mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-08 10:27:08 +02:00
docs(jellyfin): correct the rationale for the public image endpoint (#6114)
The comment justified anonymous access with "item ids are unguessable". That is not true: an artist id is a deterministic, unsalted hash of the artist name, id.NewHash(id.NewHash(str.Clear(lower(name)))), so it is computable offline by anyone who knows the name. The real reason the route is public is that upstream Jellyfin's is too. ImageController.GetItemImage carries no [Authorize] attribute (verified on v12.0, master/13.0.0, v10.11.9 and v10.10.7), and an anonymous request reaches LibraryManager.ItemIsVisible with a null user, which returns true unconditionally. Clients build cover URLs with no credentials at all, so requiring auth here would break them. No behavior change.
This commit is contained in:
parent
bea9715001
commit
043de7a86c
1 changed files with 2 additions and 2 deletions
|
|
@ -34,8 +34,8 @@ func imageSize(maxWidth, maxHeight int) int {
|
|||
}
|
||||
|
||||
func (api *Router) getItemImage(w http.ResponseWriter, r *http.Request) {
|
||||
// Public endpoint, like real Jellyfin's image routes: clients fetch cover URLs without credentials
|
||||
// and item ids are unguessable, so resolution runs elevated to bypass the visibility filter.
|
||||
// Public, like Jellyfin's own image routes: clients build cover URLs without credentials, and
|
||||
// upstream resolves them with no visibility check either (LibraryManager.ItemIsVisible, null user).
|
||||
ctx := request.WithUser(r.Context(), model.User{IsAdmin: true})
|
||||
itemId, ok := itemIDParam(w, r, "itemId")
|
||||
if !ok {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue