Spent a real debugging session chasing a "not matching configuration"
error assuming it was host mode, when it was actually guest PKCE mode
hitting a redirect URI (production, root path) that was simply never
registered — the README only documented the two local dev URIs, not
that host mode and guest mode each need their own entry per
environment (four total), and gave no way to tell which flow's
request was actually failing.
Added the full four-URI table and a note to check the browser's actual
address bar at the point of failure — the error message is identical
regardless of which flow's redirect_uri didn't match.
Based on bingo-bango by f8al (MIT) — same core card-generation idea
("both facets": a square is either an exact song title or an artist,
and an artist square lights up on any of their tracks), reworked with
a real host/guest split, live multiplayer sessions, and cover-art
squares. f8al credited in the footer, README, and PROPOSAL.md.
Three ways to play: host a live session (server-side Spotify
connection, join code + QR, caller screen, auto-call from real
playback), join someone else's session (no login needed), or solo
(guest PKCE login or a pasted public playlist URL, one-off card).
Genuinely verified against a real Spotify account throughout, not
just built and assumed working — including two real bugs found and
fixed along the way (Spotify's playlist-tracks endpoint quietly
renamed to /items with a reshaped response; reading playlist tracks
needs real user auth even for public playlists, so the "no guest
login" public-playlist path routes through the host's connection
instead of a dead-end app-only token). Both Docker images built and
run together on a real network with the nginx proxy verified working
end-to-end, and auto-call confirmed detecting an actual track playing
live through Spotify Connect within one poll tick.