mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-10 11:27:11 +02:00
On a multi-library instance, a few reads and writes built their own queries without the per-user library filter that every other media read applies. A user granted only some libraries could see, and store, tracks from libraries they had no access to. - getBookmarks now filters the query. It has to be the query and not the result: the loop below it pre-sizes the response from the bookmark count, so a row dropped afterwards would emit an empty bookmark entry. - createBookmark rejects an id the caller cannot read, returning error 70 to match getSong. Stored rows are left alone rather than purged, so a temporary revoke does not lose saved playback positions. - playlistTrackRepository Read, Count and GetAlbumIDs get the filter their siblings CountAll and GetMediaFileIDs already had. Read is the one that mattered most: its id is the integer playlist position, so it needed no track id at all. - Playlist track writes are filtered in playlistRepository.addTracks, the only writer of playlist_tracks rows apart from smart playlists, so Add, Insert, AddAlbums/AddArtists/AddDiscs and a full replace through Put all go through it. Insert reserves a slot per requested id, so when the filter drops one it renumbers to close the hole. - playTracker.GetNowPlaying honours its context instead of discarding it. The cache is process-global, so the filter belongs in the tracker rather than in the Subsonic handler, and any future caller inherits it. Admins and single-library installs are unaffected: applyLibraryFilter and HasLibraryAccess both short-circuit for them. Scanner playlist sync runs as admin, and M3U and CLI imports already resolve tracks through FindByPaths as the same user, so neither changes.
224 lines
5.2 KiB
Go
224 lines
5.2 KiB
Go
package subsonic
|
|
|
|
import (
|
|
"errors"
|
|
"net/http"
|
|
"time"
|
|
|
|
"github.com/navidrome/navidrome/model"
|
|
"github.com/navidrome/navidrome/model/request"
|
|
"github.com/navidrome/navidrome/server/subsonic/responses"
|
|
"github.com/navidrome/navidrome/utils/req"
|
|
"github.com/navidrome/navidrome/utils/slice"
|
|
)
|
|
|
|
func (api *Router) GetBookmarks(r *http.Request) (*responses.Subsonic, error) {
|
|
user, _ := request.UserFrom(r.Context())
|
|
|
|
repo := api.ds.MediaFile(r.Context())
|
|
bookmarks, err := repo.GetBookmarks()
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
response := newResponse()
|
|
response.Bookmarks = &responses.Bookmarks{}
|
|
response.Bookmarks.Bookmark = slice.Map(bookmarks, func(bmk model.Bookmark) responses.Bookmark {
|
|
return responses.Bookmark{
|
|
Entry: childFromMediaFile(r.Context(), bmk.Item),
|
|
Position: bmk.Position,
|
|
Username: user.UserName,
|
|
Comment: bmk.Comment,
|
|
Created: bmk.CreatedAt,
|
|
Changed: bmk.UpdatedAt,
|
|
}
|
|
})
|
|
return response, nil
|
|
}
|
|
|
|
func (api *Router) CreateBookmark(r *http.Request) (*responses.Subsonic, error) {
|
|
p := req.Params(r)
|
|
id, err := p.String("id")
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
comment, _ := p.String("comment")
|
|
position := p.Int64Or("position", 0)
|
|
|
|
repo := api.ds.MediaFile(r.Context())
|
|
ok, err := repo.Exists(id)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
if !ok {
|
|
return nil, newError(responses.ErrorDataNotFound, "Song not found")
|
|
}
|
|
|
|
err = repo.AddBookmark(id, comment, position)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return newResponse(), nil
|
|
}
|
|
|
|
func (api *Router) DeleteBookmark(r *http.Request) (*responses.Subsonic, error) {
|
|
p := req.Params(r)
|
|
id, err := p.String("id")
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
repo := api.ds.MediaFile(r.Context())
|
|
err = repo.DeleteBookmark(id)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return newResponse(), nil
|
|
}
|
|
