Skip to content

Fix the YouTube cookie mount advice, and document the Firefox export - #31

Merged
davior merged 1 commit into
mainfrom
claude/brave-keller-1soxwa
Sep 28, 2026
Merged

davior merged 1 commit into
mainfrom
claude/brave-keller-1soxwa

Conversation

@davior

@davior davior commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Follow-up to #30.

The bug

The URL-import docs said to mount a YouTube cookies file through docker-compose.override.yml. Compose only reads that file when COMPOSE_FILE is unset. Every deployment of this app sets COMPOSE_FILE for the reverse-proxy overlay (docs/deployment.md), so the mount was silently ignored. Confirmed with docker compose config:

Setup /app/secrets mounted?
Old advice: docker-compose.override.yml, with COMPOSE_FILE set (production) no
Old advice, COMPOSE_FILE unset (why it looked right) yes
New: docker-compose.cookies.yml listed in COMPOSE_FILE yes, read-only, with URL_IMPORT_COOKIES_FILE defaulted

Changes

  • docker-compose.cookies.yml is a new opt-in overlay, enabled by listing it in COMPOSE_FILE like the prod one.
    • It mounts ./secrets → /app/secrets as a directory, read-only, rather than the file. A single-file bind mount pins the inode, so a refreshed file written by rsync or an editor would stay invisible until the container was recreated. A missing file would also make Docker create a directory in its place.
    • It sets URL_IMPORT_COOKIES_FILE=${URL_IMPORT_COOKIES_FILE:-/app/secrets/youtube-cookies.txt}. An explicit .env value still wins, and the empty value copied from .env.example falls through to the default. Both verified with docker compose config.
  • .gitignore: /secrets/. A cookies file is a login, and the server's checkout is a git clone.
  • docs/url-import.md#youtube-cookies replaces the old paragraph with the full procedure, Linux only:
    • a dedicated Firefox profile (and why not a private window: its cookies never reach disk)
    • where the profile folder lives for Snap, Flatpak, XDG and legacy installs
    • exporting by explicit profile path, and that the "must provide at least one URL" error is harmless
    • filtering to youtube.com lines
    • the server steps, with permissions
    • refreshing an expired session, and other browsers
  • .env.example and docs/deployment.md point at that section, and say that setting COMPOSE_FILE turns off docker-compose.override.yml.

No application code changes.

Verification

  • The export and filter commands were extracted from the doc's code blocks and run verbatim against a fake Firefox profile at the Snap location. The filtered file loads in yt-dlp's YoutubeDLCookieJar with only youtube.com cookies.
  • The same fake setup showed why the docs require the explicit path. With two profiles, bare --cookies-from-browser firefox exported the most recently used one (the everyday profile, with unrelated site sessions). The explicit path exported the right one.
  • git check-ignore secrets/youtube-cookies.txt matches.
  • pytest -q tests/test_url_import.py tests/test_imports_api.py: 64 passed. No code changed; this is a sanity check.

🤖 Generated with Claude Code

https://claude.ai/code/session_017KYsSofkyeywy1NNPV8NtM


Generated by Claude Code

The URL-import docs said to mount a YouTube cookies file through
docker-compose.override.yml. Compose reads that file only when
COMPOSE_FILE is unset, and every deployment of this app sets COMPOSE_FILE
for the reverse-proxy overlay, so the mount was silently ignored
(reproduced with `docker compose config`).

- docker-compose.cookies.yml: an opt-in overlay, named in COMPOSE_FILE
  like the prod one. Mounts the ./secrets directory read-only (not the
  file, so a refreshed file needs no restart and a missing one cannot
  become a directory) and defaults URL_IMPORT_COOKIES_FILE to it.
- /secrets/ gitignored: a cookies file is a login.
- docs/url-import.md#youtube-cookies: the full Linux procedure: a
  dedicated Firefox profile, finding its folder (Snap, Flatpak, XDG and
  legacy locations), exporting by explicit path, keeping only
  youtube.com lines, installing it on the server, refreshing it.
  Commands were run verbatim against a fake profile. A bare
  `--cookies-from-browser firefox` exported the most recently used
  profile instead, so the docs require the path.
- .env.example and deployment.md point at it, and say that setting
  COMPOSE_FILE turns off docker-compose.override.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KYsSofkyeywy1NNPV8NtM
@davior
davior marked this pull request as ready for review September 28, 2026 12:47
@davior
davior merged commit ee8b168 into main Sep 28, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants