## ADDED Requirements ### Requirement: Embedded LAN import server as primary path The app SHALL provide an in-app local network file server as the primary import path, so a computer on the same LAN can upload files into the app library without relying on the desktop-style system file picker. Uploads land flat under `library/` (optional target subdirectory); folder organization happens afterward in Explorer. #### Scenario: Start server from Import - **WHEN** the user enables LAN import on the Import screen - **THEN** the app starts an HTTP listener and displays connection information usable from a computer browser #### Scenario: Upload registers catalog entries - **WHEN** a client uploads one or more allowed media files to a target directory under `library/` - **THEN** the files are written to Documents/`library/` using basename-only flat placement (no nested relative paths from the upload client) AND corresponding `CatalogEntry` records are created or updated ### Requirement: Discovery information While the server is running, the app SHALL present at least the device LAN IPv4 address, port, and a scannable QR code (or equivalent) that helps the user open the upload page; the app MAY also advertise via Bonjour/mDNS. #### Scenario: Connection card visible - **WHEN** the LAN server is running - **THEN** the Import UI shows URL (or host:port), and a QR code encoding that connection target ### Requirement: No upload authentication The LAN server MUST NOT require a token, password, or other upload credential. Write operations are accepted while the server is running. The app MUST present trusted-LAN-only messaging because the endpoint is unauthenticated. #### Scenario: Upload without credentials succeeds when running - **WHEN** a client posts an allowed media file to `/upload` with no Authorization header or token field while the server is running - **THEN** the server accepts the upload (subject to type and path safety checks) and writes the file #### Scenario: Upload rejected when stopped - **WHEN** the user stops the LAN server and a client posts to `/upload` - **THEN** the server MUST NOT write files (service unavailable) ### Requirement: File-only upload (no folder transfer) The server and browser upload page SHALL accept multi-file selection only. The server MUST NOT provide folder-structured upload (browser `webkitdirectory` / nested multipart relative paths) or zip-archive extraction as an import path. Nested library folders are created later via Explorer. #### Scenario: Flat multi-file upload - **WHEN** a client uploads files `video.mp4` and `book.pdf` (optionally with a flat `targetDir`) - **THEN** both files land under that target directory (or library root) by basename with catalog entries pointing at those relative paths #### Scenario: Nested client paths ignored - **WHEN** a client supplies a filename or relative path containing directories (e.g. `Series/A/video.mp4`) - **THEN** the server stores only the basename under the chosen target directory and MUST NOT create intermediate folders from that path ### Requirement: Secondary Files picker import The Import area SHALL optionally allow importing via the system Files / document picker as a secondary path, writing into the same `library/` + SwiftData catalog pipeline. #### Scenario: Pick files from Files app - **WHEN** the user chooses the secondary import action and selects allowed media files - **THEN** those files are copied into `library/` and cataloged like LAN uploads ### Requirement: Foreground-only LAN service lifecycle The LAN import server SHALL be intended for foreground use. When the app leaves the active foreground state, the app MUST stop accepting new import connections or stop the server, and MUST surface that the service is no longer available until re-enabled. #### Scenario: Background stops accepting uploads - **WHEN** the LAN server is running and the app moves to background - **THEN** new upload connections are not accepted (server stopped or paused) and the UI reflects inactive status on return if still stopped ### Requirement: Local-network scope and safety messaging The app SHALL request local network permission as needed and SHALL document or present that the service is for trusted LAN use only (not a public internet share), especially because uploads are unauthenticated. #### Scenario: Permission prompt context - **WHEN** the user first enables LAN import and the OS requires local network permission - **THEN** the system permission flow is triggered with an app usage description explaining LAN file import