Commit graph

199 commits

Author SHA1 Message Date
Deluan
d1b876097f refactor(api): use the grant secret as the API v1 bearer credential
API v1 no longer mints short-lived JWT access tokens. Clients send the grant
secret from POST /auth/login or /auth/setup as `Authorization: Bearer` on
every request.

Every request already looked the grant up in the database, so the JWT gave
no speed or revocation benefit and only added a refresh loop, which early
client authors pushed back on. The grant already is an API key: one per
client sign-in, scoped and revocable. Revocation is now immediate on every
node; the contract promises "within one minute".

Removed: POST /auth/token, the grantAuth scheme, the TokenRequest and
AccessToken schemas, the token_expired problem code, the API v1 JWT signer
and its signing key, the grant liveness cache, and PropertyRepository.PutIfAbsent.
ResolveGrant is now Authenticate.

Short-lived tokens return later only as narrow media tokens for
?access_token= on media URLs, together with the media endpoints.

Signed-off-by: Deluan <deluan@navidrome.org>
2026-09-28 21:05:57 -04:00
Deluan
8789561b60 fix(api): consolidate grant deletes and harden API v1 auth after review
- GrantRepository keeps three deletes: DeleteForUser, DeleteStaleEpochs
  (replaces DeleteOtherEpochs and DeleteIfEpoch) and DeleteIdle. Delete(id)
  is gone; the idle path in ResolveGrant now calls DeleteIdle, so a grant
  renewed by another node between the read and the delete survives.
  settleEpoch deletes the user's grants below the snapshot's epoch, which
  is safe outside the transaction because epochs only move forward.
- The "dead grants on an older epoch are only deleted when presented"
  policy note moves from the repository to core ListGrants.
- SQL trace logging no longer prints the args of property writes (signing
  keys) or user password writes, both encrypted with a key that may be the
  public default. The SQL statement is still logged.
- The spec gate rejects JSON body keys that differ from a declared property
  only in case. kin-openapi validates exact names while encoding/json
  decodes case-insensitively, so {"scopes":[],"Scopes":null} minted a
  token with every scope and a "Client" key skipped maxLength.
  It also rejects data after the first JSON value, which the handlers'
  decoder ignores and which let a body skip the alias check.
- The liveness cache trims its eviction log on evict, not only on put, so
  evict-only traffic stays bounded; the floor still drops stale fills.
- createAccessToken, login and setupFirstAdmin declare Cache-Control:
  no-store on their success responses.
2026-09-28 20:06:28 -04:00
Deluan
45d8a7724d test(api): share API v1 test helpers and check scopes in Go
Move the end-to-end call/setup/mint helpers to a suite-level test client
and the apiauth login/mustMint helpers to package level. Replace the
hardcoded vacuum x-scope enum with a Go test that every known scope is
a valid spec Scope; the gate already rejects unknown x-scope values.
2026-09-28 20:06:28 -04:00
Deluan
88a652346b docs(api): say a password change ends the user's other Navidrome sessions
changePassword now documents that on Navidrome the change also ends the
user's sessions on its other APIs, regardless of revokeOtherGrants, which
only covers API v1 grants.
2026-09-28 20:06:28 -04:00
Deluan
28d023449d feat(api): report login methods and add GET /capabilities 2026-09-28 20:06:27 -04:00
Deluan
294c1a9a6a feat(api): add API v1 login, setup, token, grant and password endpoints
Adds the seven auth operations to the spec (createAccessToken, listGrants,
revokeGrant and logout in core; login, setupFirstAdmin and changePassword in
the password module), the bearerAuth/grantAuth schemes, and vacuum rules
requiring explicit security and a known x-scope. The strict handlers sit on
core/apiauth and are covered end to end against a real SQLite database.

The first operations with parameters make the generated code import
github.com/oapi-codegen/runtime. An oapi-codegen overlay renames the shared
offset/limit parameter types, since a generated Offset clashes with Ginkgo's
dot-imported Offset in this package's tests; the published spec is unchanged.
2026-09-28 20:06:27 -04:00
Deluan
3e645959f8 feat(api): enforce API v1 security from the spec and harden problem responses 2026-09-28 20:06:27 -04:00
Deluan Quintão
c22ce9ebb2
feat(api): add the API v1 foundation behind DevAPIv1 (#6227)
* feat(api): add OpenAPI v1 spec skeleton, lint ruleset and bundle tooling

vacuum v0.30.6's `bundle --composed` mangles component names for this
spec's multi-file layout (duplicates Problem as Problem__schemas etc.),
so api-bundle uses the Redocly CLI (npx @redocly/cli bundle) instead.

