The product's core promise, complete anonymity with no accounts, conflicts directly with two features that normally assume some form of identity.
Spotify no longer allows a single app level credential to read an arbitrary playlist, so importing more than one song at a time needed real user authorization without turning the product into an account based service.
Full length playback inside an embedded player depends on a Spotify session cookie scoped to Spotify's own domain, something the app has no access to and cannot influence, particularly on mobile browsers where that session often never exists in the first place.
Getting third party embeds, Spotify and YouTube, to behave consistently across browsers, hosts, and devices surfaced a long tail of separate problems: content security policy blocking legitimate scripts, autoplay policy blocking track transitions, and DOM ownership conflicts between React and each provider's own SDK.
§ 02Solution
Each tension was resolved by narrowing scope rather than working around it.
Playlist import got its own short lived OAuth flow using PKCE, with the access token discarded after one use and no refresh token ever stored, so it functions as a temporary permission rather than a login.
Full playback was left as Spotify's own decision to grant or withhold. The product instead gives an honest explanation plus a direct link to open the track in Spotify itself, which sidesteps the cross origin cookie problem entirely on mobile.
The embedded player was rewritten so every third party SDK receives a plain DOM node that React never tracks, removing a class of reconciliation crashes that showed up when switching tracks.
§ 05Gallery
§ 01 / 04
Autoplay across mixed Spotify and YouTube tracks was made reliable by muting a video before starting it and unmuting immediately after, since muted autoplay is permitted unconditionally while unmuting already playing media counts as a volume change, not a new autoplay attempt.
Content security policy was scoped tightly to four named third party hosts rather than opened broadly, with the one unavoidable relaxation, allowing script evaluation, documented and justified rather than left as an unexplained exception.
§ 03Result
The finished product is a working anonymous letter and music exchange with real playback, a functioning moderation pipeline, and no account system anywhere in the stack.
Every optional integration, Spotify, YouTube, and error monitoring, degrades gracefully when unconfigured rather than breaking the build or the app.
The visual design reads as a deliberate editorial product rather than a generated interface, carrying its own typographic and motion language end to end.
Moderators can review both flagged letters and incoming feedback from one authenticated queue, closing the loop on a product that otherwise has no direct way to reach its users.
§ 04Highlights
01Anonymous session model using HMAC signed cookies, with no accounts or passwords anywhere in the product
02Real Spotify and YouTube playback embedded directly in the letter view, with auto advance across mixed playlists
03Optional Spotify OAuth flow used only for playlist import, kept separate from the anonymous core and discarded after one use
04Postgres backed rate limiting paired with a local moderation filter that gates content before it goes public
05Admin queue for reviewing flagged letters and incoming user feedback from one authenticated view
06Anonymous feedback system with honeypot spam protection and an internal review workflow
07Content security policy scoped per environment across two different third party embed providers
08Progressive web app support with a generated manifest and icon set
09Open Graph metadata generated per letter so shared links preview accurately
10Error monitoring wired in but fully inactive until configured, so it costs nothing when unused