mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-08 18:37:09 +02:00
Two blocking bugs found while reviewing this branch: 1. Compile error: validateURL() was called in fetchAndParse/doDownload (added while applying Strix's SSRF suggestions) but the function itself was never committed - only "Add validateURL and isReservedIP helper functions" was left as a plain-text suggestion with no one-click apply, and it got missed. Implemented validateURL/isReservedIP plus a safeHTTPTransport whose DialContext re-resolves and re-checks the target IP at actual connection time (not just once via a URL pre-check), so a DNS answer that changes between the check and the request (DNS rebinding) can't reach a reserved address - this also covers HTTP redirect targets for free, since redirects reuse the same Transport. Added AllowLoopbackHTTPForTests() so the existing httptest-based suite (which binds to 127.0.0.1) still passes without weakening the guard for any other address. 2. Migration boot failure: the podcast migrations were dated 2026-04-27/28 (when the feature was actually developed), but goose.UpContext (as this project calls it, no WithAllowMissing) hard-errors on any pending migration older than the DB's already-applied max version. Any install already past April on current master would fail to start entirely on upgrade. Renumbered all 5 podcast migrations to 2026-09-02 (after everything currently on master). This also meant the podcast_* columns added to the already-shipped uniform_canonical_ids migration's idColumns were dead code for any install that had already run that migration - editing an applied migration's Go source doesn't make it re-run. Reverted that edit and split the podcast id canonicalization into its own, later migration (20260902000005) that reuses the same buildIDMap/ applyIDMap machinery. Verified both fresh-install and existing-install upgrade paths end-to-end against real sqlite DBs: no boot error, and legacy-shaped podcast ids (plus their FK references) get correctly rewritten to canonical form. Verified: full build clean, core/podcasts + server/nativeapi + db/migrations test suites all pass, gofmt clean. |
||
|---|---|---|
| .. | ||
| agents | ||
| artwork | ||
| auth | ||
| external | ||
| ffmpeg | ||
| lyrics | ||
| matcher | ||
| metrics | ||
| playback | ||
| playlists | ||
| podcasts | ||
| publicurl | ||
| scrobbler | ||
| sonic | ||
| storage | ||
| stream | ||
| archiver.go | ||
| archiver_test.go | ||
| common.go | ||
| common_test.go | ||
| core_suite_test.go | ||
| inspect.go | ||
| library.go | ||
| library_test.go | ||
| maintenance.go | ||
| maintenance_test.go | ||
| players.go | ||
| players_test.go | ||
| share.go | ||
| share_test.go | ||
| user.go | ||
| user_test.go | ||
| wire_providers.go | ||