navidrome/db
Jiho Andrew Lee 23f28aac66 fix(podcast): implement missing SSRF validation and fix migration boot failure
Two blocking bugs found while reviewing this branch:

1. Compile error: validateURL() was called in fetchAndParse/doDownload (added
   while applying Strix's SSRF suggestions) but the function itself was never
   committed - only "Add validateURL and isReservedIP helper functions" was
   left as a plain-text suggestion with no one-click apply, and it got missed.
   Implemented validateURL/isReservedIP plus a safeHTTPTransport whose
   DialContext re-resolves and re-checks the target IP at actual connection
   time (not just once via a URL pre-check), so a DNS answer that changes
   between the check and the request (DNS rebinding) can't reach a reserved
   address - this also covers HTTP redirect targets for free, since redirects
   reuse the same Transport. Added AllowLoopbackHTTPForTests() so the
   existing httptest-based suite (which binds to 127.0.0.1) still passes
   without weakening the guard for any other address.

2. Migration boot failure: the podcast migrations were dated 2026-04-27/28
   (when the feature was actually developed), but goose.UpContext (as this
   project calls it, no WithAllowMissing) hard-errors on any pending
   migration older than the DB's already-applied max version. Any install
   already past April on current master would fail to start entirely on
   upgrade. Renumbered all 5 podcast migrations to 2026-09-02 (after
   everything currently on master). This also meant the podcast_* columns
   added to the already-shipped uniform_canonical_ids migration's idColumns
   were dead code for any install that had already run that migration -
   editing an applied migration's Go source doesn't make it re-run. Reverted
   that edit and split the podcast id canonicalization into its own,
   later migration (20260902000005) that reuses the same buildIDMap/
   applyIDMap machinery. Verified both fresh-install and existing-install
   upgrade paths end-to-end against real sqlite DBs: no boot error, and
   legacy-shaped podcast ids (plus their FK references) get correctly
   rewritten to canonical form.

Verified: full build clean, core/podcasts + server/nativeapi + db/migrations
test suites all pass, gofmt clean.
2026-09-19 21:07:31 +09:00
..
migrations fix(podcast): implement missing SSRF validation and fix migration boot failure 2026-09-19 21:07:31 +09:00
backup.go fix(cli): fail restore when the backup file does not exist instead of wiping the database (#6085) 2026-09-11 20:50:45 -04:00
backup_test.go fix(cli): fail restore when the backup file does not exist instead of wiping the database (#6085) 2026-09-11 20:50:45 -04:00
db.go feat(cli): add 'doctor' and 'search rebuild' commands to recover from FTS5 corruption (#6069) 2026-09-11 22:26:28 -04:00
db_test.go feat(bfr): Big Refactor: new scanner, lots of new fields and tags, improvements and DB schema changes (#2709) 2025-02-19 20:35:17 -05:00
export_test.go feat(cli): add 'doctor' and 'search rebuild' commands to recover from FTS5 corruption (#6069) 2026-09-11 22:26:28 -04:00
optimize.go perf(db): keep query planner statistics trustworthy with full ANALYZE (#5740) 2026-07-13 12:04:29 -04:00
optimize_test.go perf(db): keep query planner statistics trustworthy with full ANALYZE (#5740) 2026-07-13 12:04:29 -04:00
repair.go feat(cli): add 'doctor' and 'search rebuild' commands to recover from FTS5 corruption (#6069) 2026-09-11 22:26:28 -04:00
repair_test.go feat(cli): add 'doctor' and 'search rebuild' commands to recover from FTS5 corruption (#6069) 2026-09-11 22:26:28 -04:00