* fix(api): pin the Redocly CLI version

Tried moving components out of the root document (per libopenapi's
nested_files example) so vacuum's own bundler could produce clean
names, but any component declared via $ref inside components.* still
gets a __<parent>-suffixed twin regardless of collisions elsewhere, so
vacuum's --composed bundler can't cleanly bundle this spec. Pin the
already-working Redocly fallback to an exact version instead of
@latest.

* fix(api): bundle the OpenAPI spec with vacuum

vacuum's --composed bundler suffixes any component reached via a $ref
written directly inside the root document's own components.* block,
regardless of collisions elsewhere. Dropping the root-level schemas/
parameters/responses declarations (keeping only securitySchemes, and
leaving every component file under api/openapi/components/ untouched)
lets vacuum bundle cleanly with no __ suffixes, going back to Go-only
tooling. Components nothing references yet (ListMeta, offset, limit,
BadRequest, Unauthorized, Forbidden, NotFound) are absent from the
bundle until a later task's operation references them.

* fix(api): make spec lint rules cover all schemas and error codes

nd-schema-property-descriptions targeted $.components.schemas, but our
schemas live in path/response files, not the root document, so it was
dead code; switched to $..properties[*] to walk every resolved schema
wherever it ends up. nd-error-responses-are-problems only checked a
hardcoded status-code list; switched to a patternProperties schema
matching the full 4xx/5xx range. Also: api-diff now diffs against the
merge-base with API_DIFF_BASE (falling back to its tip with a notice
if no merge-base exists), gen no longer depends on api-gen until Task
3 wires up oapi-codegen, and api-lint suppresses vacuum's banner.

* feat(api): embed the bundled OpenAPI spec and expose its version

* feat(api): generate the v1 server interface with oapi-codegen

* feat(api): add RFC 9457 problem responses for API v1

* feat(api): add API v1 router with /server discovery and spec routes

* fix(api): serve the OpenAPI document without range support

* feat(api): mount API v1 behind the DevAPIv1 flag

* chore(ci): lint, regenerate and diff the OpenAPI v1 spec

* refactor(api): tighten spec version access, lint rules and test naming

* refactor(api): simplify spec routes, tests and OpenAPI tooling

Share one If-None-Match parser (utils/req) between the image and spec
routes, declare the YAML spec response as an object so tests need no
decoder override, and reuse ETag/304 spec components.

Install the OpenAPI tools only when missing or at a different version,
fail api-diff when its base ref does not exist, and in CI cache the
tools, fold regeneration into the go generate check, and fetch only the
PR base commit for the breaking-change gate.

* refactor(api): raise the list limit maximum to 2000 and drop the flag test

* feat(api): treat added enum values as non-breaking

Enums in API v1 are open: clients must accept unknown values. api-diff
now downgrades response-property-enum-value-added to INFO, while
removing a value from a request enum stays breaking.

* feat(api): gate breaking changes on x-stability-level

Every operation declares x-stability-level (alpha, beta, stable). oasdiff
ignores breaking changes to alpha operations and rejects lowering a
level, so unreleased endpoints can evolve while beta and stable ones
stay additive. All current operations start as alpha.

* feat(api): declare loginMethods as an enum

Prefix generated enum constants with their type name so enums sharing a
value (for example password) cannot collide in package apiv1.

* feat(api): send Allow on 405 and answer HEAD wherever GET is routed

chi only sets Allow in its default 405 handler, so the problem-format
handler now builds it by matching each method against the v1 router.
HEAD requests fall back to the GET route, as RFC 9110 expects.

* refactor(api): hash the spec ETag with xxh3

The bytes are compiled in, and the digest was truncated to 64 bits
anyway, so this matches the artwork ETags instead of paying for
cryptographic strength we discard.

* docs(api): explain the about:blank problem type

* feat(api): make code the problem identifier and omit a blank type

RFC 9457 says clients switch on the type URI, but no adopter surveyed
ships both a populated type and a separate code. Declare code as an
enum, and send type only once a problem has semantics of its own.

* fix(api): advertise the configured base path in the served OpenAPI spec

With BaseURL=/music the API is mounted at /music/api/v1, but the spec
told clients to call /api/v1 at the host root. The server now rewrites
servers[0].url to BasePath + /api/v1 when it serves the document.

