2020-02-29 20:01:09 -05:00
|
|
|
package persistence
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"context"
|
|
|
|
|
|
|
|
|
|
. "github.com/Masterminds/squirrel"
|
|
|
|
|
"github.com/deluan/rest"
|
|
|
|
|
"github.com/navidrome/navidrome/model"
|
2023-12-09 13:52:17 -05:00
|
|
|
"github.com/pocketbase/dbx"
|
2020-02-29 20:01:09 -05:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
type transcodingRepository struct {
|
|
|
|
|
sqlRepository
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func NewTranscodingRepository(db dbx.Builder) model.TranscodingRepository {
|
2020-02-29 20:01:09 -05:00
|
|
|
r := &transcodingRepository{}
|
2023-12-09 13:52:17 -05:00
|
|
|
r.db = db
|
2024-09-09 19:45:02 -04:00
|
|
|
r.registerModel(&model.Transcoding{}, nil)
|
2020-02-29 20:01:09 -05:00
|
|
|
return r
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) Get(ctx context.Context, id string) (*model.Transcoding, error) {
|
|
|
|
|
sel := r.newSelect(ctx).Columns("*").Where(Eq{"id": id})
|
2020-03-16 12:56:15 -04:00
|
|
|
var res model.Transcoding
|
2026-09-25 18:06:10 -04:00
|
|
|
err := r.queryOne(ctx, sel, &res)
|
2020-03-16 12:56:15 -04:00
|
|
|
return &res, err
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) CountAll(ctx context.Context, qo ...model.QueryOptions) (int64, error) {
|
|
|
|
|
return r.count(ctx, Select(), qo...)
|
2020-03-17 16:49:37 -04:00
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) FindByFormat(ctx context.Context, format string) (*model.Transcoding, error) {
|
|
|
|
|
sel := r.newSelect(ctx).Columns("*").Where(Eq{"target_format": format})
|
2020-03-16 14:28:13 -04:00
|
|
|
var res model.Transcoding
|
2026-09-25 18:06:10 -04:00
|
|
|
err := r.queryOne(ctx, sel, &res)
|
2020-03-16 14:28:13 -04:00
|
|
|
return &res, err
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) Put(ctx context.Context, t *model.Transcoding) error {
|
|
|
|
|
if !loggedUser(ctx).IsAdmin {
|
2025-05-21 22:19:23 -04:00
|
|
|
return rest.ErrPermissionDenied
|
|
|
|
|
}
|
2026-09-25 18:06:10 -04:00
|
|
|
_, err := r.put(ctx, t.ID, t)
|
2020-02-29 20:01:09 -05:00
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) Count(ctx context.Context, options ...rest.QueryOptions) (int64, error) {
|
|
|
|
|
return r.count(ctx, Select(), r.parseRestOptions(ctx, options...))
|
2020-02-29 20:01:09 -05:00
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) Read(ctx context.Context, id string) (*model.Transcoding, error) {
|
|
|
|
|
res, err := r.Get(ctx, id)
|
fix: restrict transcoding config reads to admins (#5564)
* fix(security): restrict transcoding config reads to admins
Authenticated non-admin users could read transcoding configs through
the native API (GET /api/transcoding and /api/transcoding/{id}) when
EnableTranscodingConfig was enabled. The responses included the full
command templates, disclosing admin-configured ffmpeg invocations and
local command paths. Write operations were already admin-only.
The /transcoding route was registered in the general authenticated
group, and only the repository's write methods checked IsAdmin. This
applies the boundary at two layers:
- Move the route under adminOnlyMiddleware, alongside the other
admin-only resources (/library, /config, /inspect).
- Add an IsAdmin guard to the repository's rest.Repository read
methods (Read, ReadAll, Count) as defense-in-depth.
The guard is scoped to the REST methods only. The streaming pipeline
resolves profiles via Get/FindByFormat (model.TranscodingRepository),
which stay open so transcoding keeps working for non-admin users.
Adds regression tests covering non-admin read denial and confirming
non-admin streaming lookups (Get/FindByFormat) still succeed.
* fix(security): redact transcoding Command for non-admins instead of blocking reads
Reworks the previous approach after review (Codex P2): moving /transcoding
under adminOnlyMiddleware and denying non-admin reads broke legitimate
non-admin UI flows. The web UI reads the transcoding resource as a regular
user in several places that need only the profile name and target format:
the player edit dropdown (ReferenceInput), the player list (ReferenceField),
and the share/download format pickers (useGetList -> {targetFormat, name}).
The only sensitive field is Command (the admin-owned ffmpeg template). So:
- Revert the route move; /transcoding stays in the authenticated group.
- Read/ReadAll now return the profiles to any authenticated user but blank
the Command field for non-admins (mirrors user_repository's field-level
redaction). Count is no longer denied (the UI needs list pagination).
- Writes remain admin-only (Save/Update/Delete/Put).
- Streaming is unaffected: it resolves profiles via Get/FindByFormat, which
are not redacted, so on-the-fly transcoding keeps working for non-admins.
