🎧 Your Personal Streaming Service https://www.navidrome.org
  • Go 81.3%
  • JavaScript 15.4%
  • Rust 2.2%
  • Go Template 0.5%
  • Makefile 0.2%
  • Other 0.4%
Find a file
Adrián Sánchez Zapico 27483a46dc
fix(server): fail startup on initial setup errors and fix JSON/M3U response headers (#5897)
* fix(server): stop swallowing errors and correct two response bugs

Four independent bugs found while reviewing the HTTP layer:

initial_setup.go: createInitialAdminUser assigned the users.Put error to a
shadowed err, so the outer err (always nil by then, since a CountAll failure
panics) was returned instead. A failure to create the admin user was reported
as success, and initialSetup went on to commit the "setup complete" property
in the same transaction — so no admin user existed and initial setup was
skipped on every later boot.

auth.go: createAdminUser logged the Put error but returned nil, so createAdmin
fell through to doLogin and answered 401 "Invalid username or password"
instead of surfacing the real failure. It also logged the whole model.User,
which puts the new admin's password in the log in clear text; every other call
site logs user.UserName.

native_api.go: writeDeleteManyResponse did not return after http.Error when
marshaling failed, then wrote a nil body over the 500. It also built the
single-id body by hand with html.EscapeString, which does not escape
backslashes, so an id ending in one produced `{"id":"a\"}` — invalid JSON.
Both shapes now go through json.Marshal. A failed Write is now logged rather
than answered with http.Error, which could not work once the body had started.

handle_shares.go: handleM3U set Content-Type after WriteHeader, so it was
never sent and shared playlists were served with a sniffed type.

Signed-off-by: zapisanchez <zapisanchez@gmail.com>

* fix(server): address review feedback

- writeDeleteManyResponse uses rest.RespondWithJSON, so the response now
  has Content-Type: application/json. This also removes a marshal error
  branch that could never run.
- createInitialAdminUser returns the CountAll error instead of panicking,
  and wraps its errors. initialSetup now stops the server with log.Fatal
  when setup fails. Before, the error was dropped and the server started
  with a half-done setup.
- Trim comments that described PR history.