|
|
func (api *Router) GetPlayQueue(r *http.Request) (*responses.Subsonic, error) {
|
|
user, _ := request.UserFrom(r.Context())
|
|
|
|
repo := api.ds.PlayQueue(r.Context())
|
|
pq, err := repo.RetrieveWithMediaFiles(user.ID)
|
|
if err != nil && !errors.Is(err, model.ErrNotFound) {
|
|
return nil, err
|
|
}
|
|
if pq == nil || len(pq.Items) == 0 {
|
|
response := newResponse()
|
|
response.PlayQueue = &responses.PlayQueue{
|
|
Username: user.UserName,
|
|
}
|
|
return response, nil
|
|
}
|
|
|
|
response := newResponse()
|
|
var currentID string
|
|
if pq.Current >= 0 && pq.Current < len(pq.Items) {
|
|
currentID = pq.Items[pq.Current].ID
|
|
}
|
|
response.PlayQueue = &responses.PlayQueue{
|
|
Entry: slice.MapWithArg(pq.Items, r.Context(), childFromMediaFile),
|
|
Current: currentID,
|
|
Position: pq.Position,
|
|
Username: user.UserName,
|
|
Changed: pq.UpdatedAt,
|
|
ChangedBy: pq.ChangedBy,
|
|
}
|
|
return response, nil
|
|
}
|
|
|
|
func (api *Router) SavePlayQueue(r *http.Request) (*responses.Subsonic, error) {
|
|
p := req.Params(r)
|
|
ids := p.Strings("id")
|
|
currentID, _ := p.String("current")
|
|
position := p.Int64Or("position", 0)
|
|
|
|
user, _ := request.UserFrom(r.Context())
|
|
client, _ := request.ClientFrom(r.Context())
|
|
|
|
items := slice.Map(ids, func(id string) model.MediaFile {
|
|
return model.MediaFile{ID: id}
|
|
})
|
|
|
|
currentIndex := 0
|
|
for i, id := range ids {
|
|
if id == currentID {
|
|
currentIndex = i
|
|
break
|
|
}
|
|
}
|
|
|
|
pq := &model.PlayQueue{
|
|
UserID: user.ID,
|
|
Current: currentIndex,
|
|
Position: position,
|
|
ChangedBy: client,
|
|
Items: items,
|
|
CreatedAt: time.Time{},
|
|
UpdatedAt: time.Time{},
|
|
}
|
|
|
|
repo := api.ds.PlayQueue(r.Context())
|
|
err := repo.Store(pq)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return newResponse(), nil
|
|
}
|
|
|
|
func (api *Router) GetPlayQueueByIndex(r *http.Request) (*responses.Subsonic, error) {
|
|
user, _ := request.UserFrom(r.Context())
|
|
|
|
repo := api.ds.PlayQueue(r.Context())
|
|
pq, err := repo.RetrieveWithMediaFiles(user.ID)
|
|
if err != nil && !errors.Is(err, model.ErrNotFound) {
|
|
return nil, err
|
|
}
|
|
if pq == nil || len(pq.Items) == 0 {
|
|
response := newResponse()
|
|
response.PlayQueueByIndex = &responses.PlayQueueByIndex{
|
|
Username: user.UserName,
|
|
}
|
|
return response, nil
|
|
}
|
|
|
|
response := newResponse()
|
|
|
|
var index *int
|
|
if len(pq.Items) > 0 {
|
|
index = &pq.Current
|
|
}
|
|
|
|
response.PlayQueueByIndex = &responses.PlayQueueByIndex{
|
|
Entry: slice.MapWithArg(pq.Items, r.Context(), childFromMediaFile),
|
|
CurrentIndex: index,
|
|
Position: pq.Position,
|
|
Username: user.UserName,
|
|
Changed: pq.UpdatedAt,
|
|
ChangedBy: pq.ChangedBy,
|
|
}
|
|
return response, nil
|
|
}
|
|
|
|
func (api *Router) SavePlayQueueByIndex(r *http.Request) (*responses.Subsonic, error) {
|
|
p := req.Params(r)
|
|
ids := p.Strings("id")
|
|
|
|
position := p.Int64Or("position", 0)
|
|
|
|
var err error
|
|
var currentIndex int
|
|
|
|
if len(ids) > 0 {
|
|
currentIndex, err = p.Int("currentIndex")
|
|
if err != nil || currentIndex < 0 || currentIndex >= len(ids) {
|
|
return nil, newError(responses.ErrorMissingParameter, "missing parameter index, err: %s", err)
|
|
}
|
|
}
|
|
|
|
items := slice.Map(ids, func(id string) model.MediaFile {
|
|
return model.MediaFile{ID: id}
|
|
})
|
|
|
|
user, _ := request.UserFrom(r.Context())
|
|
client, _ := request.ClientFrom(r.Context())
|
|
|
|
pq := &model.PlayQueue{
|
|
UserID: user.ID,
|
|
Current: currentIndex,
|
|
Position: position,
|
|
ChangedBy: client,
|
|
Items: items,
|
|
CreatedAt: time.Time{},
|
|
UpdatedAt: time.Time{},
|
|
}
|
|
|
|
repo := api.ds.PlayQueue(r.Context())
|
|
err = repo.Store(pq)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return newResponse(), nil
|
|
}
|