Tests updated: non-admin reads succeed with Command blank, admin reads keep
Command, non-admin Get/FindByFormat keep Command, writes still denied.
2026-06-04 23:07:13 -04:00
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
2026-09-25 18:06:10 -04:00
|
|
|
if !loggedUser(ctx).IsAdmin {
|
fix: restrict transcoding config reads to admins (#5564)
* fix(security): restrict transcoding config reads to admins
Authenticated non-admin users could read transcoding configs through
the native API (GET /api/transcoding and /api/transcoding/{id}) when
EnableTranscodingConfig was enabled. The responses included the full
command templates, disclosing admin-configured ffmpeg invocations and
local command paths. Write operations were already admin-only.
The /transcoding route was registered in the general authenticated
group, and only the repository's write methods checked IsAdmin. This
applies the boundary at two layers:
- Move the route under adminOnlyMiddleware, alongside the other
admin-only resources (/library, /config, /inspect).
- Add an IsAdmin guard to the repository's rest.Repository read
methods (Read, ReadAll, Count) as defense-in-depth.
The guard is scoped to the REST methods only. The streaming pipeline
resolves profiles via Get/FindByFormat (model.TranscodingRepository),
which stay open so transcoding keeps working for non-admin users.
Adds regression tests covering non-admin read denial and confirming
non-admin streaming lookups (Get/FindByFormat) still succeed.
* fix(security): redact transcoding Command for non-admins instead of blocking reads
Reworks the previous approach after review (Codex P2): moving /transcoding
under adminOnlyMiddleware and denying non-admin reads broke legitimate
non-admin UI flows. The web UI reads the transcoding resource as a regular
user in several places that need only the profile name and target format:
the player edit dropdown (ReferenceInput), the player list (ReferenceField),
and the share/download format pickers (useGetList -> {targetFormat, name}).
The only sensitive field is Command (the admin-owned ffmpeg template). So:
- Revert the route move; /transcoding stays in the authenticated group.
- Read/ReadAll now return the profiles to any authenticated user but blank
the Command field for non-admins (mirrors user_repository's field-level
redaction). Count is no longer denied (the UI needs list pagination).
- Writes remain admin-only (Save/Update/Delete/Put).
- Streaming is unaffected: it resolves profiles via Get/FindByFormat, which
are not redacted, so on-the-fly transcoding keeps working for non-admins.
Tests updated: non-admin reads succeed with Command blank, admin reads keep
Command, non-admin Get/FindByFormat keep Command, writes still denied.
2026-06-04 23:07:13 -04:00
|
|
|
res.Command = ""
|
|
|
|
|
}
|
|
|
|
|
return res, nil
|
2020-02-29 20:01:09 -05:00
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) ReadAll(ctx context.Context, options ...rest.QueryOptions) ([]model.Transcoding, error) {
|
|
|
|
|
sel := r.newSelect(ctx, r.parseRestOptions(ctx, options...)).Columns("*")
|
2020-02-29 20:01:09 -05:00
|
|
|
res := model.Transcodings{}
|
2026-09-25 18:06:10 -04:00
|
|
|
err := r.queryAll(ctx, sel, &res)
|
fix: restrict transcoding config reads to admins (#5564)
* fix(security): restrict transcoding config reads to admins
Authenticated non-admin users could read transcoding configs through
the native API (GET /api/transcoding and /api/transcoding/{id}) when
EnableTranscodingConfig was enabled. The responses included the full
command templates, disclosing admin-configured ffmpeg invocations and
local command paths. Write operations were already admin-only.
The /transcoding route was registered in the general authenticated
group, and only the repository's write methods checked IsAdmin. This
applies the boundary at two layers:
- Move the route under adminOnlyMiddleware, alongside the other
admin-only resources (/library, /config, /inspect).
- Add an IsAdmin guard to the repository's rest.Repository read
methods (Read, ReadAll, Count) as defense-in-depth.
The guard is scoped to the REST methods only. The streaming pipeline
resolves profiles via Get/FindByFormat (model.TranscodingRepository),
which stay open so transcoding keeps working for non-admin users.
Adds regression tests covering non-admin read denial and confirming
non-admin streaming lookups (Get/FindByFormat) still succeed.
* fix(security): redact transcoding Command for non-admins instead of blocking reads
Reworks the previous approach after review (Codex P2): moving /transcoding
under adminOnlyMiddleware and denying non-admin reads broke legitimate
non-admin UI flows. The web UI reads the transcoding resource as a regular
user in several places that need only the profile name and target format:
the player edit dropdown (ReferenceInput), the player list (ReferenceField),
and the share/download format pickers (useGetList -> {targetFormat, name}).
The only sensitive field is Command (the admin-owned ffmpeg template). So:
- Revert the route move; /transcoding stays in the authenticated group.
- Read/ReadAll now return the profiles to any authenticated user but blank
the Command field for non-admins (mirrors user_repository's field-level
redaction). Count is no longer denied (the UI needs list pagination).