---------

Signed-off-by: zapisanchez <zapisanchez@gmail.com>
Co-authored-by: Deluan <deluan@navidrome.org>
2026-09-23 12:10:25 -04:00
.devcontainer chore(deps): upgrade to Go 1.27 (#5990) 2026-08-30 12:43:15 -04:00
.github ci: scope digest artifact cleanup to the current run 2026-09-21 19:27:48 -04:00
adapters fix(lastfm): report a failure when the artist page has no image (#6198) 2026-09-21 17:34:32 -04:00
cmd feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
conf feat(jellyfin): add Quick Connect sign-in (#6174) 2026-09-19 14:57:01 -04:00
consts feat: validate all configuration durations (#6002) 2026-09-01 21:16:14 -04:00
contrib fix(contrib): support libblas in systemd sandbox (#6190) 2026-09-21 09:06:12 -04:00
core fix(artwork): make stored images group-readable (#6189) 2026-09-21 17:25:46 -04:00
db fix(scanner): keep tag numbers within the int32 range (#6202) 2026-09-22 19:51:32 -04:00
git feat(plugins): experimental support for plugins (#3998) 2025-06-22 20:45:38 -04:00
log refactor(log): replace sort with slices.SortFunc and use atomic for currentLevel 2026-09-06 13:08:05 -04:00
model fix(scanner): keep tag numbers within the int32 range (#6202) 2026-09-22 19:51:32 -04:00
persistence fix(server): enforce player ownership on create and registration (#6184) 2026-09-20 21:10:41 -04:00
plugins fix(artwork): block private and loopback addresses in remote image fetches (#6181) 2026-09-20 20:46:46 -04:00
release fix(release): repair root-owned artwork and plugins folders on upgrade (#6143) 2026-09-17 17:17:56 -04:00
resources fix(ui): update Portuguese (BR) translations from POEditor (#6197) 2026-09-21 16:18:38 -04:00
scanner feat(cli): add missing file list and remap subcommands (#5928) 2026-09-12 12:08:25 -04:00
scheduler fix(log): change debug log level to trace to reduce log noise from cron 2026-08-06 00:40:58 -04:00
scripts build(worktree): add script for setting up git worktrees 2026-03-17 21:34:00 -04:00
server fix(server): fail startup on initial setup errors and fix JSON/M3U response headers (#5897) 2026-09-23 12:10:25 -04:00
tests fix(lastfm): report a failure when the artist page has no image (#6198) 2026-09-21 17:34:32 -04:00
ui fix(auth): ExtAuth logout redirect on unauthenticated loads, and warning spam from untrusted sources (#6176) 2026-09-19 17:08:49 -04:00
utils sec(server): sanitize user-controlled filenames in Content-Disposition (#5895) 2026-09-23 09:47:16 -04:00
.dockerignore fix: add music.old to .dockerignore and .gitignore 2026-02-06 07:40:05 -05:00
.git-blame-ignore-revs Move project to Navidrome GitHub organization 2021-02-06 21:47:19 -05:00
.gitignore ci: run the plugins test suite in parallel processes (#6051) 2026-08-30 16:57:40 -04:00
.golangci.yml refactor: replace md5 with xxh3 for faster and more efficient hashing 2026-08-19 09:28:25 -04:00
.nvmrc chore(deps): update all dependencies (#4618) 2025-10-25 17:05:16 -04:00
.octocov.yml ci: exclude tests/ from the coverage report on pull requests too (#6070) 2026-09-01 23:02:15 -04:00
CODE_OF_CONDUCT.md Use Contributor Covenant v2.0 2020-07-21 14:40:21 -04:00
context7.json Add context7.json with URL and public key 2026-04-14 19:19:42 -04:00
CONTRIBUTING.md docs: update commit message format in CONTRIBUTING.md 2026-02-20 11:00:34 -05:00
Dockerfile build(docker): add curl to container image (#6111) (#6116) 2026-09-09 11:38:59 -04:00
go.mod fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
go.sum fix(server): return 404 instead of 500 for missing native API resources (#6131) 2026-09-14 22:46:21 -04:00
LICENSE Change license to GPLv3 2020-01-22 14:48:38 -05:00
main.go feat(server): implement FTS5-based full-text search (#5079) 2026-02-21 17:52:42 -05:00
Makefile chore(deps): upgrade to Go 1.27 (#5990) 2026-08-30 12:43:15 -04:00
Procfile.dev chore(deps): upgrade to Go 1.24.1 (#3851) 2025-03-17 21:08:10 -04:00
README.md feat(subsonic): add structured sidecar lyrics support with OpenSubsonic v2 karaoke cues and agent layers (#5076) 2026-06-19 12:00:58 -04:00
reflex.conf fix(reflex): exclude .worktrees from the reflex configuration regex 2026-09-07 14:43:18 -04:00

Navidrome logo

Navidrome Music Server  Tweet

Last Release Build Downloads Docker Pulls Dev Chat Subreddit Contributor Covenant Gurubase

Navidrome is an open source web-based music collection server and streamer. It gives you freedom to listen to your music collection from any browser or mobile device. It's like your personal Spotify!

Note: The master branch may be in an unstable or even broken state during development. Please use releases instead of the master branch in order to get a stable set of binaries.

Check out our Live Demo!

Any feedback is welcome! If you need/want a new feature, find a bug or think of any way to improve Navidrome, please file a GitHub issue or join the discussion in our Subreddit. If you want to contribute to the project in any other way (ui/backend dev, translations, themes), please join the chat in our Discord server.

Installation

See instructions on the project's website

Cloud Hosting

PikaPods has partnered with us to offer you an officially supported, cloud-hosted solution. A share of the revenue helps fund the development of Navidrome at no additional cost for you.

PikaPods

Features

  • Handles very large music collections
  • Streams virtually any audio format available
  • Reads and uses all your beautifully curated metadata
  • Great support for compilations (Various Artists albums) and box sets (multi-disc albums)
  • Multi-user, each user has their own play counts, playlists, favourites, etc...
  • Very low resource usage
  • Multi-platform, runs on macOS, Linux and Windows. Docker images are also provided
  • Ready to use binaries for all major platforms, including Raspberry Pi
  • Automatically monitors your library for changes, importing new files and reloading new metadata
  • Supports lyrics from sidecar .ttml, .yaml/.yml Lyricsfile, .elrc, .lrc, .srt, .txt files and embedded TTML, Enhanced LRC, LRC, SRT, and plain-text tags (via lyricspriority)
  • Themeable, modern and responsive Web interface based on Material UI
  • Compatible with all Subsonic/Madsonic/Airsonic clients
  • Transcoding on the fly. Can be set per user/player. Opus encoding is supported
  • Translated to various languages

Translations

Navidrome uses POEditor for translations, and we are always looking for more contributors

Documentation

All documentation can be found in the project's website: https://www.navidrome.org/docs. Here are some useful direct links:

Screenshots