Relative server URLs were tested first: "." and "../v1" work in
openapi-generator, Swagger UI and Redoc, but Scalar resolves them
against the page origin, so it breaks even without a base path. The
committed bundle keeps /api/v1, and a test pins that it appears exactly
once, which the rewrite relies on.
2026-09-26 15:27:23 -04:00
Deluan
7610b42f4b Moved package api to subsonic under server 2020-01-19 18:23:09 -05:00
Deluan
67eeb218c4 Big Refactor:
- Create model.DataStore, with provision for transactions
- Change all layers dependencies on repositories to use DataStore
- Implemented persistence.SQLStore
- Removed iTunes Bridge/Importer support
2020-01-19 16:28:09 -05:00
Deluan
128e165aba Add Stars to the DB, including Artists! Only if DevUseFolderScanner is true 2020-01-18 20:03:52 -05:00
Deluan
c0beaa6377 Integrate ArtistIndex logic into Artist 2020-01-17 20:54:28 -05:00
Deluan
814db3f033 Add extension to snapshots files (make it easier to format them for visualization) 2020-01-15 18:03:22 -05:00
Deluan
36d93774bc Add GetGenre endpoint 2020-01-15 17:56:02 -05:00
Deluan
0ea2bd79d9 Rename domain to model 2020-01-14 22:22:34 -05:00
Deluan
31dfab90bd Simplify StreamController 2020-01-14 15:34:18 -05:00
Deluan
d68342bd97 Add a 410-Gone handler for endpoints that will not be implemented 2020-01-13 20:45:38 -05:00
Deluan
614f4afe28 Implement Artist search with SQL, removed old search/indexer code 2020-01-13 16:06:30 -05:00
Deluan
bfac3e3c91 Refactor: NewResponse is more explicit 2020-01-11 17:18:20 -05:00
Deluan
23e080bc15 Remove stuttering 2020-01-11 17:08:10 -05:00
Deluan
52fc580a2b Expose mediafile.AbsolutePath to remove dependency of the persistence layer in the API layer 2020-01-11 15:27:32 -05:00
Deluan
48b465f2fb Simplify API routes mounting 2020-01-11 15:27:32 -05:00
Deluan
5acc9c7a22 Make DisableAuthentication a Dev flag 2020-01-11 15:27:32 -05:00
Deluan
30ebbc1fa1 Move API dependency injection to main package, opening the possibility to switch persistence without code changes 2020-01-11 15:27:32 -05:00
Deluan
52f682debf Remove state from SearchController 2020-01-11 15:27:32 -05:00
Deluan
dc6b812587 Remove state from StreamController 2020-01-11 15:27:32 -05:00
Deluan
cead8906d6 Implements NowPlayingRepository as an in-memory only struct 2020-01-11 15:27:32 -05:00
Deluan
4f151a7409 Storm PlaylistRepository complete. 2020-01-11 15:27:32 -05:00
Deluan
70d7793147 Moved MediaFolders Repository to persistence agnostic package 2020-01-11 15:27:32 -05:00
Deluan
11f4505925 Renamed persistence packages 2020-01-11 15:27:32 -05:00
Deluan
dbeba1dea9 Storm MediaFileRepository complete. 2020-01-11 15:27:32 -05:00
Deluan
c608e917db Storm AlbumRepository complete. 2020-01-11 15:27:32 -05:00
Deluan
0ca691b37f Storm ArtistRepository and PropertyRepository complete. 2020-01-11 15:27:32 -05:00
Deluan
40904b220e Renamed Id to ID, following GoLang convention 2020-01-11 15:27:32 -05:00
Deluan
018352463f Moved ledis implementation to a new package 2020-01-11 15:27:32 -05:00
Deluan
d90c1cdc44 Removed commented out tests 2020-01-09 22:50:01 -05:00
Deluan
ee5cda38fb Restore AlbumListController tests 2020-01-09 22:44:45 -05:00
Deluan
b1e58352e9 Restore MediaRetrievalController tests 2020-01-09 22:44:45 -05:00
Deluan
0c3edc0279 Rewriting Response tests as snapshot tests 2020-01-09 22:44:45 -05:00
Deluan
6aa6c2d9a5 Add middleware tests 2020-01-09 22:44:45 -05:00
Deluan
ff5b91da54 Renamed DisableValidation to DisableAuthentication 2020-01-09 22:44:45 -05:00
Deluan
a706429a4a Don't disable required params check 2020-01-09 22:44:45 -05:00
Deluan
542bea6fcc Setting correct content-type for JSONP 2020-01-09 22:44:45 -05:00
Deluan
84d69a4f41 Replaced Beego logging 2020-01-09 22:44:45 -05:00
Deluan
c9605862a1 Add support for endpoints without .view 2020-01-09 22:44:45 -05:00
Deluan
23e38ec82f Removed (almost) all remaining init() 2020-01-09 22:44:45 -05:00
Deluan
e8a8313b43 Removed inject lib, only use wire for DI 2020-01-09 22:44:45 -05:00
Deluan
79701caca3 Removed Beego routing/controllers, converted to Chi.
Also introduced Wire for dependency injection
2020-01-09 22:44:45 -05:00
Deluan
f7c182b1f8 Fixes context, and adds more info to it 2017-04-03 23:53:38 -04:00
Deluan
2861a97a89 Introduces context.Context in API controllers 2017-04-03 00:16:21 -04:00