Omahub
← All plugins
I

Apple Music

by Iulian Safta

Apple Music web player controls and now-playing information for the Omarchy bar.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
e712d0e
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts docs/DEVELOPMENT.md:25

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/iuliansafta/omarchy-apple-music.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e712d0e
Reviewed
1 month ago

The plugin is a legitimate Apple Music web integration: MPRIS-based playback controls, a small local Python bridge daemon, and a Chromium extension scoped to music.apple.com. The deterministic scan's only finding is a `git clone` command in DEVELOPMENT.md, which is documentation, not executed code. The code is unusually defensive (no-follow file operations, bounded input validation, localhost-only CDP), though it intentionally opens a Chromium remote-debugging port and runs an always-on local daemon, which slightly broadens the local attack surface.

  • The launcher runs Chromium with --remote-debugging-port=0, so any local process able to reach the localhost port can interact with the Apple Music page; this is needed for the bridge but is an additional local attack surface.
  • The plugin starts a persistent Python bridge daemon and a dedicated Chromium profile holding Apple Music login state; if either were compromised, session data could be exposed, though the code applies strict validation and permissions.
  • The launcher script depends on `jq` even though it is not listed in the README requirements, which can cause launch/focus commands to fail on systems without it (a usability issue, not a security issue).
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/iuliansafta/omarchy-apple-music --enable
Widgets #bar

Omarchy Apple Music

Apple Music Web as a first-class Omarchy 4.0 bar widget.

Apple Music bar widget with the now-playing popup open

The plugin keeps authentication, DRM, library access, and playback in the official Apple Music web player. It uses Quickshell's native MPRIS integration for now-playing information and controls.

Features

  • Dedicated Chromium app/profile for reliable Apple Music detection
  • Compact, fixed-width album-art button that keeps the bar layout stable
  • Theme-colored vector Apple Music fallback when artwork is unavailable
  • Optional legacy text label for visible title and artist metadata
  • Always-available bar button that launches Apple Music when closed
  • Launch or focus Apple Music from the bar
  • Track title, artist, album, and artwork
  • Previous, play/pause, and next controls
  • Like and dislike for the current song, synced to the Apple Music library
  • Up-next queue with click-to-jump
  • Recently played history, persisted across shell and machine restarts
  • Shuffle, repeat (off/all/one), and autoplay controls, synced with Apple Music
  • Recently played entries replay the exact song (old entries keep working)
  • Add the current song to the Apple Music library, with truthful state
  • Player panel with a blurred artwork backdrop

Requirements

  • Omarchy 4.0
  • Chromium
  • python3 (standard library only, no packages)
  • An Apple Music subscription

playerctl is not required.

Install

omarchy plugin add https://github.com/iuliansafta/omarchy-apple-music.git --enable

Add the widget to the bar if your Omarchy version does not place it automatically:

omarchy plugin enable iuliansafta.apple-music center

First launch and sign-in

The compact Apple Music button is always available in the bar. Click it to launch the web app, or use either command:

~/.config/omarchy/plugins/iuliansafta.apple-music/scripts/apple-music open
omarchy-shell iuliansafta.apple-music open

Sign in inside the opened window with your Apple ID (two-factor authentication works as usual — the confirmation code prompt appears in the same window). Credentials are stored in the plugin's isolated Chromium profile at ~/.local/share/omarchy-apple-music/chromium-profile, so you stay signed in across restarts and the login never touches your normal browser profile. Without an active Apple Music subscription you can browse the library, but playback is limited to previews.

Add Apple Music to the app launcher

To also start Apple Music from the application launcher (SUPER + SPACE), either use the plugin's own installer — recommended, because it registers the dedicated app with its bundled extension:

~/.config/omarchy/plugins/iuliansafta.apple-music/scripts/apple-music install

Or create a web app the generic Omarchy way, pointing its custom-exec at the plugin's launcher so the extension and the bridge daemon still load:

omarchy webapp install "Apple Music" https://music.apple.com \
  "$HOME/.config/omarchy/plugins/iuliansafta.apple-music/assets/apple-music.svg" \
  "$HOME/.config/omarchy/plugins/iuliansafta.apple-music/scripts/apple-music open"

Remove it again with omarchy webapp remove "Apple Music".

A plain omarchy webapp install "Apple Music" https://music.apple.com apple-music (without the custom exec) opens music.apple.com in a generic app window on your normal Chromium profile. The bar widget's playback controls may work, but the bundled extension will not load — so the HLS duration fix, ratings, and queue features are unavailable.

Controls

The default bar display is a fixed-width album-art button. Hover it for the full track title and artist; long track names never resize the bar slot. Select Text under the widget's Bar display setting to restore the Apple icon and text label.

  • Click while closed: launch/focus Apple Music
  • Click while connected: open the player panel
  • Middle-click: play/pause
  • Scroll up/down: previous/next

The player panel keeps previous/play/next as the primary controls and places ratings, library, shuffle, repeat, and autoplay in one compact secondary row.

Progress handling

Some Apple Music HLS tracks expose Infinity as the HTML audio duration even though MusicKit's queue contains the real catalog duration. Chromium converts that infinity to the maximum signed 64-bit MPRIS value.

The plugin bundles a minimal extension, restricted to https://music.apple.com/*, that republishes MusicKit's durationInMillis through the standard Media Session API. This restores MPRIS progress and seeking. It uses Apple Music's private MusicKit queue object, so a future Apple Music Web update may require an adjustment. Invalid values still fall back safely to elapsed time with --:--.

Ratings and queue

Chromium's Media Session cannot carry ratings or queue contents, so those travel a different path: the bundled extension also exposes a collect/command hook on the page, and a small daemon (scripts/bridge-daemon, spawned by the plugin service) relays it over Chromium's DevTools protocol — which the dedicated browser enables with --remote-debugging-port=0 on a localhost-only port. Ratings are read and written through Apple Music's own ratings API with the tokens MusicKit already holds in the page. If Apple Music Web changes its internals, rating and queue features degrade to hidden while duration bridging and playback controls keep working.

Playback modes

The player panel has a shuffle / repeat / autoplay row next to the rating controls. All three are read from and written through MusicKit on the Apple Music page (the single source of truth — Chromium's Media Session cannot carry them, and MPRIS has no autoplay concept), so the controls always show the state Apple Music itself reports, including changes made inside Apple Music. Repeat cycles Off → Repeat All → Repeat One → Off. When the bridge is unavailable the row hides and ordinary MPRIS transport keeps working.

Autoplay means Apple Music's infinite continuation of the queue (recommended tracks after your queue ends), not automatic application launch.

Recently played

Recently played entries persist across shell and machine restarts in ~/.local/share/omarchy-apple-music/history.jsonl. The visible list keeps each title/artist pair once; replaying a song moves its newest occurrence to the top instead of adding a duplicate row. New entries recorded while the bridge is active carry an exact-song descriptor (catalog/library song IDs from MusicKit); clicking such an entry replaces Apple Music's current playback with that exact song — never a title/artist guess — and lets Apple Music establish its normal continuation. Entries recorded before this feature (or while the bridge was unavailable) remain listed but only focus Apple Music when clicked.

Add to library

The library button next to the rating controls adds the currently audible song to your Apple Music library. It is a distinct action from like/dislike: membership is read from Apple's own library API (matched by exact catalog ID, never by title), and the button only offers an add when Apple reports the song as absent. Pending adds show a waiting state and cannot trigger duplicate writes; the check mark appears only once Apple's library actually reflects the song. Failure and unknown states stay non-committal instead of claiming success. Removal is not offered — Apple's web API does not allow it from the browser.

Remove

omarchy plugin remove iuliansafta.apple-music

The isolated browser profile remains at:

~/.local/share/omarchy-apple-music/chromium-profile

Remove it manually only if you also want to delete its Apple Music login and browser data.

Development

See docs/DEVELOPMENT.md.

License

MIT