiredby site live to show friends, and spotted that the old data was full of nonsense (Britney Spears "inspiring" a 1984 Madonna song).

Same service and port as before (inspiredby-web on 8440 behind NPM), but the site now has a public form, a secrets file and a Spotify login, so this records what a maintainer needs to know.

1. Claims are validated before they show

The extractor now drops sentences from reception/covers/live/legacy sections, people born after a song's release, performers, critics, band members and musical influences. Hand-graded precision went from 28% to 82%. All 90,706 already-processed pages were re-extracted offline (~2.4 h) and claims rebuilt; backup first at ~/inspiredby/backups/inspiredby-2026-10-05-pre-redesign.db. The database is now in WAL mode: copy it with sqlite3 .backup, never cp.

2. A public write path: suggestions

POST /suggest is the site's only write. It appends JSON lines to /home/plex/inspiredby/submissions/ (never the database), with a honeypot field, a 16 KB body cap and rate limits (5/hour per client IP from X-Forwarded-For when the peer is NPM's 172.18.0.0/16, 200/day overall). The hourly worker imports suggestions as leads that are only shown once the cited page is fetched and the quote is found on it. "Report a problem" rows wait for a human in the same folder. Spotify artists visitors listen to land in submissions/interest.jsonl, and the worker queues their songs first.

3. Secrets file

/home/plex/inspiredby/.env (mode 600, not in git, excluded from deploys), loaded by all three inspiredby units via EnvironmentFile=-: LASTFM_API_KEY and SPOTIFY_CLIENT_ID/SECRET, copied from the music-discovery app (Spotify allows one development-mode client per developer account, so the two apps share it and its 5-user cap), plus INSPIREDBY_SECRET, which signs the site's cookies.

4. Spotify login and player

Song pages embed Spotify's player (an iframe to open.spotify.com, no API quota). "Connect Spotify" is Authorization Code + PKCE with read-only scopes (top items, follows, library). It needs the redirect URI https://inspiredby.skyhouse.dev/spotify/callback on the music-discovery app in the Spotify dashboard, and each user allowlisted there. The access token is discarded after one read; only matched artist IDs are kept, in a signed cookie.

5. Local photos

A new worker task downloads one 500px Commons thumbnail per person into /home/plex/inspiredby/media/photos/ (~400 MB eventually, excluded from deploys and git), served by the site with author/licence credits. Only files that exist on Commons are used, which excludes fair-use promo shots.

Net effect: a public, browsable inspiredby with validated data, one rate-limited write path into a folder, and secrets kept in one 600-mode file.

← Back to Admin Hub