TuneNest
PartialMusic Without Middlemen
Creator-sovereign music distribution. Artists keep 90%+ of revenue. AI-powered DAW studio with beat/lyrics/melody generation. Part of Sporus.
13
Live
3
Partial
1
Stub
2
Missing
13/13
Pages
0/22
APIs
58%
Security
Features (19)
Core3/5 live
Audio + cover art upload with metadata and scheduling
Public artist profiles with track listings
Personal library, playlists, and track likes
UI has scheduling dialog, backend incomplete
No Spotify/Apple Music distribution connectors
Auth1/1 live
Passwordless passkey authentication
Monetization2/3 live
Stripe payments with 5% platform fee, 95% to creator
Onboarding, payout status, earnings tracking
No multi-artist revenue sharing
Studio3/6 live
Genre-specific drum patterns via Claude API
Full/continue/rewrite modes with syllable counting
3 additional AI endpoints for music production
Sequencer/piano roll UI built, Tone.js playback partial
UI complete, audio processing partially integrated
Database schema ready, sharing UI not built
Social2/2 live
Cross-platform following from all 5 Sporus platforms
Tips, follows, and publishing event notifications
Protection2/2 live
Perceptual hash duplicate detection
Per-content training/remix/style protections
Security
Security Checklist
2/6 passing| Check | Status |
|---|---|
| CSRF Protection | Pass |
| Rate Limiting | Fail |
| Input Validation | Partial |
| Security Headers | Partial |
| Auth / Session | Pass |
| Encryption | Partial |
Issues(6 open)
No rate limiting — AI endpoints can be abused (expensive Anthropic calls)
Missing CSP header — XSS risk on public profiles
No server-side file type verification — relies on extension only
Username/bio fields lack output sanitization
Passkey challenge table has no cleanup job
Studio audio engine partially integrated
API Route Inventory
22
Total Routes
0
Rate Limited
13
Total Pages
13
Live Pages