- Writes remain admin-only (Save/Update/Delete/Put).
- Streaming is unaffected: it resolves profiles via Get/FindByFormat, which
are not redacted, so on-the-fly transcoding keeps working for non-admins.
Tests updated: non-admin reads succeed with Command blank, admin reads keep
Command, non-admin Get/FindByFormat keep Command, writes still denied.
2026-06-04 23:07:13 -04:00
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
2026-09-25 18:06:10 -04:00
|
|
|
if !loggedUser(ctx).IsAdmin {
|
fix: restrict transcoding config reads to admins (#5564)
* fix(security): restrict transcoding config reads to admins
Authenticated non-admin users could read transcoding configs through
the native API (GET /api/transcoding and /api/transcoding/{id}) when
EnableTranscodingConfig was enabled. The responses included the full
command templates, disclosing admin-configured ffmpeg invocations and
local command paths. Write operations were already admin-only.
The /transcoding route was registered in the general authenticated
group, and only the repository's write methods checked IsAdmin. This
applies the boundary at two layers:
- Move the route under adminOnlyMiddleware, alongside the other
admin-only resources (/library, /config, /inspect).
- Add an IsAdmin guard to the repository's rest.Repository read
methods (Read, ReadAll, Count) as defense-in-depth.
The guard is scoped to the REST methods only. The streaming pipeline
resolves profiles via Get/FindByFormat (model.TranscodingRepository),
which stay open so transcoding keeps working for non-admin users.
Adds regression tests covering non-admin read denial and confirming
non-admin streaming lookups (Get/FindByFormat) still succeed.
* fix(security): redact transcoding Command for non-admins instead of blocking reads
Reworks the previous approach after review (Codex P2): moving /transcoding
under adminOnlyMiddleware and denying non-admin reads broke legitimate
non-admin UI flows. The web UI reads the transcoding resource as a regular
user in several places that need only the profile name and target format:
the player edit dropdown (ReferenceInput), the player list (ReferenceField),
and the share/download format pickers (useGetList -> {targetFormat, name}).
The only sensitive field is Command (the admin-owned ffmpeg template). So:
- Revert the route move; /transcoding stays in the authenticated group.
- Read/ReadAll now return the profiles to any authenticated user but blank
the Command field for non-admins (mirrors user_repository's field-level
redaction). Count is no longer denied (the UI needs list pagination).
- Writes remain admin-only (Save/Update/Delete/Put).
- Streaming is unaffected: it resolves profiles via Get/FindByFormat, which
are not redacted, so on-the-fly transcoding keeps working for non-admins.
Tests updated: non-admin reads succeed with Command blank, admin reads keep
Command, non-admin Get/FindByFormat keep Command, writes still denied.
2026-06-04 23:07:13 -04:00
|
|
|
for i := range res {
|
|
|
|
|
res[i].Command = ""
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
return res, nil
|
2020-02-29 20:01:09 -05:00
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) Save(ctx context.Context, t *model.Transcoding) (string, error) {
|
|
|
|
|
if !loggedUser(ctx).IsAdmin {
|
2025-05-21 22:19:23 -04:00
|
|
|
return "", rest.ErrPermissionDenied
|
|
|
|
|
}
|
2026-09-25 18:06:10 -04:00
|
|
|
return r.put(ctx, t.ID, t)
|
2020-02-29 20:01:09 -05:00
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) Update(ctx context.Context, id string, entity model.Transcoding, cols ...string) error {
|
|
|
|
|
if !loggedUser(ctx).IsAdmin {
|
2025-05-21 22:19:23 -04:00
|
|
|
return rest.ErrPermissionDenied
|
|
|
|
|
}
|
2026-09-25 18:06:10 -04:00
|
|
|
t := &entity
|
2021-11-01 13:55:47 -04:00
|
|
|
t.ID = id
|
2026-09-25 18:06:10 -04:00
|
|
|
_, err := r.put(ctx, id, t)
|
2020-02-29 20:01:09 -05:00
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-25 18:06:10 -04:00
|
|
|
func (r *transcodingRepository) Delete(ctx context.Context, ids ...string) error {
|
|
|
|
|
if !loggedUser(ctx).IsAdmin {
|
2025-05-21 22:19:23 -04:00
|
|
|
return rest.ErrPermissionDenied
|
|
|
|
|
}
|
2026-09-25 18:06:10 -04:00
|
|
|
for _, id := range ids {
|
|
|
|
|
if err := r.deleteByID(ctx, id); err != nil {
|
|
|
|
|
return err
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
return nil
|
2020-02-29 20:01:09 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
var _ model.TranscodingRepository = (*transcodingRepository)(nil)
|
2026-09-25 18:06:10 -04:00
|
|
|
var _ rest.Repository[model.Transcoding] = (*transcodingRepository)(nil)
|
|
|
|
|
var _ rest.Persistable[model.Transcoding] = (*transcodingRepository)(nil)
|