Hotstar API是否采用statefull架构?未登录用户追踪及直播时长机制问询
Hey there! Let's break down your questions about Hotstar's architecture and user tracking for unauthenticated users:
First off, Hotstar's core APIs are primarily stateless—following modern RESTful design principles to support easy horizontal scaling. That said, they do implement stateful-like tracking for unauthenticated users to maintain context across sessions.
For tracking unlogged-in users, Hotstar relies on a combination of these methods:
- Device Fingerprinting: It collects unique device/browser attributes like User-Agent string, screen resolution, OS version, installed browser plugins, and even limited hardware details (where accessible). These attributes are hashed into a unique "fingerprint" that the server uses to identify the same device across visits.
- First-Party Cookies: Even without logging in, Hotstar drops first-party cookies containing an anonymous user ID (e.g.,
anonymous_id). This ID is sent with every subsequent request, letting the server link your actions to a single anonymous profile. - Client-Side Storage: In some cases, it uses Local Storage or Session Storage to store backup anonymous identifiers, acting as a fallback if cookies are cleared (though this doesn't help with incognito mode, where these storages are wiped on session end).
- IP Address Context: While IPs aren't unique to a single device (e.g., shared WiFi), they're combined with other data to refine device identification, though they're not the primary tracking method.
This restriction is tied directly to device identity, not browser sessions—which is why refreshing the page or using incognito mode doesn't bypass it, but switching devices does. Here's how it works:
- Server-Side Device Fingerprint Mapping: When you first load the cricket stream, Hotstar's backend creates a record tied to your device's fingerprint. This record stores your remaining watch time and is persisted in their database.
- Real-Time Validation on Stream Requests: Every time your device requests stream data, the server checks the associated fingerprint's watch time record. Even if you refresh or use incognito (which only clears browser-level data, not your device's core fingerprint attributes), the server recognizes the same device and enforces the remaining limit.
- Why Incognito Fails: Incognito mode erases cookies and local storage, but it doesn't change your device's inherent attributes (like User-Agent or hardware specs) that form the fingerprint. The server still matches your device to the existing watch time record.
- Device Swap Bypasses the Limit: A new device will generate a completely unique fingerprint. The server sees this as a fresh unauthenticated user, so it creates a new record with a full 5-minute watch allowance.
These mechanisms balance user experience (letting casual users sample content) with business goals (encouraging logins/subscriptions) while preventing abuse of the free access window.
内容的提问来源于stack exchange,提问作者user12634860

