Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Project: private inspection clip playback

Last updated: 7 Oct 20268 min read
project
IntermediateBy AITrove Editorial

Build a private inspection clip page for case 47. The report and a descriptive transcript load first; an 83 MiB clip does not have to download before the reviewer can read the finding. Provide native media controls, a poster with dimensions, captions, and a playable direct source. A separate adaptive path may choose between three rendition levels. It measures stalls and available buffer, switches quality conservatively, and caps retained media. A browser without that path still plays the direct source or opens the transcript. The service publishes each clip cut as an immutable revision with matching renditions, poster, captions, and transcript. A seek requests a byte interval from one revision and receives an exact partial body and range metadata. An invalid interval is rejected without fetching arbitrary bytes. A re-encode creates a new identity; the active player cannot mix old and new fragments. Access to the manifest, direct file, segment, poster, caption, and transcript follows one case permission policy. If delivery grants are used, record their expiry and revocation limit honestly. The browser handles blocked play, stalled transfer, decode failure, ended state, and route changes. A private error never exposes the case file name to an unauthorized account. The project must work when script fails, when a source format is unavailable, when the adaptive buffer reaches quota, and when a reviewer loses permission midway through playback.

Build contract

  • Keep essential report and transcript content available before or without media playback.
  • Serve correct, immutable byte ranges and reject malformed seeks.
  • Bound segment fetching and buffered media while retaining a direct source fallback.
  • Apply one revision and access policy to every derived clip asset.

Implementation checkpoint

javascript
function canServeClipAsset(request, manifest) {
  return request.caseAuthorized && request.assetRevision === manifest.videoRevision &&
    manifest.assetIds.has(request.assetId) && request.grantExpiresAt > request.now;
}
console.log(canServeClipAsset({ caseAuthorized: true, assetRevision: 29, assetId: 'caption-47', grantExpiresAt: 63, now: 47 }, { videoRevision: 30, assetIds: new Set(['caption-47']) }));
// Output: false

The checkpoint denies an old caption revision even while the requester still has case access. The server must resolve the asset family and permission from authoritative storage, not from fields the browser supplies. Expected set membership is O(1), with O(A) space for A manifest asset IDs; actual delivery remains O(R) for R requested bytes. A short grant lowers repeated authorization calls but leaves a defined exposure window after revocation. Retention must remove old renditions and caption copies only after active references and review obligations are accounted for.

Failure drill

Load the report on a metered connection and record media bytes before pressing play. Reject autoplay, fail the first codec, then start playback from the alternative. Seek to minute 6 and verify response status, body length, range bounds, and immutable rendition key through the deployed proxy. Start a second seek while the first segment is in flight and prevent its stale append. Force buffer quota exhaustion, release old ranges, and preserve controls. Publish revision 30 with captions from revision 29 and block the release. Switch accounts and try the manifest, segment, poster, caption, and transcript directly. Revoke access during playback and measure what an unexpired grant can still reach. Close the page while audio plays and verify it stops. Test captions, keyboard controls, transcript access, and all visible failure messages with assistive technology.

Acceptance checks

  • Initial reading does not require an 83 MiB download.
  • Seek responses and asset revision identity stay coherent.
  • An unsupported or quota-limited player has a tested fallback.
  • No derived asset bypasses private case permission.

Common Mistakes

  • Testing only the video file while leaving timed text or posters public.
  • Assuming a metadata preload hint guarantees a fixed transfer size.
  • Mixing cached fragments from two encoded revisions.

Related lessons

Media Player Source and Load State; Media Byte Ranges, Seeking, and Version Identity; Adaptive Media Buffer and Fallback Policy; Private Media Session, Cache, and Timed Text.

web-tech
web-development
Storage details